DBX Dream Draws

How our draws work

We use a commit-and-reveal system. That means we lock in the randomness before anyone buys a ticket, publish proof of it, and reveal it afterwards so anyone can check we didn't change anything.

Main draws

  1. Before launch we generate a random secret seed and publish its SHA-256 hash on the competition page.
  2. At the draw we take every confirmed ticket number, sort them, join them with commas and hash the list (the entries hash).
  3. The winning position is HMAC-SHA256(seed, entries hash) read as a number, modulo the number of tickets. The ticket at that position in the sorted list wins.
  4. After the draw we reveal the seed. Check its hash matches the one published at launch, download the entry list, and recompute the winner yourself.

Instant wins

Instant-win numbers are chosen at random and sealed before a competition goes live. We publish a hash of every number and prize plus a secret salt. When the competition closes, we reveal the salt and any unclaimed numbers so you can confirm the list never changed.

Check a main draw yourself (Python)

import hashlib, hmac
seed = "REVEALED_SEED"
tickets = sorted([...])  # every ticket number from the entry list
print(hashlib.sha256(seed.encode()).hexdigest())  # matches the published hash
digest = hashlib.sha256(",".join(map(str, tickets)).encode()).hexdigest()
i = int(hmac.new(seed.encode(), digest.encode(), hashlib.sha256).hexdigest(), 16) % len(tickets)
print("winning ticket:", tickets[i])

Check instant wins

import hashlib
salt = "REVEALED_SALT"
prizes = [(17, "£10 Credit"), (342, "£50 Credit")]   # every number:prize, sorted by number
body = ",".join(f"{n}:{t}" for n, t in sorted(prizes))
print(hashlib.sha256(f"{salt}|{body}".encode()).hexdigest())  # matches the sealed hash