Every official round commits to a secret seed before entries open and reveals it when the hunt begins. With the revealed seed and the frozen participant list, anyone can recompute who became the Seeker — in the browser, with no trust in us.
seedCommit published with the round
Round announced
Players qualify through Fomo
Entries open
Qualified profile ids are locked and sorted
Entries close
secretSeed published; roundSeed + Seeker derived
~60 s before start
Anyone recomputes everything here
Forever
Isomorphic code — the server and this website run the same functions. No Math.random anywhere.
= 32 cryptographically random bytes, hex encoded (0x + 64 hex chars)Generated when the round is created. Stored encrypted; never shown before the reveal.
= 0x + hex( SHA256( bytes(secretSeed) ) )Published on the round page the moment it's announced — before anyone can enter.
= participants' fomoProfileIds sorted by UTF-16 code unit order (a < b), duplicates rejectedThe qualified entrants, frozen when entries close. Never connection order, never locale sorting.
= 0x + hex( SHA256( utf8( "fomoseek-fair-v1\n" + lower(secretSeed) + "\n" + roundId + "\n" + ordered.join("\n") ) ) )Mixes the secret with the exact participant list, so the seed can't be chosen to favour anyone.
= uint256(roundSeed) mod ordered.lengthThe Seeker is ordered[seekerIndex].
One seed drives every random choice in the round, through labelled deterministic streams.
The seed is fixed before entries open. Changing it would break the published commitment.
The roundSeed depends on the whole frozen participant list. Joining late or reordering changes nothing you control.
Events are hash-chained and signed by the match server; the website rejects any result whose chain doesn't reproduce.
No official rounds yet. The first round's commitment appears here the moment it's announced.
= block_i = SHA256( bytes(roundSeed) || utf8(label) || u32be(i) )Consumed as big-endian u32 words. Integers in [0, n) use rejection sampling — no modulo bias.
= "spawn", "map-variant", "zones"Independent streams for spawn order, the round's map variant and the overtime zone order.
= Fisher–Yates over [0..n-1] using HashDRBG(roundSeed, "spawn"), i from n-1 down to 1, j = int(i+1)Who spawns where.
= h[n] = SHA256( h[n-1] || canonical(event[n]) ), h[-1] = 32 zero bytesEvery match event is hash-chained; the server signs the final hash with Ed25519. Edit one event and the chain breaks.