LOOTDROP

How LOOTDROP is Provably Fair

Provably Fair

Every item that drops from a box is decided by an open, cryptographic method. Three separate values feed each roll, so you can recompute any result yourself — no trust in us required.

It works like checking a die has six real sides or a deck holds 52 real cards. Online, the same idea guarantees that nothing about a roll can be steered once the seeds are set.

Game Outcome

Three values decide every outcome:

Your Hand
A code derived from input you control. You can change it any time — even compare hands with other players.
Our Hand
A secret code we hold back until you ask to reveal it. Before play you only ever see its hash.
Play Count
The number of opens on your account. It grows by one with every roll.

Each potential unbox is assigned a roll number out of 100,000,000 possible outcomes, computed from:

Client Seed
A passphrase you provide. Visible, editable, yours.
Server Seed
A long random value from us. You see its SHA-256 hash before playing; the raw seed is revealed afterwards so the hash can be checked.
Play Count
Makes every roll unique even when both seeds stay the same.

The combined string is hashed with HMAC-SHA256 and the first 13 hex characters map to the roll. This page runs the exact algorithm our servers use:

const crypto = require('crypto');

// Set these 3 values
const serverSeed = '3b79a56f040e384220d5d8c17834b017e9f9da348f3bfb7cd86d4644bb61ad8d';
const clientSeed = 'f054ef22bef543fb7bd392419bea3727ed297e9820d72335c68de209c08149c9';
const playCount = 1611;

// Calculate the spin using the seeds
const spin = getSpin(serverSeed, clientSeed, playCount);
console.log(`Spin: ${spin}`);

/* --- Algorithmic functions to calculate the Spin --- */

function getSpinFromHash(hash, maxSpin = 99999999) {
  const subHash = hash.slice(0, 13);
  const valueFromHash = Number.parseInt(subHash, 16);
  // Calculate the dynamic result for this roll
  const e = Math.pow(2, 52);
  const result = valueFromHash / e;
  return Math.floor(result * maxSpin);
}

function getSpin(serverSeed, clientSeed, playCount) {
  const seed = getCombinedSeed('BOXES', serverSeed, clientSeed, playCount);
  const hash = crypto.createHmac('sha256', seed).digest('hex');
  return getSpinFromHash(hash);
}

function getCombinedSeed(game, serverSeed, clientSeed, playCount) {
  const seedParameters = [serverSeed, clientSeed, playCount];
  if (game) {
    seedParameters.unshift(game);
  }
  return seedParameters.join('-');
}

Verify it yourself

Run the snippet in Node.js or any online JavaScript playground to reproduce any past roll. The code below is our live implementation — the mini verifier runs it in your browser right now.

Mini verifier