How LOOTDROP is Provably Fair
Provably Fair
Every item that drops from a box is decided by an open, cryptographic method. Three separate values feed each roll, so you can recompute any result yourself — no trust in us required.
It works like checking a die has six real sides or a deck holds 52 real cards. Online, the same idea guarantees that nothing about a roll can be steered once the seeds are set.
Game Outcome
Three values decide every outcome:
- Your Hand
- A code derived from input you control. You can change it any time — even compare hands with other players.
- Our Hand
- A secret code we hold back until you ask to reveal it. Before play you only ever see its hash.
- Play Count
- The number of opens on your account. It grows by one with every roll.
Each potential unbox is assigned a roll number out of 100,000,000 possible outcomes, computed from:
- Client Seed
- A passphrase you provide. Visible, editable, yours.
- Server Seed
- A long random value from us. You see its SHA-256 hash before playing; the raw seed is revealed afterwards so the hash can be checked.
- Play Count
- Makes every roll unique even when both seeds stay the same.
The combined string is hashed with HMAC-SHA256 and the first 13 hex characters map to the roll. This page runs the exact algorithm our servers use:
const crypto = require('crypto');
// Set these 3 values
const serverSeed = '3b79a56f040e384220d5d8c17834b017e9f9da348f3bfb7cd86d4644bb61ad8d';
const clientSeed = 'f054ef22bef543fb7bd392419bea3727ed297e9820d72335c68de209c08149c9';
const playCount = 1611;
// Calculate the spin using the seeds
const spin = getSpin(serverSeed, clientSeed, playCount);
console.log(`Spin: ${spin}`);
/* --- Algorithmic functions to calculate the Spin --- */
function getSpinFromHash(hash, maxSpin = 99999999) {
const subHash = hash.slice(0, 13);
const valueFromHash = Number.parseInt(subHash, 16);
// Calculate the dynamic result for this roll
const e = Math.pow(2, 52);
const result = valueFromHash / e;
return Math.floor(result * maxSpin);
}
function getSpin(serverSeed, clientSeed, playCount) {
const seed = getCombinedSeed('BOXES', serverSeed, clientSeed, playCount);
const hash = crypto.createHmac('sha256', seed).digest('hex');
return getSpinFromHash(hash);
}
function getCombinedSeed(game, serverSeed, clientSeed, playCount) {
const seedParameters = [serverSeed, clientSeed, playCount];
if (game) {
seedParameters.unshift(game);
}
return seedParameters.join('-');
}Verify it yourself
Run the snippet in Node.js or any online JavaScript playground to reproduce any past roll. The code below is our live implementation — the mini verifier runs it in your browser right now.