> ## Documentation Index
> Fetch the complete documentation index at: https://docs.darkmatter.rdytobash.tech/llms.txt
> Use this file to discover all available pages before exploring further.

# Crash Fairness

> Crash Fairness — Dark Matter Protocol on Robinhood Chain.

# Crash — Provably Fair

Crash uses a **commit→reveal** model (the same shape the vfair-games engine uses):
the outcome of every round is fixed and committed **before betting opens**, and the
key needed to verify is published **at settlement**.

## The three phases

### 1. COMMIT — before betting opens

```js theme={null}
seed = keccak(masterPepper : roundId)      // pepper = server-only secret
hash = sha256(seed)                        // stored in crash_rounds.seed_hash
```

The seed hash is committed to the database the moment the round's betting window
opens. The seed itself stays secret until settlement. Because the seed derives from
`roundId` and a stable pepper, every server instance derives the **same** seed —
there is no room for per-instance discretion.

### 2. PLAY — the outcome is derived from the committed seed

```js theme={null}
u = uniform(0,1) from keccak(seed : roundId)
crash = round2(clamp(0.96 / (1 − u), 1, 100))
```

The crash point is a pure function of committed data. Nothing about gameplay (bet
volume, timing, winner count) can influence it.

### 3. REVEAL — at settlement

The raw `seed` and `pepper` are published next to their hash. Anyone can verify:

```
1. sha256(seed) === seed_hash                      // the seed wasn't swapped
2. u = uniform(keccak(seed : roundId))             // re-derive
3. crash = round2(clamp(0.96 / (1 − u), 1, 100))   // matches the settled round
```

## Where to verify

* **In-app:** the Provably Fair popup on every game exposes the verification for the
  round/bet you're looking at — same optics as the vfair games' built-in verify.
* **API:** `GET /api/crash?action=verify-seeds` publishes `(seed_hash, seed, pepper)`
  for the 12 most recently settled bet-bearing rounds.

```json theme={null}
{
  "ok": true,
  "rounds": [
    { "roundId": 481902, "seedHash": "9f2b…", "seed": "0x81aa…", "pepper": "0x5c1e…", "crash": 1.87 }
  ]
}
```

## Why the pepper can't cheat you

The classic fear: "the operator sees my bet and picks a bad seed." Here that's
impossible **by construction**:

1. The seed hash is committed **before betting opens** — before the operator knows
   who bets or how much.
2. The seed is a deterministic function of `(pepper, roundId)` — the operator cannot
   "reroll" a round without changing the pepper, which would break every future
   verification (and any hash comparison against previously published rounds).
3. After reveal, `sha256(seed) === seed_hash` is publicly checkable — swapping the
   seed post-hoc is detectable by anyone.

## Odds table (what the formula implies)

| Cash-out target | Win probability | RTP |
| - | - | - |
| 1.50× | 64.0% | 96% |
| 2.00× | 48.0% | 96% |
| 5.00× | 19.2% | 96% |
| 10.00× | 9.6% | 96% |
| 50.00× | 1.92% | 96% |
| 100.00× | 0.96% | 96% |

The clamp at 100× caps the maximum multiplier; the clamp at 1.00× means \~4% of rounds
crash instantly at 1.00 (the house edge rounds themselves).

Next: [Dice Originals](entropy-games.md).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.