Skip to content
Tools

Winna Hilo Verifier

Recompute the cards dealt in a Hilo round on Winna from the server seed, client seed and nonce. Same HMAC-SHA256 stream the operator publishes, run in your browser.

Verify one betAnalyze a range
Casino
Game
Examples

Verification Inputs

Recomputes as you type. Nothing leaves your browser.

Hilo Result

Paste the server seed and client seed from the bet. The hilo result appears here as you type.

Algorithm sourceWinna Help Center, Provably Fair: Implementationchecked 2026-09-20

Published 2026-05-21, after our April 2026 audit placed Winna in the VERIFIER_ONLY tier; that audit is superseded for the algorithm question. Same byte stream as Stake (HMAC-SHA256 of clientSeed:nonce:cursor keyed by the server seed, eight uint32 / 2^32 floats per digest) and the same event mapping for the games listed, with two operator differences the verifier applies: Coinflip is float < 0.5 = heads (the opposite of Stake's Flip rule) and the Hilo card table is suit-major from Ace (♠A … ♦K). Dragon Tower is Winna's Pepe Tower, same LEVEL_MAP. Not listed: Slide (hash chain), Plinko Extreme (inverse-transform table), Coin Climber and Blackjack (not implemented here).

How Winna derives a Hilo result

From float to result

Each card is floor(float × 52) into the operator's published 52-card index, from an unlimited deck, so cards can repeat. The index order is the operator's (Stake: 2♦, 2♥, 2♠, 2♣ … A♣; Winna: A♠, 2♠ … K♦), so the same float can name a different card on another casino. One float per card, in stream order.

What to compare

The sequence below should match the cards dealt in your round, in order. Cards you skipped still count as dealt.

Where the seeds are

Open the bet in your history on Winna. The client seed and nonce show immediately. The unhashed server seed appears only after you rotate your seed pair, so rotate first, then verify every bet from the old pair.
The byte stream, Winna
bytes = HMAC_SHA256(key = serverSeed, msg = clientSeed:nonce:round) // round starts at 0float = b0/256 + b1/256^2 + b2/256^3 + b3/256^4 // 4 bytes per floatresult = game event mapping applied to the floats, in order

Other Winna games

Keep what you worked out.

A free account saves your bankroll plans, sessions and the results you run here, on every device. No card, no upsell.

Frequently Asked Questions

Why can the same card appear twice?

The deck is unlimited: every card is an independent draw with the same probability, so repeats are expected.

Does the tie rule affect the cards?

No. The tie rule (higher or same, lower or same) affects whether a guess paid, not which card came next.

Which Winna algorithm does this use?

Winna Help Center, Provably Fair: Implementation, read 2026-09-20. The byte stream is HMAC-SHA256 of clientSeed:nonce:round keyed by the server seed, converted to 4-byte floats, then mapped to the dealt card sequence.

Do my seeds leave the browser?

No. The HMAC and SHA-256 run with the Web Crypto API on your device. The share link carries the seeds only because you copied it.