How our draws work
We use a commit-and-reveal system. That means we lock in the randomness before anyone buys a ticket, publish proof of it, and reveal it afterwards so anyone can check we didn't change anything.
Main draws
- Before launch we generate a random secret seed and publish its SHA-256 hash on the competition page.
- At the draw we take every confirmed ticket number, sort them, join them with commas and hash the list (the entries hash).
- The winning position is
HMAC-SHA256(seed, entries hash)read as a number, modulo the number of tickets. The ticket at that position in the sorted list wins. - After the draw we reveal the seed. Check its hash matches the one published at launch, download the entry list, and recompute the winner yourself.
Instant wins
Instant-win numbers are chosen at random and sealed before a competition goes live. We publish a hash of every number and prize plus a secret salt. When the competition closes, we reveal the salt and any unclaimed numbers so you can confirm the list never changed.
Check a main draw yourself (Python)
import hashlib, hmac
seed = "REVEALED_SEED"
tickets = sorted([...]) # every ticket number from the entry list
print(hashlib.sha256(seed.encode()).hexdigest()) # matches the published hash
digest = hashlib.sha256(",".join(map(str, tickets)).encode()).hexdigest()
i = int(hmac.new(seed.encode(), digest.encode(), hashlib.sha256).hexdigest(), 16) % len(tickets)
print("winning ticket:", tickets[i])
Check instant wins
import hashlib
salt = "REVEALED_SALT"
prizes = [(17, "£10 Credit"), (342, "£50 Credit")] # every number:prize, sorted by number
body = ",".join(f"{n}:{t}" for n, t in sorted(prizes))
print(hashlib.sha256(f"{salt}|{body}".encode()).hexdigest()) # matches the sealed hash
