Channel
verifying on-chain…
Channel
verifying on-chain…
v14 · Channel #4383
−$1.26
16 rounds · 42 steps · $10.22 wagered · lost
✓ Provably fair — the seed was committed on-chain before play, the exact step stream was signed by the player's key, and every roll, decision, and payout below is re-derived from public inputs and matches the on-chain settlement.
Verified in your browser
Re-deriving every check from chain reads in this browser — reconstructing the game trees, re-rolling the seed, recovering the signature…
Don't trust this site's RPC either? Paste any HyperEVM RPC URL and re-run — the verification then never touches this site. The algorithm is verifyChannel in @freeroll/sdk — run it yourself from a terminal for zero trust in this page.
Parameters chain
Proof of randomness
✓1.The seed was committed before you played
The commitment keccak256(serverSeed) was fixed on-chain in the open transaction at block 61308759, before any step was played. The seed revealed at close must hash back to that commitment — since keccak256 has no known way to find a second preimage, the house had exactly one seed it could ever reveal, chosen before it saw a single one of your bets.
Commitment (bound at open)
0xc14110a214ccd33904f052700ad87f8b5b8e4bd881ebe1bd45105bf7bff00f99
Server seed (revealed at close)
0x19f01a92d74c86774f68829d0d77d6f2283cbdd100a9d99db238776b3158d448
keccak256(serverSeed)
✓ matches the commitment
✓2.You signed the exact stream that settled
Each step, your session key signed DrawCommit(channelId, steps, root) — a running hash-chain over every round you entered, every decision you took, and every reveal you requested, signed before the outcome was shown. The close can only settle a stream and count carrying your signature: the house can't add, drop, or reorder a single step.
Signed message
DrawCommit(channelId=4383, steps=42, root=0x07613d12…db2c124b)
Recovered signer
0xdcf3e45606FcE00731236F97d874449c4d4Cd513 ✓ = your session key
✓3.The stream hash-chain checks out
Re-folding the submitted stream — root_t = keccak256(root_(t−1), t, …) over each round's (stake, game), each decision's choice, and each reveal — must reproduce the root you signed, pinning the exact sequence to your signature.
Signed root
0x07613d12334aeeafa9b9d14ff4c19fb041a647576afd0fba814e5d91db2c124b
Recomputed from the submitted stream
✓ identical
✓4.Every roll re-derived from public inputs
Each roll is keccak256(serverSeed, clientSeed, channelId, t) mod 10000, walked through the on-chain game tree it was played against. Recomputed below — not read from anywhere.
Round 1 · played against Relics (base) — sealed tree #62game stats →
fold t1 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000
Round 2 · played against Relics (base) — sealed tree #62game stats →
fold t3 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000
Round 3 · played against Relics (base) — sealed tree #62game stats →
fold t5 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000
Round 4 · played against Relics (soft 2) — sealed tree #64game stats →
fold t7 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000
Round 5 · played against Fog — sealed tree #124game stats →
t9 · you chose option 2 of 24 · worth 0.00× under optimal play · best free option was 0.98× — no roll here, the choice was yours. Values come from the sealed tree itself.
Round 6 · played against Siege (Line) — sealed tree #128game stats →
t11 · you chose option 1 of 3 · worth 0.98× under optimal play · the best option available — no roll here, the choice was yours. Values come from the sealed tree itself.
fold t12 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000
Round 7 · played against Siege (Line) — sealed tree #128game stats →
t14 · you chose option 2 of 3 · worth 0.98× under optimal play · the best option available — no roll here, the choice was yours. Values come from the sealed tree itself.
fold t15 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000
Round 8 · played against Blockchain (Blitz) — sealed tree #123game stats →
fold t17 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000
Round 9 · played against Blockchain (Frenzy) — sealed tree #121game stats →
fold t19 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000
Round 10 · played against Blockchain (Frenzy) — sealed tree #121game stats →
fold t21 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000
Round 11 · played against Blackjack (3:2) — sealed tree #96game stats →
fold t23 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000
fold t24 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000
Round 12 · played against Blackjack (3:2) — sealed tree #96game stats →
fold t29 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000
fold t30 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000
Round 13 · played against Streak 128× — sealed tree #74game stats →
fold t35 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000
Round 14 · played against Streak 128× — sealed tree #74game stats →
fold t37 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000
Round 15 · played against Streak 128× — sealed tree #74game stats →
fold t39 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000
Round 16 · played against Streak 128× — sealed tree #74game stats →
fold t41 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000
⏏ The final round ended mid-play, so it settled at the position's table value — the same mark the contract paid.
✓ The recomputed net, wagered total, and step count match the on-chain settlement exactly.
✓5.Every round respected the committed caps
The channel committed hard walls before play: no stake above the budget of $23.99, and no single round whose worst-case win exceeds the committed per-round cap of $238.80 against its own game's maximum multiplier. Every round in the stream was re-checked against both — the same integer comparison the contract itself enforces. All rounds fit.
Games (on-chain catalog) chain
Each game is a value tree stored on-chain and validated by the contract when it was sealed — the edge under optimal play is enforced inside a fixed band, so no game referenced here can be unfair in either direction. The payouts above were walked from these exact trees, reconstructed from the chain's packed words.
What this page proves · what it assumes
Proven (recomputable by anyone)
Assumed (and why it's bounded)
fold t25 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000
t26 · you chose option 1 of 3 · worth 0.82× under optimal play · the best option available — no roll here, the choice was yours. Values come from the sealed tree itself.
fold t27 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000
fold t31 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000
t32 · you chose option 1 of 3 · worth 0.33× under optimal play · best free option was 0.48× — no roll here, the choice was yours. Values come from the sealed tree itself.
fold t33 · roll = keccak256(serverSeed ‖ clientSeed ‖ channelId ‖ t) mod 10000