routeEdge() splits it 50/50 between the Event Horizon VIP pots and the LP treasury.
Crash money model
Formula, round clock, bet bounds and money flow.
Crash provably fair
Commit, play, reveal, and how to verify a round.
Dice originals
Mines, Limbo, Plinko and Keno.
Own a share of the house
Every bet across Crash and the dice games feeds one bank. When rounds settle, the realized edge (stakes minus payouts) is booked per token and forwarded on-chain:Crash money model
“Dust Runner” is the flagship Entropy game. Its economy is simple to state and exact: RTP is exactly 99% for every cash-out target.The crash formula
m:
(1 − edge) numerator is what makes every target identical in expectation — there is no “good” or “bad” cash-out point, only variance.
Round clock
Bet bounds
CrashVault custody, so bounds stay conservative out of the box. DUST is deliberately not a bet currency — it is the non-transferable activity score (see Stardust).
The money flow, end to end
1. Deposit (custody). Player deposits intoCrashVault themselves (ETH via depositEth(), USDG via depositToken()). The server sweeps Deposited events and credits the chip ledger minus the 1% deposit fee:
m → payout = amount × m credited instantly in-ledger.
3. Settlement (the bank). When a round settles, realized edge is booked per token:
CrashVault.routeEdge(), split 50/50 as described in Own a share of the house.
Worked examples
Example A — 0.01 ETH bet, cash out at 2.00×:- P(crash ≥ 2.00) = 0.99 / 2 = 49.5%
- Win: 0.02 ETH back (+0.01 profit). Lose: bet.
- EV = 2 × 0.495 × 0.01 = 0.0099 ETH → exactly 99% RTP.
- P(crash ≥ 10) = 0.099 → 9.9%
- EV = 10 × 0.099 × 0.01 = 0.0099 ETH — identical.
Auth & session model
Stateless wallet signature — the client signs once per day:Withdrawal
Player signs(player, token, amount, nonce); relayer submits CrashVault.withdraw. Gasless for the player, signature-enforced on-chain — the server cannot move player funds. See Two Vaults & Custody.
Crash provably fair
Crash uses a commit→reveal model (the same shape the vfair-games engine uses): the outcome of every round is fixed and committed before betting opens, and the key needed to verify is published at settlement.1. COMMIT — before betting opens
roundId and a stable pepper, every server instance derives the same seed — there is no room for per-instance discretion.
2. PLAY — the outcome is derived from the committed seed
3. REVEAL — at settlement
The rawseed and pepper are published next to their hash. Anyone can verify:
Where to verify
- In-app: the Provably Fair popup on every game exposes the verification for the round/bet you’re looking at — same optics as the vfair games’ built-in verify.
- API:
GET /api/crash?action=verify-seedspublishes(seed_hash, seed, pepper)for the 12 most recently settled bet-bearing rounds.
Why the pepper can’t cheat you
The classic fear: “the operator sees my bet and picks a bad seed.” Here that’s impossible by construction:- The seed hash is committed before betting opens — before the operator knows who bets or how much.
- The seed is a deterministic function of
(pepper, roundId)— the operator cannot “reroll” a round without changing the pepper, which would break every future verification (and any hash comparison against previously published rounds). - After reveal,
sha256(seed) === seed_hashis publicly checkable — swapping the seed post-hoc is detectable by anyone.
Odds table (what the formula implies)
Win probability for any target
x is 0.99 / x, so RTP is 99% at every cash-out target. The clamp at 100× caps the maximum multiplier; the clamp at 1.00× means ~1% of rounds crash instantly at 1.00 (the house edge rounds themselves).
Dice originals
The four Entropy dice games (Mines · Limbo · Plinko · Keno) share one money model with Crash: bets are crash chips (sharedcrash_chips ledger, ETH / USDG), debited at bet, credited at settle. Every bet draws a fresh server seed; keccak(seed) is stored alongside the result so any settled row can be audited — recompute the outcome from the stored seed, and the hash proves the row wasn’t rewritten.
Shared economics
Fee routing mirrors the crash side: realized edge accrues in the bank and flows to the same sinks (VIP pots + LP treasury) through
routeEdge().
Mines — single pick, M mines on a 5×5 grid
25 tiles, M mines (1–24). One pick. The more mines on the board, the higher the payout multiplier — but the lower the win chance. All outcomes are verifiable from the stored seed.Limbo — target the multiplier
Pick a target multiplier. If the result meets or exceeds it, you win. The result is capped at 1,000,000×. Higher targets pay more but win less often.Plinko — 16-row binomial drop
16 rows of pegs; the ball drops through and lands in one of 17 buckets. Edge buckets carry the highest multipliers (up to 170×/1000× on high risk); center buckets pay fractions of a stake. Three risk tables (low / medium / high) are available.Keno — pick up to 10 of 40
40 numbers, 10 drawn. Player picks k numbers (1–10). More picks = more chances to hit, but the paytable adjusts accordingly. Top multipliers are hit at extreme tails.Verification walkthrough
For any settled bet:- Fetch the row (API exposes
seedHash,seedafter settle, plus full result meta). - Check
keccak(seed) === seedHash. - Re-run the engine function on
(seed, bet params)— pure, deterministic, and the same code path the settle used. - Confirm the payout matches the derived outcome × the paytable.