VERIFIABLE BY DESIGN

DON'T TRUST IT.
CHECK IT.

Your browser reads the public chain, rebuilds the Merkle path and request ID, then recomputes the exact outcome.

VERIFY A FLIP
50% HEADS+50% TAILS2× ON A WIN
READ THE CONTRACT

VERIFY A FLIP.

THE PROOF PATH

NOT A PROMISE.
A SEQUENCE.

01

COMMIT.

Your side and exact wager are recorded before randomness is requested.

02

RESERVE.

The Vault locks one matching wager. If every pending player wins, every payout remains covered.

03

DRAW.

A precommitted secret and your fresh browser entropy produce one verifiable word. Its lowest bit maps evenly to Heads or Tails.

04

SETTLE.

The contract resolves once. A win pays exactly 2× gross; a loss sends the wager to the House.

THE HONEST LIMIT

FAIR ODDS AREN'T
ZERO RISK.

The provider publishes immutable Merkle roots before wagers and cannot replace them. Anyone can relay a valid reveal. If no reveal arrives before the hard deadline, the player receives 2× gross—not a refund—so withholding cannot improve the House result. The self-operated seed holder knows unrevealed secrets and must never wager or collude with a player; removing that trust assumption requires a third-party VRF or threshold provider.

HOW IT WORKS CALL YOUR SIDE