Provably Fair CS2 Case Opening
Every case, battle, upgrade, coinflip, Plinko drop and Chicken crossing on CS2Bolt is decided by a roll you can recalculate yourself. We lock in the server’s secret before you play, mix in a seed you control, and reveal the secret afterwards so you can check the result was not changed.
Sign in to see your own rounds and seedsHow a result is decided
- The server commits to a secret
Before your round, CS2Bolt generates a random server seed and shows you only its SHA-256 hash. The hash works like a sealed envelope: it proves the seed already exists without revealing it.
- Your seed and the round number are mixed in
The roll combines the server seed with your client seed, the nonce (your round counter), the game and the round’s details, using HMAC-SHA256.
- The secret is revealed and checked
After the round the server seed is published. Hash it yourself: if it matches the hash you were shown, the seed was never swapped, and recalculating the roll gives exactly your result.
message = clientSeed + ":" + nonce + ":" + game + ":" + context
digest = HMAC_SHA256(key = serverSeed, message)
roll = first 13 hex characters of digest ÷ 16¹³ → 0 ≤ roll < 1
Thirteen hex characters are 52 random bits, which a browser can hold exactly, so the roll is identical on every device.
How each game uses the roll
Cases
The roll picks an item by its odds. Every item owns a slice of the range from 0 to 1 that matches its drop chance; the item whose slice contains the roll is the one you win.
context = the case’s URL name, e.g. afterpartyCase Battles
One server seed is shared by the whole battle. All players’ client seeds are joined with “:”, and each seat in each round gets its own nonce, so every opening is a separate roll that nobody can steer.
nonce = round × players + seat · context = battle numberUpgrader
You win when the roll lands inside the green zone. The zone starts at the offset shown with the round and is as wide as your win chance, wrapping around from 1 back to 0.
win if the roll is in [offset, offset + chance)Coinflip
Both players’ client seeds are combined as creator|joiner. The creator wins when the roll is below their share of the pot, so a bigger stake means a proportionally bigger chance.
creator wins if roll < creator stake ÷ total potPlinko
The roll is turned back into its 52 random bits. Each row of pegs uses the next bit: 0 goes left, 1 goes right. The number of rights is the slot the ball lands in.
context = plinko:rows:riskChicken Crossing
One roll is made when you start. Each lane has a safety threshold for your difficulty; the chicken is hit at the first lane where the roll is at or above that threshold.
lose at the first lane where roll ≥ thresholdVerify a round
Paste the values from any round and it is checked in your browser. Sign in with Steam to pick one of your own rounds with one click instead.
Enter values manually
Check it without this website
Run this with Node.js, replacing the values with your round’s:
node -e "const c=require('crypto');const d=c.createHmac('sha256','SERVER_SEED').update('CLIENT_SEED:NONCE:GAME:CONTEXT').digest('hex');console.log(d,parseInt(d.slice(0,13),16)/2**52)"Questions
Can CS2Bolt change the result after I place a bet?
No. The fingerprint (SHA-256 hash) of the server seed is shown before you play. If the seed revealed afterwards were different, its hash would not match the one you saw, and the verifier below would flag it.
Why should I set my own client seed?
Your client seed is mixed into every roll. The server seed is locked in before you choose or change yours, so the site cannot have picked a server seed that produces a particular result with it.
What is the nonce?
A counter that goes up by one with every round you play. It makes each roll different even when the seeds are the same, and it lets you check that no rounds were skipped or replayed.
Why is the server seed new every round?
CS2Bolt reveals the server seed as soon as a round is settled so you can check it straight away. A revealed seed can never be used again, so a fresh one is committed for your next round.
Do I have to trust this page to verify a round?
No. The check is standard HMAC-SHA256, so any independent tool gives the same answer. The verifier on this page runs entirely in your browser and sends nothing to our servers.