Part of the complete guide: Provably fair: the complete guide
What "provably fair" proves
Provably fair means the outcome can be recomputed from published inputs. If the inputs are the closed ticket list and a public random value, you can confirm that the winners follow from them. It protects you from one specific kind of cheating: choosing the winners.
It happens after the fact, on every draw, by you. That is its strength: it does not rely on anyone's reputation.
What an audit proves
An audit is a professional review. For a smart contract, it means reviewers read the code looking for bugs, unsafe patterns and unexpected powers. For a traditional lottery, auditors inspect procedures and equipment.
Its strength is expertise: reviewers can see problems you will not. Its limits are time (a snapshot of one version), scope (some risks are out of scope) and trust (you rely on the auditor's reputation).
A comparison
| Question | Provably fair | Audited |
|---|---|---|
| Who checks | You, on every draw | A specialist, once or periodically |
| What it covers | How winners follow from inputs | Code or procedures reviewed |
| Catches rigged winners | Yes | Only if the rigging is in the reviewed code |
| Catches software bugs | No | Often |
| Catches non-payment of prizes | No | Only for contracts that pay automatically |
| Still valid after changes | Yes, for each new draw | No, only for the audited version |
Why you want both
Provable fairness handles "were the winners chosen honestly?". Audits handle "can the system be broken?". A lottery that holds funds in a contract needs both, because a perfectly fair draw is no use if the pool can be drained.
For an operator-run lottery that pays prizes itself, an audit of code matters less than the transparency of the draw and the operator's track record of paying.
Where CryptoDrawz stands
- Provably fair: yes. Each draw publishes its ticket list, a public random value and the winners, and can be recomputed in the browser.
- Audited: no. There is no smart contract today, so there is nothing to audit in that sense. If we move on-chain, an independent audit comes first.
- Prize payment: manual, by us. That is the main thing you are trusting.
How to read other sites' claims
- 1Ask "provably fair" of what, exactly? If there is no data to check, the phrase is decoration.
- 2Ask "audited" by whom, when, and which version? Look for a link to the report.
- 3Match the claim to the money flow. If the site holds your money, you want to know how it is protected.
Examples of what each would catch
| Scenario | Caught by verifiable draws | Caught by an audit |
|---|---|---|
| Operator picks a friend as winner | Yes: the result will not match the recomputation | Only if the code path exists in the audited version |
| A bug lets anyone drain the pool | No | Often |
| Operator never pays prizes | No | Only for automatic payouts in a contract |
| A ticket is quietly removed from the list | Yes, if the buyer checks their ticket is listed | No |
| Weak random number source | Yes, if the source is public | Often |
Combining signals into a decision
- 1Decide what you are trusting the operator for: holding money, picking winners, paying prizes.
- 2For each, ask which signal covers it: verification, audit, licence, track record.
- 3Where nothing covers it, keep the amount small.
Why we are open about this
We would rather you know exactly what is and is not covered. Today our draw is verifiable, prizes are paid by us and there is no audited contract. That is a deliberate, stated position, and it is why we encourage small stakes. As we add more protections, this page and the rest of the site will say so.
Example: two lotteries, two failures
Lottery A has a published audit of its contract and a verified source. A bug found later lets an attacker take funds from the pool. The audit did not catch it, and the draw could be recomputed all day without saving the money. Lottery B has no audit but publishes every ticket and the public randomness used. The operator quietly leaves out a few tickets from the list. Entrants who check their own tickets notice the omission, and the fingerprint published at close does not match the list. Each type of check catches the failure the other cannot. This is the practical reason to want both.
What to ask for
- 1An audit report, with the scope, the version and the fixes.
- 2A published draw you can recompute.
- 3A statement of who holds keys and what they can do.
- 4A track record of paying prizes.
Ready?
A weekly draw you can check yourself.
$5 tickets, a public random value, and every result published with the data to recompute it.
Frequently asked questions
Which matters more?
It depends on who holds the money. For on-chain pools, audits matter a lot. For operator-run draws, verifiable draws and a payout track record matter more.
Can a lottery be provably fair but still unsafe?
Yes. A fair draw does not guarantee that prizes are paid or that funds are safe.
Is "audited" a legal status?
No. It is not a licence. It describes a technical review.
Do I have to verify every draw?
No. Even if only a few people check, the possibility of being checked keeps an operator honest.
Can I trust an audit by an unknown firm?
Be cautious. Look for reputable, independent firms and a public report.
Do audits expire?
They apply to a specific version of code, so changes can void their relevance.
Should a lottery publish both?
Yes, ideally, together with its rules and a record of paying.