Raffles
Enter for free, watch the live draw, and check every result yourself.
Past raffles
Drawntest
1 prizes
Draw Fri, 9 October 2026 at 15:35
- Showcase: Murders at Karlov Manor · Rainbow FoilT-0001 J***l R.
How we keep it fair
We use drand, a public random number service run by the League of Entropy (Cloudflare, universities and others). Every 3 seconds it publishes a new random number, called a round. Nobody can know a round's number before its time — not even us.
- Raffle opens: we roll a secret number and publish its fingerprint. Like a sealed envelope — you see the envelope, not what's inside, and we can't swap it later.
- Entry closes: we freeze the masked ticket list and publish it with its fingerprint and the exact time. Five minutes later drand publishes the announced round's number. The list must be frozen before that round — if it isn't, we announce a new, later round here first.
- Mix: secret + drand number + ticket-list fingerprint are mixed into one draw seed.
- Each prize: the seed becomes a big number; the remainder when dividing by the number of tickets still in is the winning position in the list. Afterwards we reveal the secret so anyone can redo it.
Why nobody can cheat, us included
- The secret is sealed before anyone enters (the fingerprint proves it).
- The drand number doesn't exist yet while people can enter, nor when the ticket list is frozen (the times are published).
- The ticket list is sealed too: adding fake tickets changes the result unpredictably, so it can't steer a winner.
- Re-running a prize needs a new drand round that is announced here before it exists, and leaves out everyone who has already won — so a re-run can't be used to pick someone.
The maths, for the curious
commitment = sha256(serverSeed)
entryHash = sha256(ticketLines.join("\n"))
beaconRound = first drand round at or after entryClose + 5 min
frozenAt < time(beaconRound) (else: a new, later round is announced)
seed = HMAC-SHA256(serverSeed, drandRandomness + ":" + entryHash)
for each prize unit (prizes in order, units 1..n):
unitKey = prizeId + ":" + unit + ":" + run
attempt = 0, 1, …
r = HMAC-SHA256(seed, unitKey + ":" + attempt) as a 256-bit number
accept if r < floor(2^256 / n) · n (n = tickets still in)
winner = tickets[r mod n]
re-run of a unit: new announced round, seed from its randomness,
every ticket that has won any earlier run is outdrand quicknet (chain 52db9ba70e0c…). If the big number lands in the tiny leftover range above the last full multiple of the ticket count, it is hashed again — that keeps every ticket at exactly 1 in n.