Bitcoin Forum
October 04, 2026, 10:59:22 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: [Edit: Resolved] Winna is not provably fair  (Read 911 times)
Zwei
Legendary
*
Offline

Activity: 2170
Merit: 1449


Trêvoid █ No KYC-AML Crypto Swaps


View Profile
February 11, 2026, 07:24:00 PM
Last edit: February 12, 2026, 12:45:52 PM by Zwei
Merited by AHOYBRAUSE (1)
 #21

Oh the guy with the winna ad campaign is defending winna

Im sure its objective.  
i don't read what he said as him defending them at all. he is actually being objective, and what he said is all true.
if that bet was fake, winna wouldn't make it disappear from the wins tab, and the player (jaketherake172) would not have opened a complaint on casino.guru because they nuked his account after that.

but we are getting off topic here. this thread is about winna fake provably fair system, so let's keep the discussion on that.

VeniVidiV
Member
**
Offline

Activity: 73
Merit: 10


View Profile
February 13, 2026, 09:05:06 PM
 #22

Winna owners ignore this topic anywhere it is brought up online.


I wonder why?
bennettwinna
Copper Member
Jr. Member
*
Offline

Activity: 33
Merit: 4


View Profile WWW
March 09, 2026, 04:38:29 PM
 #23

Hello everyone,

I’ve just seen this thread and wanted to respond. We appreciate discussions around transparency and fair play, as these are core principles for us. However, I do not agree with the way some of these technical points are being presented in a manner that implies malicious intent on our side. It is worth noting that competitive dynamics in the crypto casino space can sometimes influence how these discussions emerge. Nevertheless, we prefer to focus on the technical aspects and verifiable facts.

The Winna Originals fairness system has never been tampered with, and every game result has always been generated fully randomly.

Quote
-- Winna's server seed hashing implementation is not provable, or provably fair.

The previous implementation used HMAC-SHA256 to generate the server seed hash. We have now migrated to using a simple SHA256 hash to align with the implementations used by platforms such as Stake or Shuffle.

It is important to clarify that the hashing algorithm itself does not determine the fairness of the system. The purpose of the hash is to commit to the server seed before gameplay begins. Provable fairness is achieved through the combination of the server seed, client seed, and nonce, which together determine the final game result. As long as the server seed is revealed after the seed rotation and matches the previously published hash, users can independently verify that outcomes were generated correctly. Using HMAC-SHA256 instead of SHA256 therefore had no impact on the randomness or fairness of the seed pair.

Quote
-- Winna's zero-bet nonce disuse is suspicious and the code being used in the backend should be audited by a third party, as all steps are not externally repeatable.

This point is somewhat more complex. We are still working on properly addressing $0 bets, as doing so requires changes to how these bets are stored and how the seed incrementing process is handled internally. These adjustments involve larger architectural changes, but we expect this to be implemented by early Q2 2026.

Our backend has already undergone an in-depth audit previously. Most recently, the system was tested in 2025 by Cyrex Enterprise (cyrexenterprise.com). In addition, we are planning to open-source the Originals codebase in Q2 2026 and have the games independently tested again so the results can be published publicly.

Quote
-- Winna not allowing you to pick your own client seed is a clear violation of standard provable fairness practices.

This has already been addressed. Users are now able to choose their own client seed on Winna.

Quote
-- Winna's laggy originals imply excessive processing in the backend, or highly unoptimized code.

Since we are one of the few casinos that build all Originals fully in-house rather than relying on third-party providers, some performance issues occurred as a result of the rapid growth we have experienced over the past period. These issues have already been partially addressed, and our team is continuing to improve performance further in the coming months.

Quote
-- Winna has ties to a recent rug which is clear from even minor snooping in the DNS and page designs/structure.

We have publicly stated before that we have no connection to this site, and that remains the case.

Quote
-- Some questionable affiliate practices which are not the core of this complaint.

Without further details, this appears to be an unsupported claim. I would appreciate more information so that we can properly review and address any concerns.

Anyone is welcome to independently verify game outcomes through the provably fair system. The purpose of this system is precisely to allow users to reproduce results and confirm that no manipulation has occurred.

Transparency and trust are important to us, and we will continue improving our systems and sharing more information as we move forward.
Paney_Thrill
Newbie
*
Offline

Activity: 9
Merit: 3


View Profile
March 10, 2026, 11:37:55 AM
 #24

It is a fake bet from a fake account in order to get people to start chasing similar hits and just pour money into Winna.

Thrill (the casino that Ayezee advertises) is exactly the same, even worse than Winna.

I came across this thread, and although the accusation is not about us, I had to respond.


We consume nonce and cursors on zero bets, and we also allow the players to choose their own client seed.

Here is more information :

https://intercom.help/thrill/en/collections/14974650-provably-fair
https://intercom.help/thrill/en/articles/12117573-provably-fair-implementation

Therefore, your accusations are completely unfounded.
If you think otherwise, feel free to post proof or create a thread altogether with it.


All the best,
The Thrill Team




stakestatsSeal
Newbie
*
Offline

Activity: 1
Merit: 0


View Profile
March 10, 2026, 09:26:45 PM
 #25

Hello everyone,

I’ve just seen this thread and wanted to respond. We appreciate discussions around transparency and fair play, as these are core principles for us. However, I do not agree with the way some of these technical points are being presented in a manner that implies malicious intent on our side. It is worth noting that competitive dynamics in the crypto casino space can sometimes influence how these discussions emerge. Nevertheless, we prefer to focus on the technical aspects and verifiable facts.

The Winna Originals fairness system has never been tampered with, and every game result has always been generated fully randomly.

Quote
-- Winna's server seed hashing implementation is not provable, or provably fair.

The previous implementation used HMAC-SHA256 to generate the server seed hash. We have now migrated to using a simple SHA256 hash to align with the implementations used by platforms such as Stake or Shuffle.

It is important to clarify that the hashing algorithm itself does not determine the fairness of the system. The purpose of the hash is to commit to the server seed before gameplay begins. Provable fairness is achieved through the combination of the server seed, client seed, and nonce, which together determine the final game result. As long as the server seed is revealed after the seed rotation and matches the previously published hash, users can independently verify that outcomes were generated correctly. Using HMAC-SHA256 instead of SHA256 therefore had no impact on the randomness or fairness of the seed pair.

Quote
-- Winna's zero-bet nonce disuse is suspicious and the code being used in the backend should be audited by a third party, as all steps are not externally repeatable.

This point is somewhat more complex. We are still working on properly addressing $0 bets, as doing so requires changes to how these bets are stored and how the seed incrementing process is handled internally. These adjustments involve larger architectural changes, but we expect this to be implemented by early Q2 2026.

Our backend has already undergone an in-depth audit previously. Most recently, the system was tested in 2025 by Cyrex Enterprise (cyrexenterprise.com). In addition, we are planning to open-source the Originals codebase in Q2 2026 and have the games independently tested again so the results can be published publicly.

Quote
-- Winna not allowing you to pick your own client seed is a clear violation of standard provable fairness practices.

This has already been addressed. Users are now able to choose their own client seed on Winna.

Quote
-- Winna's laggy originals imply excessive processing in the backend, or highly unoptimized code.

Since we are one of the few casinos that build all Originals fully in-house rather than relying on third-party providers, some performance issues occurred as a result of the rapid growth we have experienced over the past period. These issues have already been partially addressed, and our team is continuing to improve performance further in the coming months.

Quote
-- Winna has ties to a recent rug which is clear from even minor snooping in the DNS and page designs/structure.

We have publicly stated before that we have no connection to this site, and that remains the case.

Quote
-- Some questionable affiliate practices which are not the core of this complaint.

Without further details, this appears to be an unsupported claim. I would appreciate more information so that we can properly review and address any concerns.

Anyone is welcome to independently verify game outcomes through the provably fair system. The purpose of this system is precisely to allow users to reproduce results and confirm that no manipulation has occurred.

Transparency and trust are important to us, and we will continue improving our systems and sharing more information as we move forward.

Thanks for the response addressing the previous concerns Bennett; we will work through these and check that they follow the general-best practices for Provable Fairness, and I will have Ruby modify the post if we believe they have all been addressed.

Thanks!
Seal
StakeStats
foxymethoxy (OP)
Newbie
*
Offline

Activity: 15
Merit: 8


View Profile
March 13, 2026, 06:12:38 AM
 #26

Thread updated.
robelneo
Legendary
*
Offline

Activity: 4116
Merit: 1308


Bitz.io Best Bitcoin and Crypto Casino


View Profile WWW
March 13, 2026, 11:06:39 PM
 #27

Thread updated.

It's good that you updated this thread after your concern was resolved. It's the right thing to do; many accusations or questions about the platform were resolved, but the accuser failed or doesn't want to update the thread as resolved. It's better to lock this thread as the concern is addressed

███ 
███████▄▄███▄███▄
███▄▄████████▌████▄
▄██████████████▐███▌
██▄███████████▌████▌
████████▀███████▐▌█
███████████████▌█▌▐
████████▄████████▐▐
██████████████████▌
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀
Bitz.io███ ████████▄████▄▄▄█████▄▄
██████▄████████▀▀██▀▀
█████▀▀█████▀▀▄▄█
███████████▄▀▀███
████████████████▐▌
████████████████▐▌
███▄▄█████▄▄█▄▄█████▄▄
█▄█████████████████████▄
▄███████████████████████▄
██
███████████████████████
▀██
█████████████████████▀
█▀████
█████████████████▀
███▀▀████▀▀██▀▀█████▀▀
98%
RTP
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄███████████████
██████▄
▄███████████████████████▄
█████████████████████████
█████████████████████████
█████████████████████████
████████████████████████▀
▀█████████████████████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀
HIGH
ODDS
 ████ PLAY NOW   ███
Vara1959
Newbie
*
Offline

Activity: 21
Merit: 0


View Profile
July 01, 2026, 07:56:14 PM
 #28

Glad your issue was resolved, but there were some major issues with plinko and altered probability tables. For those who aren't aware of the situation:

https://www.ltccasino.io/blog/winna-plinko-odds-rigged/

Short summary: From December 17, 2025, to March 10, 2026, Plinko was advertised as having a 99% RTP. In reality, the underlying probability tables had been altered, resulting in an actual RTP of less than 98%.

To this day, I still haven't been compensated, even though I was affected (confirmed by host). The reason is that I refused the compensation offer, which amounted to only 10% of my estimated losses (4,5K usd).

Bennett now denies this and claims that Plinko was advertised as 98% RTP during that period. However, that directly contradicts the facts. Winna themselves sent out an email acknowledging that an error had caused the RTP to be lower than intended, and the other co-owner (Paul) publicly admitted the issue as well. They also compensated some of the larger players while smaller players like myself were left behind.

Bennett response: https://www.talkimg.com/images/2026/07/01/ULvpNd.jpg

cronosone
Jr. Member
*
Offline

Activity: 67
Merit: 4


View Profile
July 23, 2026, 10:07:13 PM
 #29


-- Winna has ties to a recent rug, Heybets, which is clear from even minor snooping in the DNS and page designs/structure.

Winna is Heybets. Both were ran by the same team Noah Fischer (Paul), Bennett Becker (Bennet) and Dominic Karim Jamil under the company Over99 at Berlin.

As you can see here https://web.archive.org/web/20260605182049/https://www.curacaochronicle.com/post/unknown/curacao-court-orders-online-casino-to-repay-gambling-losses-after-ignoring-addiction-warning-signs Dominic Karim Jamil was the owner of Heybets.

You can see their relationships https://www.northdata.com/Jamil,%20Dominic%20Karim,%20Berlin/3e7

More info in the official Winna thread.
cronosone
Jr. Member
*
Offline

Activity: 67
Merit: 4


View Profile
July 23, 2026, 10:41:10 PM
 #30



Quote
-- Winna has ties to a recent rug which is clear from even minor snooping in the DNS and page designs/structure.

We have publicly stated before that we have no connection to this site, and that remains the case.


Why you lie Bennet?Huh?
Iqballen22
Newbie
*
Offline

Activity: 1
Merit: 0


View Profile
October 03, 2026, 02:10:21 AM
 #31

I think this needs to be readdressed in regards to what Bennett has admitted in his response to this post. I believe it is quite serious and most definitely allows for the possibility of result manipulation in provably fair games available on winna, whether it is being used for the manner or not I am not commenting on, it just shows it is possible if they choose to do so.


The previous implementation used HMAC-SHA256 to generate the server seed hash. We have now migrated to using a simple SHA256 hash to align with the implementations used by platforms such as Stake or Shuffle.

It is important to clarify that the hashing algorithm itself does not determine the fairness of the system. The purpose of the hash is to commit to the server seed before gameplay begins. Provable fairness is achieved through the combination of the server seed, client seed, and nonce, which together determine the final game result. As long as the server seed is revealed after the seed rotation and matches the previously published hash, users can independently verify that outcomes were generated correctly. Using HMAC-SHA256 instead of SHA256 therefore had no impact on the randomness or fairness of the seed pair.


The most important part here is the type of encryption used. The only way the Provably Fair system can be fair and not manipulated is by using HMAC-SHA256 to generate the server seed hash. It is proven that standard SHA256 encryption is vulnerable to length extension attacks, which is the exact process one would use if they were trying to manipulate the “random generated” results implemented by the provably fair system.

“A length extension attack is a cryptographic exploit where an attacker uses an existing hash digest (Hash(secret ‖ message)) and the total length of the secret and message to calculate a valid hash for an extended message (Hash(secret ‖ message ‖ padding ‖ extra_data)) without needing to know the secret.”

“Vulnerable and Safe Algorithms
• Vulnerable: Algorithms based on the Merkle–Damgård construction, including MD5, SHA-1, and standard SHA-256 / SHA-512.
• Safe / Immune:
   • HMAC (Hash-based Message Authentication Code): Uses a nested hashing construction that prevents this form of state reuse.
   • SHA-3 (Keccak): Uses a sponge construction where the internal state is much larger than the output, preventing direct state reconstruction.
   • Truncated SHA-2 variants: Like SHA-384 or SHA-512/256, because they drop portions of the internal state from the final digest”

https://en.wikipedia.org/wiki/Length_extension_attack

https://pentesterlab.com/glossary/length-extension-attack

Please look and read through these links, they explain it all perfectly.

So based upon Bennett’s own admissions about the encryption used, we know that winna’s provably fair games are vulnerable to manipulation, whether that is being taken advantage of or not I cannot say.


logfiles
Copper Member
Legendary
*
Offline

Activity: 2856
Merit: 2423



View Profile WWW
October 03, 2026, 11:17:02 AM
 #32

<...>
I am not going to go deep into their provably fair system as it doesn't matter any more but in case you missed it, you might want to look at this - Moderator bribed to delete scam accusations against Winna
At this point in time, no one should trust what Bennett and company say or even think of using their casino. There are so many casinos out there can be trusted than the lying corrupt winna folks.

AHOYBRAUSE
Legendary
*
Offline

Activity: 1470
Merit: 2104


よろしく


View Profile WWW
October 03, 2026, 04:05:32 PM
 #33

<...>
I am not going to go deep into their provably fair system as it doesn't matter any more but in case you missed it, you might want to look at this - Moderator bribed to delete scam accusations against Winna
At this point in time, no one should trust what Bennett and company say or even think of using their casino. There are so many casinos out there can be trusted than the lying corrupt winna folks.

Nothing else to add. If a site goes that far to build up a fake reputation who knows what else they are willing to do when push comes to shove. I wouldn't feel safe on that site and I didn't even feel that before this all came to light since I called out their shit way before actually.
Anyway, I still wonder if Bennett will amuse us with an explanation sooner or later, as he said he would do.  Roll Eyes I mean obviously we will never hear from this clown again but it would definitely be entertaining.

Last thing, I wonder why this is marked as "resolved" when it's obvious their "provably fair" isn't what it pretends to be.


logfiles
Copper Member
Legendary
*
Offline

Activity: 2856
Merit: 2423



View Profile WWW
Today at 12:55:45 PM
 #34

Anyway, I still wonder if Bennett will amuse us with an explanation sooner or later, as he said he would do.  Roll Eyes I mean obviously we will never hear from this clown again but it would definitely be entertaining.
I am pretty certain he will never come back here to tell us of the what "findings" he discovered after promising to review their "relationships with external agencies and contractors" that very day when Theymos posted about the bribing. That was on 22 July 2026, we are now in October  Grin

Last thing, I wonder why this is marked as "resolved" when it's obvious their "provably fair" isn't what it pretends to be.
Given their history of trying to force users to mark threads as resolved or even bribing people to do anything to make their reputation look clean, I won't be surprised about any possible alternative routes they used.

Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!