Provably Fair — and a 0% house edge

The math behind Bustament's crash curve, and a tool to verify it yourself.

The claim

Bustament takes nothing from the crash curve. Every multiplier pays exactly what it should. We make money from tournament buy-in fees, and only from those.

The formula

h = first 13 hex characters of HMAC-SHA256(seed, "crash") crash = floor(100 x 2^52 / (2^52 - h)) / 100

The proof

P(crash >= m) = P(h >= 2^52 (1 - 1/m)) = 1/m

Cashing out at m wins mx with probability exactly 1/m, so expected value is 1.00 at every multiplier.

The comparison

Most crash sites use 99 in that numerator instead of 100. That single digit is their 1% house edge. Bustament uses 100.

Survival table

Cash out atChance of reaching itExpected value
1.5x66.67%1.00
2x50.00%1.00
3x33.33%1.00
5x20.00%1.00
10x10.00%1.00
100x1.00%1.00

A note on 1.00x

Rounds crash at exactly 1.00x about 1% of the time. This is not a forced or rigged bust — it's a natural consequence of the same formula above: whenever the raw computed value lands in [1.00, 1.01), the round crashes immediately. No special case, no separate rule.

The three stages

1. Commitment

Before a tournament's first round, we generate a random terminal seed and hash it forward through a long chain. We publish SHA-256(seed[0]) — the committed hash — before anyone plays a single round.

2. Per-round

Each round uses the next seed in the chain, shown to players as its hash before betting opens. After the round ends, the seed itself is revealed and the crash point can be recomputed from it.

3. Final

When the tournament completes, the terminal seed is published. Anyone can hash it forward the required number of times to derive every round's seed and confirm every crash point that ever ran.

The chain runs backwards: each round's seed is derived by hashing the terminal seed forward multiple times. Revealing a round's seed lets you derive every earlier round's seed, but reveals nothing about rounds that haven't happened yet.

Verify a seed yourself