- Commitment transaction hashPoints to the immutable
OVCRpayload. - Expected signer addressMust be both sender and recipient of the commitment.
Deterministic selection · Tool 02
Replay the winner, input by input.
Fetch the public commitment and finalized target block, then run the same unbiased selection algorithm in your browser. The output should match the published winner exactly.
Complete evidence checklist
Everything needed to verify independently.
The organizer publishes two references. Every other draw value is either chosen by the verifier or read directly from Ethereum mainnet.
- Ethereum RPC URLPublicNode is prefilled, and the verifier may replace it with any mainnet endpoint.
- No private draw valueThe winner replay needs no secret, seed, or participant record.
- Transaction and receiptStatus, sender, recipient, value, calldata, and commitment block.
- Committed raffle dataRaffle ID, target block, code count, Merkle root, and full ordered code list.
- Finalized target blockIts public block hash is the future entropy used by the draw.
Public draw details
No raffle code is needed to reproduce the winner.
Beginner-friendly option
Ask an AI to replay the winner.
Fill in the public details above, then copy this short prompt into an AI assistant that can browse the web and run code. It will follow the complete public instructions for this audit.
Copying only places the prompt on your clipboard. Pasting it into an AI service shares these values with that provider. A legitimate verification never needs a seed phrase, private key, password, or wallet connection.
Technical details
Open verification specification
Expand this section to inspect the complete, independently reproducible method.
Technical details
Open verification specification
Expand this section to inspect the complete, independently reproducible method.
The exact winner-selection method.
This is the complete method implemented by the tool. It is intentionally specific enough to reproduce in another language or application.
Shared precondition
Authenticate the on-chain commitment.
The RPC must report Ethereum mainnet.
Transaction exists and its receipt status equals 1.
from == to == expectedSigner and value == 0.
commitmentBlock < targetBlock.
Calldata schema
Decode the commitment with no hidden fields.
04Magic0x4f564352 (“OVCR”)416Raffle IDUUID bytes208Target blockUnsigned 64-bit integer284Code countUnsigned 32-bit integer; 1–8,0003232Merkle root32-byte hash649 × countRaffle codesNine UTF-8 bytes eachThe payload is rejected unless its total length is exactly 64 + (9 × codeCount) bytes.
Public future entropy
Require the target block to be finalized.
The committed target block exists and has a 32-byte block hash.
The network’s finalized head is at or beyond the target block.
The target block hash was not available when the earlier commitment fixed the raffle ID, root, target block, and code order.
Selection hash
Encode the exact draw inputs in this order.
domain = keccak256(UTF8("OVCR_WINNER"))selectionHash(counter) = keccak256(abi.encode( bytes32 domain, bytes16 raffleId, uint64 targetBlock, bytes32 merkleRoot, bytes32 targetBlockHash, uint256 counter))The counter begins at 0. All integer values use standard ABI encoding.
Unbiased mapping
Reject the tiny biased tail, then select one index.
R = 2²⁵⁶limit = R − (R mod codeCount)candidate = uint256(selectionHash(counter))while candidate ≥ limit: counter = counter + 1winnerIndex = candidate mod codeCountwinnerCode = sortedCodes[winnerIndex]Indexing note: the algorithm uses a zero-based index. The displayed winner ordinal is winnerIndex + 1.