CryptoDrawz

SHA-256 hashes explained for lottery fairness

You may have seen long strings of letters and numbers next to a lottery result and wondered what they are. They are hashes: fingerprints of data. They look like noise, but they are one of the most useful tools for proving that nothing was changed after the fact.

4 min readUpdated October 7, 2026By the CryptoDrawz editorial team

Part of the complete guide: Provably fair: the complete guide

A fingerprint for data

Think of a hash as a fingerprint. Put in a word, a document or an entire list of tickets and you get a short string. Two different inputs, even ones that differ by a single character, give totally different strings.

SHA-256 is a standard hash function used widely, including in Bitcoin. Its output is 256 bits, usually written as 64 characters of 0-9 and a-f.

InputSHA-256 (first 16 characters)
lotterybe7f94bb10c4be7b…
lotterz5d83a0d44b18f12c…

The three properties that matter

  • Deterministic: the same input always produces the same hash.
  • Avalanche effect: change one character and about half of the output bits flip.
  • One-way: given a hash, you cannot find an input that makes it, except by guessing.

How a ticket-list hash works

If someone later added, removed or swapped a single ticket, the fingerprint of the list would no longer match. That means the list you see is the list that was drawn from.

  1. 1When a draw closes, the ticket numbers in it are sorted alphabetically.
  2. 2They are joined into one block of text, one ticket per line.
  3. 3The SHA-256 of that text is the ticket fingerprint.
  4. 4We publish the fingerprint with the result, along with the full list.

From fingerprint to winners

The fingerprint also feeds the winner calculation. We build a seed from the public random value and the ticket fingerprint, then hash the seed with a counter (seed:0, seed:1, seed:2 and so on). Each hash is turned into a number, and that number picks a position in the sorted list.

Because every step is a hash, every step is exactly repeatable. The "Every calculation, step by step" table on each published draw shows these hashes so you can compare them with your own.

Check a hash yourself

You can compute SHA-256 without trusting us. Most operating systems include a command-line tool, and browsers include a built-in function. The code sample on our Draws page uses the browser's own crypto library. Paste in the ticket list and the random value and compare the output with what we published.

Why a tiny change changes everything

The table above shows two inputs that differ by one letter and produce totally unrelated hashes. This is the avalanche effect. It is what makes a hash useful as a tamper detector: if one ticket in a list of thousands were altered, the hash of the whole list would change beyond recognition.

A hash is a commitment

Publishing a hash before revealing the data is a way of committing to it. Anyone who later sees the data can hash it and compare. If the hashes match, the data is the same as the data that was committed to. We apply the idea to the ticket list: the fingerprint is part of the result, so the list is locked in once the draw is run.

What a hash cannot do

  • It cannot tell you whether the data it fingerprints was honest to begin with.
  • It does not hide the data. Hashing a short, guessable input is easy to reverse by trying guesses.
  • It does not prove who created the data. Signatures do that.

Example: fingerprinting a three-ticket list

Take three tickets: CD-AAAAA-AAAAA, CD-BBBBB-BBBBB, CD-CCCCC-CCCCC. Sorted and joined with newlines, they form one block of text. Hash it with SHA-256 and you get a 64-character fingerprint. Now change one letter in one ticket, say the last A to B, and hash again. The fingerprint is completely different, with no resemblance to the first. If an operator had published the first fingerprint before the draw, a later list with a swapped ticket would not match, and anyone could see it. Our SHA-256 generator lets you try this with any text.

Hash trivia worth knowing

  • A SHA-256 hash has 2^256 possible values, a number so large that guessing a specific one is not feasible.
  • Bitcoin uses SHA-256 twice for block hashes.
  • A hash is not encryption. You cannot recover the input from it.

Ready?

A weekly draw you can check yourself.

$5 tickets, a public random value, and every result published with the data to recompute it.

Frequently asked questions

Can two different inputs have the same SHA-256 hash?

In theory yes, but finding one is computationally infeasible with today's technology.

Is a hash the same as encryption?

No. Encryption can be reversed with a key. A hash is one-way by design.

Why sort the tickets first?

So everyone builds the exact same text from the same list, which gives the exact same hash.

Does the hash prove the draw was fair?

It proves the ticket list is unchanged. Fairness also needs the public random value and a published rule for choosing winners.

Is SHA-256 safe from quantum computers?

Current understanding is that hash functions like SHA-256 are far more resistant than public-key systems. Research continues.

Can two files have the same hash?

In theory yes, but no practical collision for SHA-256 is known.

Is a hash the same as a checksum?

A checksum catches accidents. A cryptographic hash is built to resist deliberate tampering.

Keep reading