Independent verification
National Lotto · Draw #00003
Fri 25 Sept 2026 · 12:51 UTC · Draw ID 9739c338-fb86-48e5-bb08-055ffc09be80
Verification result
VERIFIED
This draw verifies. All 5 checks passed. The published result can be reproduced from the inputs that were fixed before and at the draw.
- Checks passed
- 5 of 5
- Verifier
- 0.0.0
Who computed this verdict
This website's server, by re-running the open verifier over the public record it fetched from the draw API: the plan, the rules document, every committed entry, the revealed seed, the beacon and the signed result. It did not ask the draw engine whether the draw is valid.
The platform's own gate
Before this draw could be marked complete, the platform ran @draw-platform/verifier 0.1.0 over the same public record (1 inclusion proofs) at Fri 25 Sept 2026 · 12:53 UTC and recorded PASSED. A failed gate holds the draw for review; nothing about it is rewritten. This is a fact about the platform's check — the verdict above is this page's own.
The public record
Five questions, answered from what was published for this draw. Open any item to see the exact values and copy them into your own tools.
What was committed before the draw?
ConfirmedTwo things were fixed in advance: the operator's secret seed (published as a commitment before sales opened) and the complete entry set of 1 entries, locked and published when sales closed.
Entry set commitment
A Merkle root over every accepted entry. It prevents entries being added, removed or changed after sales close. It is not an input to the draw randomness.
- Merkle root
- ce33eafbd03133f59340fe4fdc1cdeacf53dfc26976f3c055de24978ed9b4d88
- Entries
- 1
- Schema
- merkle v1
- Published
- 2026-09-25T12:48:02.192Z
- Inclusion proofs checked
- 1 of 1
Seed commitment
A hash of the operator’s secret seed, published before sales opened. The seed itself is revealed only after the draw, so it could not be chosen to fit the entries.
- Seed commitment
- a1a708e4010017bcd040bf3bd4427ac90f3d336448aa1e21b731f933d57dd8a4
When did sales close?
RecordedSales closed at Fri 25 Sept 2026 · 12:48 UTC. The entry set was published after that moment and before any randomness existed.
Timeline
- Sales closed
- 2026-09-25T12:48:00.000Z
- Published
- 2026-09-25T12:48:02.192Z
- Acquired
- 2026-09-25T12:53:01.586Z
What public randomness was used?
ConfirmedA value from a public randomness beacon, taken after sales closed. Nobody — including the operator — could know it while entries were still being accepted.
Public beacon
- Source
- drand Quicknet 52db9ba7…
- Round
- 32512472
- Value
- 2971a2196b09e590977b5d3a08fdc9a08cbb82bc150ab3bf4d8754b6e09a8af3
- Acquired
- 2026-09-25T12:53:01.586Z
- Planned before sales opened
- round 32512472, ≥ 300s after sales close
Entropy context
Draw entropy is derived from the revealed seed, the beacon value and the draw context. Anyone can recompute it from these published values.
- Algorithm
- dp-draw/1 (HMAC-SHA256 over seed ‖ beacon ‖ context)
- Seed commitment
- a1a708e4010017bcd040bf3bd4427ac90f3d336448aa1e21b731f933d57dd8a4
- Revealed seed
- fad8d42de1d1981624b942bdd1575c078d2905cf9e21640e1d6cc46f93d1149d
- Beacon value
- 2971a2196b09e590977b5d3a08fdc9a08cbb82bc150ab3bf4d8754b6e09a8af3
- Draw context
- D00003 / 2026-09-25
- Entropy
- b60b6011014cefca683d14087a0b7489d0c903ccaf8b5235c550f96d76b800e0
- Rules hash
- f77aca65485cca24b717f847c95964dfcf2b379b480d752e98b4fbaee1d15a8e
What result was signed?
ConfirmedThe complete result — the winning numbers in order — was signed before the first one was shown publicly. The signature matches the published result.
Signed result
- Winning numbers
- 12 20 29 38 54 59
- Recomputed by
- this server · @draw-platform/verifier 0.0.0
Signature
- Algorithm
- Ed25519
- Key ID
- 733c9a9e4e76ecebe1fcbef701867f47d167911043632639ea6238f657e0ded7
- Trusted because
- this key id is pinned in the verifier’s own configuration
- Result hash
- fbfcdab5124ea24edfa68cc774e70455f6b5acb8e67b88cc649bb92fb030bb68
- Signature
- 74966dd7b2417fe771727b57ba30eb56a46a3f0bd2e11641345b19695710695a0870e9ff726cb1df41a20ca189d7194aa08ba1a5ef8c63991e8d967f9785710c
- Signed
- 2026-09-25T12:53:01.652Z
How can inclusion be proven?
How to checkEvery accepted entry is a leaf of the published Merkle root. Open one of your tickets to see its inclusion proof: a short chain of hashes that leads from your entry to this root. It proves your entry was in the locked set — it has no part in selecting the winner.
Root to check against
- Merkle root
- ce33eafbd03133f59340fe4fdc1cdeacf53dfc26976f3c055de24978ed9b4d88
- Schema
- merkle v1
Check it yourself
Re-run this verification in your browser
Your browser downloads the published record — the plan, the rules, every committed entry, the revealed seed, the beacon and the signed result — and recomputes the draw with the same open verifier. Nothing is sent anywhere; the server's verdict is not consulted. The signature is checked against 1 key id pinned in this deployment.
Check your own entry
Each of your tickets carries its own inclusion proof against the entry set published above.