Every spin
in the open.
Arcade does not ask you to trust it. It publishes enough that you do not have to.
Arc has no VRF. So we did not claim one.
Chainlink is integrated with Arc, but that integration covers CCIP, Data Feeds, Data Streams and Proof of Reserve — not VRF. A lot of onchain games would call a blockhash-derived number “provably fair” and move on. Arcade uses an explicit commit–reveal construction instead, and states exactly what it does and does not guarantee.
The randomness source sits behind a swappable adapter interface. If a reputable VRF arrives on Arc, it can be dropped in without redeploying the machines, the vault or the registry — and without touching any spin already in flight.
Pay. Lock. Randomize. Settle. Verify.
Before any spin exists
The operator publishes a batch of commitments — each one keccak256(seed, salt) — onchain. They are consumed in strict ascending order, one per spin, exactly once. A seed that already exists cannot be adapted to an outcome that has not happened yet.
- 01
Pay
One signature in native USDC. Price, machine and version are frozen into the spin.
- 02
Lock
The next pre-published commitment is consumed, bound to you and to a future block.
- 03
Randomize
The sealed seed is revealed and hashed with the request entropy and anchor blockhash.
- 04
Settle
The band and amount are derived, reserved in the vault, and sent to your wallet.
- 05
Verify
Every input is public. Recompute the word yourself, or ask the contract to.
randomWord = keccak256(
seed, // sealed before your spin, revealed after
salt, // sealed with it
requestEntropy, // your address, spin id, machine version, config hash
blockhash(anchorBlock) // a block that did not exist when you signed
)
tierIndex = keccak256(randomWord, "tier") % totalWeight -> weighted band
amount = keccak256(randomWord, "amount") % (span + 1) -> within the bandThe band and the amount are drawn from independent domains of the same word, so they are uncorrelated. Both are pure functions of public data, which is why settlement is permissionless: whoever calls it, the answer is identical.
The operator cannot choose your outcome
The seed was committed before your spin existed, and the anchor block had not been mined. Revealing anything other than the committed pre-image fails the onchain hash check.
You cannot predict your outcome
The seed stays hidden behind its commitment until after your spin is accepted, and the anchor blockhash does not exist when you sign.
There are no re-rolls
Commitments are consumed in strict ascending order, one per request, exactly once. A revealed word is immutable and no admin function can overwrite it.
The price and table are frozen
Accepting a spin copies the price, machine id and machine version into immutable storage. Publishing a new version cannot change a spin already in flight.
Anyone can recompute the result
The revealed seed, salt, request entropy and anchor blockhash are all public. The contract exposes a pure recompute function so you can check its own stored answer.
Selective withholding
Between the anchor block and the reveal, the operator can compute your outcome and could choose not to publish it. That cannot change a result — only deny one.
The mitigation is mechanical, not a promise: once the reveal window closes, anyone can report the miss. The request is marked failed, your spin price is refunded in full, and a penalty is slashed from the operator's posted bond and paid to you. Missed reveals are counted onchain and published.
No audit
These contracts have not been independently audited. They ship with unit, fuzz and invariant tests — including a solvency invariant exercised across thousands of randomised call sequences — but tests are not an audit and are not presented as one.
The animation decides nothing
The orbit animates toward a result that is already fixed onchain. Close the tab mid-spin and the outcome is unchanged and still settleable — by you, or by anyone.
Where to look.
- Machine manager
- 0x69c4aa34cB47Dc4d0E6d4a39C39F7278B333AAB7
- Prize vault
- 0x13041baE3da3616E432314D3e0F562b87aF66E55
- Reward registry
- 0xE639aD6D6e81c997AC043cc7dac95d7223aF7fE0
- Discovery
- Reading…
Each is the configHash that publishVersion sealed onchain — a keccak256 over the machine id, version, spin price, effective block and the full reward table. Read it from the contract yourself and compare.
The ledger.
The awkward ones.
Why not Chainlink VRF?
Because it is not available on Arc. Chainlink’s Arc integration covers CCIP, Data Feeds, Data Streams and Proof of Reserve — not VRF. Rather than call a blockhash scheme “provably fair”, Arcade ships an explicit commit–reveal construction and states its assumptions. The randomness adapter is a swappable interface, so a reputable VRF can be dropped in without redeploying the machines, the vault or the registry.
What is the residual trust assumption?
Selective withholding. Between the anchor block and the reveal, the operator can compute the outcome and could choose not to publish it. That cannot change a result, only deny one. After the reveal window closes, anyone can report the miss: the request is marked failed, you are refunded in full, and a penalty is slashed from the operator’s bond and paid to you. Missed reveals are counted onchain and published.
Could the operator grind the seed to pick a favourable outcome?
No. Commitments are published in advance and consumed in strict ascending order, so the operator cannot choose which seed serves which spin. The final word also mixes in the hash of a block that did not exist when the seed was committed, so a seed cannot be precomputed to target an outcome.
Could I predict my own outcome before spinning?
No. The seed is hidden behind its commitment hash until after your spin is accepted, and the anchor blockhash does not exist yet when you sign. Choosing when to submit gains you nothing, because you cannot see the seed.
Does the animation decide anything?
No, and this matters. The orbit animation reads a result that is already fixed onchain. It cannot influence, delay or reinterpret it. If you close the tab mid-spin, the outcome is unchanged and still settleable by anyone — including you, later.
Have the contracts been audited?
No. The contracts in this repository have not been independently audited. They ship with unit, fuzz and invariant tests, and the solvency invariant is exercised across thousands of randomised call sequences, but that is not a substitute for an audit and is not presented as one.


