Skip to main content

Verify this draw

Win A VTech Toy Story Explore & Learn LilyPad #1 was drawn on 13 Aug 2026. The winner was Delyth J. from Sesnsea with ticket #1.

Method

Verified auto-draw

Tickets in the draw

46

Winning ticket

#1

Winner's odds

1 in 46

In plain English

Before entries closed, we locked in a secret number and published a “fingerprint” of it (a one-way SHA-256 code) that proves we couldn’t change it later. After entries closed, that number, mixed with a public source of randomness that nobody controls, picked the winning ticket. So the result couldn’t be set in advance or predicted by anyone. The steps further down let you re-run it and land on the same ticket yourself.

How this draw is provable

Before entries closed we published a commitment: a one-way fingerprint (SHA-256) of a secret random seed. After the draw we revealed the seed. Because the commitment was public before entries closed, the seed could not have been changed afterwards to draw a particular ticket.

The draw also folds in a public randomness beacon (drand, the League of Entropy) whose value is only published after entries close. Anyone can re-fetch the exact beacon round below and confirm the same value went into the draw.

Commitment (published before entries closed)
9ce501020e603c91be031d2e8ef867090ee09f1e3726aa8b34e2f59dbffe2f83
Revealed seed (published after the draw)
f1353c08cd83dcb9fce5fd844b3a2139033fc61cc312777080573a174809d4dc
Beacon round (emitted after close) & its public value
Round 6,373,947 on the drand chain 8990e7a9aaed2ffed73dbd7092123d6f289930540d7651336225dc172e51b2ce
ed4d1fe0096714d32ac67213ccbeddfbc9f42654ad7e13aa22c16defc2c15280
Re-fetch it: curl https://api.drand.sh/8990e7a9aaed2ffed73dbd7092123d6f289930540d7651336225dc172e51b2ce/public/6373947

Check it yourself

1. The seed matches the commitment

Run SHA-256 on the revealed seed - it equals the commitment above. For example, in a terminal:

printf '%s' 'f1353c08cd83dcb9fce5fd844b3a2139033fc61cc312777080573a174809d4dc' | sha256sum

2. The seed and the beacon draw the winning ticket number

Every one of the 46 tickets (numbered 1 to 46) went into this draw. The winner is drawn from the locked-in seed mixed with the post-close beacon value shown above - both are in the $msg below. The seed was committed before entries closed, and the public beacon that decides the winner didn't exist until after - so the result couldn't be set in advance or predicted. Recompute it and you'll get ticket #1:

$seed  = 'f1353c08cd83dcb9fce5fd844b3a2139033fc61cc312777080573a174809d4dc';
$total = 46;                       // tickets in the draw (numbers 1..46)
$msg   = 'draw:019fce78-7dc8-7397-978e-6c6f95a17769:'.$total.':ed4d1fe0096714d32ac67213ccbeddfbc9f42654ad7e13aa22c16defc2c15280';   // note: the trailing value is the drand beacon above
$span  = 1 << 60;                          // 60-bit space
$limit = intdiv($span, $total) * $total;   // reject above this to remove bias
$i = 0;
do {
    $n = (int) hexdec(substr(hash_hmac('sha256', $msg.':'.$i, $seed), 0, 15));
    $i++;
} while ($n >= $limit);
echo ($n % $total) + 1;                     // => winning ticket #1

3. Ticket #1 belongs to the winner

That ticket number is held by exactly one entry - Delyth J. from Sesnsea. We publish a fingerprint of every ticket number in the draw, so the set of numbers can't be altered after the fact, and we hold the full list in our tamper-evident audit trail, available to the Advertising Standards Authority on request.

Ticket-numbers fingerprint
e9987578c1b7724ed4a9cf49f355c09600e9e4c04719154da85dd82d54f088a6

How ticket numbers are assigned

On this competition you don’t choose your ticket number, and it isn’t simply the next number in order. When you buy, the system gives you a number using a secret shuffle that was set when the competition opened, before anyone had bought a ticket, and can’t be changed after.

Because that shuffle is secret and gives everyone a different number:

  • Two people can never end up with the same number.
  • Nobody, not you and not us, can guess which number a purchase will get. On this draw the number itself isn’t what picks the winner - that’s the draw above, which nobody can predict.
  • Your number is fixed the instant you buy, and recorded straight away.

We keep the shuffle secret so no one can work out in advance which number a purchase will get, which is what stops anyone targeting a winning ticket. Every number that’s given out still appears in the competition’s entrants list, so the numbers in play are public and can’t be quietly changed later.

You can see them: every entry and its ticket number is listed on the competition’s entrants page.

Prove the shuffle yourself

When the competition opened we published a fingerprint of the secret shuffle key, so it’s on record as fixed before anyone bought:

Shuffle-key fingerprint (published at open)
83fbc459069da267c4f18bb0d0383f85804acd269a8fb8f21740f8263f9279ee
The shuffle key itself (revealed now the competition has ended)
CboVK5iz9VlgMojdI1GlGO4flZjuzq81W2Xjq57h

First check the key matches the fingerprint published at open, then re-run the shuffle for yourself: feed each position 1, 2, 3… through it and you get the 46 ticket numbers in the pool, each exactly once. If it matches the fingerprint and produces a complete set with no repeats, the numbers were genuine and untouched.

Show the method
// 1. the key matches the fingerprint published at open:
printf '%s' 'CboVK5iz9VlgMojdI1GlGO4flZjuzq81W2Xjq57h' | sha256sum        // => 83fbc459069da267c4f18bb0d0383f85804acd269a8fb8f21740f8263f9279ee

// 2. re-run the shuffle: position -> ticket number
$seed   = 'CboVK5iz9VlgMojdI1GlGO4flZjuzq81W2Xjq57h';
$domain = 46;   // the pool the numbers are shuffled within
$prf = fn($v,$r) => (int) hexdec(substr(hash('sha256', "$seed:$r:$v"), 0, 8));
$permute = function(int $pos) use ($domain, $prf) {
    $half = (int) ceil(((int) ceil(log($domain, 2))) / 2);
    $mask = (1 << $half) - 1;
    $x = $pos - 1;
    do {
        $l = ($x >> $half) & $mask; $r = $x & $mask;
        for ($i = 0; $i < 4; $i++) { $n = $l ^ ($prf($r, $i) & $mask); $l = $r; $r = $n; }
        $x = ($l << $half) | $r;
    } while ($x >= $domain);
    return $x + 1;
};
// $permute(1), $permute(2), ... are the ticket numbers, in the order they were issued.

See how all our draws work on our fairness & security page, or back to all winners.

?