THE RAFFLE FAIRNESS · DRAW #929

Prove. Commit. Verify.

The operator cannot bias which holder wins. The roll is an RFC 9381 ECVRF output keyed by our on-chain frozen key, its input bound to the resolved slot hash so it cannot be precomputed, and the winner is the holder whose weighted slice of the snapshot covers the roll. Recompute AND verify everything — the binding, the ECVRF proof, the roll — right here in your browser.

Drawn  Pot 1 cards · $18Holders 2,016Outcome WONRaw draw id 2018
FOUR STEPS · ONE VIEWPORT
Freeze > Snapshot > Prove > Roll
  1. Freeze
    We froze our VRF key on-chain before any draw
    Our ECVRF public key is registered + FROZEN on-chain (Collector Crypt VRF program) under a fixed owner + label. Once frozen it cannot be swapped — every proof verifies against this one key.
    vrf_authority: frozen(pk, owner, label)
  2. Snapshot
    Every holder balance is recorded at the close slot
    When the window closes we record a Merkle root of every eligible $GACHA balance at that exact Solana slot. Nobody touches your balance — we just take a tamper-evident snapshot the weighted pick runs over.
    snapshotMerkleRoot = MerkleRoot(holders[closeSlot])
  3. Prove
    alpha binds the slot, we publish the ECVRF proof
    The proof input alpha = sha256(slotHash ‖ drawId) binds the FUTURE slot blockhash — nobody (including us) can precompute it. We produce the ECVRF proof and commit sha256(proof) on-chain.
    alpha = sha256(slotHash ‖ drawId)
  4. Roll
    beta[0:32] picks the winner
    The roll is the first 32 bytes of the VRF output (beta). We walk the prefix-sum of weights — first holder whose slice covers the offset wins the whole pot. verifyVRF confirms the proof; the roll is forced by it.
    roll = beta[0:32] (beta = ECVRF output)
SECTION 02

Recompute the roll. Right here. In your browser.

The widget recomputes the VRF input alpha = sha256(slotHash ‖ drawId), verifies the ECVRF proof itself (verifyVRF, RFC 9381) against the operator key, and confirms the published roll IS beta[0:32] — the entire chain, in your browser. Collector Crypt is an independent cross-check that the operator key is the one frozen on-chain.

RECOMPUTED IN BROWSER
ECVRF (RFC 9381) · Collector Crypt VRF
✓ VERIFIED
DRAW #2018
AUTO-RUN · NO FETCH
VRF authority
13R5zhNirknRrskNyEmyZuC5NNEQWcSwN5w8BUn6qnp8
Slot
438562020
Slot hash
7cb676fee63a1a61c15adc4dc4c0689d53293e52941d75567bf019e70f84aa14
alpha (published)
2f0d1aa53925b526f06d6a03f78ba6b7a88d6b0c7aa84c8781ea2f7a685033d2
alpha (recomputed)
2f0d1aa53925b526f06d6a03f78ba6b7a88d6b0c7aa84c8781ea2f7a685033d2
Alpha binds slot
alpha === sha256(slotHash ‖ drawId)
Operator VRF key
e75d1717431b1c691084425d0a0d96f094c7e72fb9d35a49b7052326d8f48f0e
ECVRF proof valid
verifyVRF(operatorKey, alpha, proof) === true (in-browser)
beta (VRF output)
d515ddf56ae5a0318d0b8c3364d8c079f1d22a1c37dd096adbac3b664fc78fd4651e7c58093293b4d1056bd5ac9478edfd9182ca927b0016ff51f29f59be6ddc
Published roll
0xd515ddf56ae5a0318d0b8c3364d8c079f1d22a1c37dd096adbac3b664fc78fd4
Roll is beta[0:32]
rollHex === beta[0:32]
Snapshot root
64cef0c8315a529b5cd19af399de7709ec45d75ca866575e6480b3b6d829c73f
Holders
2,016
Eligible total
902,041,287 GACHA
Winner balance
10,006,383 GACHA
Winner odds
balance / eligible = 1.1093% (matches published)
On-chain commit
14fYDihpks4WGCfTyQ2TbkAbQDrY8dS7UszSZk4LqX9T
Owner (verify input)
HuTNYccZn2U3sNpJnVTgyi9XZFRo9GjbJHBjc1F2tWYL
Label (verify input)
raffle
Memo (verify input)
pg-raffle-2018
Proof (verify input)
ed87314dabc23a1ea96405ac524f28c7ed04d636e333d5393f38a6a5b57b3db9cc178498a26f8761efdf0927280db29a00de6899354b48c3ff33c54d5bab320d64db397fb05f0d800c03a4177ede7805

Verified in your browser: alpha binds the public slot, the ECVRF proof checks out under the published operator key, and the roll IS beta[0:32]. The winner is then the balance-weighted pickWinner(snapshot, roll) walk — the snapshot itself is committed by the Merkle root above (not downloaded here), so the winner + odds rows are informational.

The pot1 card · $18 — winner takes all

1 card worth $18 opened this window — 4PDX…1UZc held 1.11% of the eligible snapshot and won the pot.

The winnerSolscan
4PDX…1UZc
4PDX…1UZc
Never claimed — cards bought back, USDC rolled into the next draw.Sweep zyTe…us2w
Win chance
1.11%
About 1-in-N
90
Winner balance
10,006,383 GACHA
Eligible pool
902,041,287 GACHA
REFERENCE IMPLEMENTATION

Copy-paste. Run it locally. Same answer.

raffle-vrf-roll.tsTypeScript
import { verifyVRF, vrfProofToHash } from '@collectorcrypt/vrf-client';
import { sha256 } from '@noble/hashes/sha2';

// alpha binds the resolved slot hash + draw id (32B slot hash || utf8 id)
const alpha = sha256(concat(slotHashBytes, utf8(String(drawId))));

// 1. the ECVRF proof must verify under our FROZEN operator key
const ok = verifyVRF(operatorPubkey, alpha, proof); // RFC 9381 -> true

// 2. the published roll must be the first 32 bytes of the VRF output
const roll = vrfProofToHash(proof).slice(0, 32); // === published rollHex

// 3. the winner: map roll into [0,1), walk the snapshot's weight
//    prefix-sum — the first holder whose slice covers it wins.

Node ≥ 20 · no dependencies · same output as the browser widget.

Raw draw id 2018 — what the proof and this URL key on.Missing rows land once the draw reveals. Very early draws predate parts of this record — what exists is shown, nothing is backfilled.This draw in historyHow the mechanism works