Your browser
Only you know it
When you bet, your browser creates a secret on your device and puts only its fingerprint on chain. The platform can't work out the result when you bet, so it can't pick which bets to take.
Fairness
On WarmUp, every result is decided by your own browser together with the platform. drand, a public randomness network, only steps in when something goes wrong. If the platform tries anything, your browser catches it on the spot.
TestnetWarmUp is currently in its testnet phase. On-chain assets are test tokens.
Three parties, three inputs
Every piece of randomness is fixed before it is used, revealed when it is used, and checked on chain.
Your browser
When you bet, your browser creates a secret on your device and puts only its fingerprint on chain. The platform can't work out the result when you bet, so it can't pick which bets to take.
The platform
Before play starts, the platform puts the fingerprints of a batch of seeds on chain and assigns them to bets in order. Seeds are revealed at settlement and can't be swapped afterwards.
drand · fallback only
Produced jointly by independent organisations around the world, a new round every 3 seconds, with signatures verified on chain. Used only if your secret doesn't arrive in time.
How a round runs
Single-player rounds like CoinFlip settle about 2 s after you tap. Multiplayer rounds like Ladykiller settle about 1–2 s after they close.
Your browser creates your secret and hands over only its fingerprint. The platform's seed is already locked on chain, and the payout is locked the moment you bet.
Each time the platform receives a secret it must sign a receipt: which bet, which secret, what time. Your browser verifies the signature on the spot and keeps it.
The platform reveals its seed. The contract checks that both the seed and your secret match their fingerprints, computes the result with a fixed formula and pays out in the same step.
Using the revealed seed and your own secret, your browser works out what the result should have been, and checks whether your secret was held back.
If your secret doesn't arrive in time, drand is used instead. If the platform doesn't settle, you win after the timeout. There is no way in the contract to void a round.
Assume the platform is the opponent
We design for the worst case: not that the platform is honest, but that it will do anything to benefit itself. Here is what it might try, and what you can do.
Swap in a different seed
It can't happen.
Nothing to do: the contract rejects any seed that doesn't match the earlier commitment.
Never settle the round
Your bet stays on “waiting for result”.
You can: after 10 minutes, tap “claim timeout win” and the bet settles as your win.
Take your secret, sign a receipt, then hold it back when you should have won
The page flags it in red and shows a “claim with receipt” button.
You can: tap the button. The contract checks the receipt, confirms you should have won and pays you from the pool. The platform's own signed receipt is its confession.
Take your secret but refuse to sign a receipt
The page flags it in red and counts how often it happens.
You can: note the bet number and the settlement transaction. Once could be the network; again and again is a cheating signal you can report publicly.
Multiplayer · Ladykiller
In a multiplayer round, the platform could slip in an account it controls, see everyone else's secrets, then decide not to reveal its own. These rules close that gap.
Which seed each round uses is fixed before play starts, and the contract checks every one that is revealed.
When time is up, the contract closes betting on chain first. Your browser only sends its secret after it has seen the “closed” block itself.
The round switches to a drand round published afterwards. The absent player's stake is frozen: it comes back only if they reveal within 7 days, otherwise it goes to the other players in the round.
After the timeout, all the reserve locked for the round is shared among the players by stake. Holding back the seed never pays for the house.
Honest limits
These close as independent validator nodes join.
If the platform takes a secret without signing a receipt, the page catches it, but payment can't yet be forced on chain. With independent validators, your secret can reach the chain through someone else's node.
By keeping its own account absent, the platform can swap a round for a drand redraw once. It can't choose the result, and each time it forfeits the stake or leaves public evidence.
The drand fallback and Ladykiller both rely on chain time. Observer-node monitoring of block times is being built.
The full technical write-up lives at warmupchain.com.
When every round ends, your browser recomputes it for you.