CryptoDrawz

Provably fair vs audited lotteries

Both phrases appear on lottery sites, often as if they meant the same thing. They do not. One is about whether you can check a result. The other is about whether an expert has reviewed the system. Knowing which is which lets you read these claims properly.

4 min readUpdated October 7, 2026By the CryptoDrawz editorial team

Part of the complete guide: Provably fair: the complete guide

What "provably fair" proves

Provably fair means the outcome can be recomputed from published inputs. If the inputs are the closed ticket list and a public random value, you can confirm that the winners follow from them. It protects you from one specific kind of cheating: choosing the winners.

It happens after the fact, on every draw, by you. That is its strength: it does not rely on anyone's reputation.

What an audit proves

An audit is a professional review. For a smart contract, it means reviewers read the code looking for bugs, unsafe patterns and unexpected powers. For a traditional lottery, auditors inspect procedures and equipment.

Its strength is expertise: reviewers can see problems you will not. Its limits are time (a snapshot of one version), scope (some risks are out of scope) and trust (you rely on the auditor's reputation).

A comparison

QuestionProvably fairAudited
Who checksYou, on every drawA specialist, once or periodically
What it coversHow winners follow from inputsCode or procedures reviewed
Catches rigged winnersYesOnly if the rigging is in the reviewed code
Catches software bugsNoOften
Catches non-payment of prizesNoOnly for contracts that pay automatically
Still valid after changesYes, for each new drawNo, only for the audited version

Why you want both

Provable fairness handles "were the winners chosen honestly?". Audits handle "can the system be broken?". A lottery that holds funds in a contract needs both, because a perfectly fair draw is no use if the pool can be drained.

For an operator-run lottery that pays prizes itself, an audit of code matters less than the transparency of the draw and the operator's track record of paying.

Where CryptoDrawz stands

  • Provably fair: yes. Each draw publishes its ticket list, a public random value and the winners, and can be recomputed in the browser.
  • Audited: no. There is no smart contract today, so there is nothing to audit in that sense. If we move on-chain, an independent audit comes first.
  • Prize payment: manual, by us. That is the main thing you are trusting.

How to read other sites' claims

  1. 1Ask "provably fair" of what, exactly? If there is no data to check, the phrase is decoration.
  2. 2Ask "audited" by whom, when, and which version? Look for a link to the report.
  3. 3Match the claim to the money flow. If the site holds your money, you want to know how it is protected.

Examples of what each would catch

ScenarioCaught by verifiable drawsCaught by an audit
Operator picks a friend as winnerYes: the result will not match the recomputationOnly if the code path exists in the audited version
A bug lets anyone drain the poolNoOften
Operator never pays prizesNoOnly for automatic payouts in a contract
A ticket is quietly removed from the listYes, if the buyer checks their ticket is listedNo
Weak random number sourceYes, if the source is publicOften

Combining signals into a decision

  1. 1Decide what you are trusting the operator for: holding money, picking winners, paying prizes.
  2. 2For each, ask which signal covers it: verification, audit, licence, track record.
  3. 3Where nothing covers it, keep the amount small.

Why we are open about this

We would rather you know exactly what is and is not covered. Today our draw is verifiable, prizes are paid by us and there is no audited contract. That is a deliberate, stated position, and it is why we encourage small stakes. As we add more protections, this page and the rest of the site will say so.

Example: two lotteries, two failures

Lottery A has a published audit of its contract and a verified source. A bug found later lets an attacker take funds from the pool. The audit did not catch it, and the draw could be recomputed all day without saving the money. Lottery B has no audit but publishes every ticket and the public randomness used. The operator quietly leaves out a few tickets from the list. Entrants who check their own tickets notice the omission, and the fingerprint published at close does not match the list. Each type of check catches the failure the other cannot. This is the practical reason to want both.

What to ask for

  1. 1An audit report, with the scope, the version and the fixes.
  2. 2A published draw you can recompute.
  3. 3A statement of who holds keys and what they can do.
  4. 4A track record of paying prizes.

Ready?

A weekly draw you can check yourself.

$5 tickets, a public random value, and every result published with the data to recompute it.

Frequently asked questions

Which matters more?

It depends on who holds the money. For on-chain pools, audits matter a lot. For operator-run draws, verifiable draws and a payout track record matter more.

Can a lottery be provably fair but still unsafe?

Yes. A fair draw does not guarantee that prizes are paid or that funds are safe.

Is "audited" a legal status?

No. It is not a licence. It describes a technical review.

Do I have to verify every draw?

No. Even if only a few people check, the possibility of being checked keeps an operator honest.

Can I trust an audit by an unknown firm?

Be cautious. Look for reputable, independent firms and a public report.

Do audits expire?

They apply to a specific version of code, so changes can void their relevance.

Should a lottery publish both?

Yes, ideally, together with its rules and a record of paying.

Keep reading