COMMIT.
Your side and exact wager are recorded before randomness is requested.
Your browser reads the public chain, rebuilds the Merkle path and request ID, then recomputes the exact outcome.
VERIFY A FLIPYour side and exact wager are recorded before randomness is requested.
The Vault locks one matching wager. If every pending player wins, every payout remains covered.
A precommitted secret and your fresh browser entropy produce one verifiable word. Its lowest bit maps evenly to Heads or Tails.
The contract resolves once. A win pays exactly 2× gross; a loss sends the wager to the House.
The provider publishes immutable Merkle roots before wagers and cannot replace them. Anyone can relay a valid reveal. If no reveal arrives before the hard deadline, the player receives 2× gross—not a refund—so withholding cannot improve the House result. The self-operated seed holder knows unrevealed secrets and must never wager or collude with a player; removing that trust assumption requires a third-party VRF or threshold provider.