Part of the complete guide: Provably fair: the complete guide
The problem drand solves
Imagine you run a lottery and say, "I rolled a die in private, and number four won." Why should anyone believe you? If instead a neutral party, watched by everybody, publishes a random number at a time you did not control, you no longer need to be believed.
That neutral party is what drand provides. It is a public randomness beacon: a service that publishes a fresh random value at regular intervals, for anyone to use.
How drand makes a random value
drand is run by a group of independent organisations (often called the League of Entropy; members have included well-known companies, universities and research groups). Each member holds a secret share. Together, using threshold cryptography, a minimum number of them must cooperate to produce each round's value.
Two properties matter. No single member, nor a small group, can produce or change a value by themselves. And nobody, including the members, can compute a future round's value ahead of time, because it depends on a signature that only exists once enough members produce it.
Each round has a number. The value is published with a signature, so later anyone can confirm it came from the network.
Unpredictable and verifiable
- Unpredictable: a future value cannot be known before it is produced.
- Unbiasable: no participant can steer the value toward a preferred outcome.
- Verifiable: each value comes with a signature that anyone can check against the network's public key.
- Available: the values are published openly and can be looked up again at any time.
Why this suits a lottery
A lottery draw has a simple requirement: the winners must not be knowable or changeable by the operator. If we close the ticket list at a set time and use the drand value published at that time, we cannot know the value earlier, and we cannot pick a convenient one later, because the round number is fixed by the clock.
We combine the drand value with a fingerprint of the closed ticket list, so the result also depends on exactly who bought tickets. Change one ticket and every winner changes.
How CryptoDrawz uses it
- 1Tickets for a draw close at Sunday 20:00 UTC.
- 2We fingerprint the sorted list of ticket numbers with SHA-256.
- 3We take the drand round that is published at the draw time.
- 4seed = SHA-256(random value + ":" + fingerprint).
- 5Winner positions are derived from the seed and read from the sorted list, skipping duplicates, until 14 different tickets are found.
- 6We publish the ticket list, fingerprint, round number, random value and winners, and you can recompute them in your browser.
What drand does not prove
drand proves the random number is genuine and was not chosen by us. It does not prove that the ticket list is complete, that payments were honest, or that prizes will be paid. That is why we publish the full ticket list and why we say plainly that prizes are currently paid by us rather than by a contract.
Looking up a drand value yourself
drand values are served over a public web API. For a given round number, the API returns a small piece of data containing the round, the random value and the signature. You can open the address in a browser and read it. The address pattern is the API host, then the chain identifier, then "public" and the round number.
Each published CryptoDrawz draw shows the round number and a "look it up at drand" link, so you can compare the value on our page with the value from the network directly.
How a round number maps to a time
The network we use started at a fixed moment and publishes one round every 3 seconds. That makes round numbers a clock: the round for any given second can be calculated. Our draw time is fixed, so the round we use is fixed too. We cannot shop around for a more convenient round, because the round number is derived from the draw time before the value exists.
Limits and honest caveats
- drand relies on enough participants staying honest. It is designed so that a minority cannot predict or bias values, not so that no one has to be trusted at all.
- If the network were unavailable at the draw time, a draw could be delayed until the value is available.
- drand does not know anything about our tickets. The link between the beacon and the lottery is our published calculation.
Ready?
A weekly draw you can check yourself.
$5 tickets, a public random value, and every result published with the data to recompute it.
Frequently asked questions
Who runs drand?
A group of independent organisations, known as the League of Entropy, operate the network together.
Can CryptoDrawz influence the drand value?
No. The value for a given moment is produced by the network, and we cannot compute it in advance or alter it.
How often does drand publish?
The network we use publishes a new value every 3 seconds.
Where can I look up a value?
Each published draw links to the exact drand round so you can fetch the value yourself from the public API.