How it works
Transparent, limited-entry Bitcoin competitions — designed to be auditable end to end.
- 1
Pick a competition
Each competition has a fixed BTC prize, a fixed entry price, and a hard cap on total entries. Those rules are frozen the moment the competition opens — they cannot be quietly changed afterwards.
- 2
Answer the skill question
Before you can purchase entries you must answer a skill question correctly. Wrong answer, no purchase — that's what makes this a competition of skill.
- 3
Choose your numbers
Pick specific ticket numbers, or take a Lucky Dip and get random ones. Numbers are reserved for you during checkout, and each number can only ever belong to one entrant.
- 4
Pay in Bitcoin
Pay directly in Bitcoin. Entry prices are denominated in BTC and accounted for in exact satoshis. Once your full payment is detected, your ticket numbers remain protected while the Bitcoin network confirms the transaction. Any fiat equivalent shown is indicative only.
- 5
The draw
Once every entry is allocated and all outstanding payments are fully resolved, the competition locks: from that point the set of eligible confirmed tickets can never change. Before the draw, we publish a SHA-256 commitment to that exact ticket set together with a specific future Bitcoin block height — a block that does not exist yet. When that block has been mined and sufficiently confirmed, its hash provides the public, unpredictable input, and our published algorithm derives the winning ticket deterministically. The result is recorded once and cannot be rerun or replaced. Full details below.
- 6
The payout
The prize is paid in Bitcoin. Our goal is for every prize payout to be publicly verifiable on-chain, with the payout transaction published alongside the draw record on the winners page as that reporting is completed for each finished competition.
How our verifiable Bitcoin draw works
The winner is not picked by a hidden random number generator. It is derived deterministically from data we commit to publicly before the deciding Bitcoin block exists.
Frozen tickets
When a competition is locked, only confirmed tickets are eligible — and that set becomes immutable. The number of tickets varies by competition; the draw works with whatever the actual eligible count is.
Entrant set hash
The eligible ticket numbers are sorted into one canonical document (WTB-ENTRANTS-V1) and hashed with SHA-256. Anyone can download the canonical list and reproduce the hash.
Future Bitcoin block
At the same moment, we commit to a specific future Bitcoin block height (currently the observed chain height plus a configured offset, default 6 blocks). That block does not exist yet — so nobody, including us, can know its hash when the entrants are committed.
Draw seed
Once the target block reaches the configured confirmation depth (default 6), its hash is combined with the committed entrant hash, network and height in the WTB-DRAW-V1 document. Its SHA-256 is the draw seed.
Winning index
The seed deterministically selects one zero-based index into the frozen canonical ticket list, using unbiased modular reduction with deterministic rejection sampling.
Winning ticket
The index points to exactly one ticket. Ticket numbers don't need to start at 1 or be contiguous — selection is by position in the canonical list, for any competition size.
Why the draw cannot be changed afterwards
Before the target block exists
- The eligible ticket set is frozen.
- Its SHA-256 commitment is published.
- The target block height is fixed.
Afterwards
- Bitcoin supplies the block hash.
- The algorithm is deterministic.
- Exactly one immutable draw result is recorded.
That means WinTheBitcoin cannot add or remove an entrant, choose a different block, choose a different seed, click “draw again”, or replace the winning ticket. Every one of those changes would either break the published commitment or produce a different, detectable result — and the stored draw record can never be rerun, edited, or deleted.
Verify a draw yourself
Every drawn competition publishes the complete data needed to reproduce its result — you don't need to trust the winner we display:
- Canonical entrant list (downloadable per competition)
- Entrant-set SHA-256 and canonicalization version (WTB-ENTRANTS-V1)
- Bitcoin network
- Target Bitcoin block height and block hash
- Draw algorithm version (WTB-DRAW-V1)
- Draw seed
- Rejection counter
- Zero-based winning index
- Winning ticket number
The canonical entrant list for a committed competition is available from that competition's page (the “canonical entrant list” link). Hash it with SHA-256, confirm it matches the published entrant-set hash, then follow the algorithm below to recompute the winning index and ticket.
Technical verification (for advanced users)
1 · Canonical entrant document — WTB-ENTRANTS-V1
UTF-8 text, one line per row, a newline between every line and a final trailing newline. Eligible confirmed ticket numbers are sorted ascending:
WTB-ENTRANTS-V1 competition:<competition slug> count:<number of eligible tickets> tickets: <ticket number, one per line, ascending>
entrant_set_hash = SHA-256 of that document, lowercase hexadecimal.
2 · Canonical draw document — WTB-DRAW-V1
WTB-DRAW-V1 network:<bitcoin_network> target_block_height:<height> entrant_set_hash:<lowercase SHA-256> block_hash:<lowercase Bitcoin block hash>
- UTF-8; a newline between every line; a final trailing newline.
- The block hash is the conventional 64-character hexadecimal string displayed by Bitcoin Core and block explorers, lowercase. The bytes are not reversed.
- draw_seed = SHA-256 of the document, lowercase hexadecimal.
- The seed is interpreted as an unsigned 256-bit big-endian integer.
3 · Unbiased winner selection
N = eligible_count (competition-specific)
R = 2^256
limit = floor(R / N) × N
x = draw_seed as unsigned 256-bit big-endian integer
if x < limit:
winning_index = x mod N (zero-based)
else:
deterministic rejection sampling (below)A simple modulo operation can introduce an extremely small mathematical bias when N does not divide 2256 evenly, so we use deterministic rejection sampling to remove even that theoretical bias. It is fully deterministic and publicly reproducible: for a counter starting at 1, hash the following document and repeat with the next counter until the candidate is below the limit:
WTB-DRAW-REROLL-V1 draw_seed:<original draw_seed hex> counter:<counter>
(UTF-8, newline-separated, final trailing newline; the candidate is the SHA-256 of the document, again read as an unsigned 256-bit big-endian integer.) The published rejection counter records which candidate was accepted — 0 means the original seed itself. Then winning_index = candidate mod N.
4 · Winning ticket
The zero-based winning index selects one position in the canonical ascending ticket list from step 1. Ticket numbers need not start at 1 or be contiguous, and the eligible count is whatever that competition actually locked with — the algorithm carries no fixed competition size.