I've been running into sites using similar methods to implement what appears to be a provably fair way to determine outcomes which could be manipulated by casino owners without detection. What makes them different from provably fair games that are actually provably fair is the use of a 'server secret' which is a predefined state of the game (order of cards, a number to be rolled, slot reel positions, etc.) which is then manipulated according to the hashed client + server seeds. The problem is, the 'server secret' is generated without any transparency - completely behind the scenes.
Video Poker Example:
- The order of the cards is determined behind the scenes, this is the 'server secret'.
- The client/server seed is hashed and used to determine which card will be dealt first. (cutting the deck).
The problem is, the possibility of a high paying hand is first determined during the initial shuffle. For example, if the A and K of each suit have more than 10 cards between them - there will be no possibility for a Royal flush to be dealt.
An example of slots from
CryptoSlots.com (
archive):
I think this is kind of a big deal and don't think Casinos should get away with promoting their games as provably fair when they aren't, it's bad for both players and casinos that are actually offering provably fair games. The problem is, the average player just doesn't have a firm grasp of the provably fair concept. They see 'seed' and 'hash' and just assume that that means it must be fair.
Anyway, I'm going to dig through my post history and make a list of all the sites I've come across that are currently doing this. If anyone else comes across some that aren't on the list feel free to let me know and I'll update. Maybe this belongs in scam accusations, I don't know. I'm fine if it gets moved, but I'd prefer it stay here and the discussion revolves more around why certain methods that appear provably fair aren't.
Cryptoslots.com/Slotland.eu (
forum thread - they disappeared from the forum after I brought this up)
Slots: Sever Secret generates 9 outcomes, Server/Client hash determines which of the 9 outcomes is used.
Video Poker: Server Secret determines the order of the cards. Server/Client hash determines where to cut the deck.
Source (
archive)
Cryptsino.io (
forum thread)
Video Poker: Server Secret determines the order of the cards. Server/Client hash determines where to cut the deck.
Dice/3D dice: Server Secret determines "initial roll", Server Client Seed hash determines a number which is added to the server secret.
Slots: Server Secret determines initial state of reels, Server/Client Seed hash adjusts initial state.
source (
archive)
Coins777.com (
forum thread -
owners response)
Video Poker: Server Secret determines the order of the cards. Server/Client hash determines where to cut the deck.
Dice/3D dice: Server Secret determines "initial roll", Server Client Seed hash determines a number which is added to the server secret.
Slots: Server Secret determines initial state of reels, Server/Client Seed hash adjusts initial state.
source (
archive)
Betabit.casino (
forum thread)
Video Poker: Server Secret determines the order of the cards. Server/Client hash determines where to cut the deck.
Don't see an explanation on their site, you have to verify a bet to figure out how it works.
I haven't checked the following casinos myself, but they all have the same verbatim terms that include "When you open the game page the server generates a secret and a seed and Reveals its hash" (Identicle to 3 of the casinos already on the list) . I believe they all use the same script, which is for sale here. (Thank you to Bitinity for posting this in another thread)Satoshicasino.io
bet42bet.com
zilflip.com
safemars.casino
bigplay.casino
cryptodicecasino.com
e-casino-games.com
cindskillgame.com
winrw.de
woowoocasino.com
cryptomegamillions.com
upcasino24.com
milliontoken.games
winning4good.com
zerocryptopoker.com
cgame88.com
cryptocazino.com
slpcasino.com
everestbet.io
moonjackcasino.com
win-star.co
cash10.io
kasinobtc.com
stakeafrica.com
siraca.com
playtoearn.casino
luckytoken.casino
nulled.to