Skip to main content
Every pack draw in Jupiter Gacha is made by a procedure that neither Jupiter nor the provider can steer after the fact, and that you can check yourself. The procedure depends on the pack’s provider: Collector Crypt packs run through an on-chain verifiable randomness function (VRF) on Solana, and Phygitals packs run through a cryptographic commit-reveal scheme.

Why verifiable randomness matters

In a pack opening product, the operator could in principle manipulate which card a draw produces. A verifiable procedure removes that possibility:
  • The random value that decides your pull is fixed by a commitment made before the draw, not chosen by a private server at draw time.
  • The result comes with a cryptographic proof that the value was generated correctly and was not chosen or altered after the fact.
  • Anyone with the proof can check it, without trusting Jupiter or the provider.
Combined with the fixed, displayed odds per rarity tier, this means both the probabilities and the individual draws are auditable.

Collector Crypt packs: on-chain VRF

Draws on Collector Crypt packs run through Collector Crypt’s verifiable randomness function, implemented as an on-chain program on Solana. The random value is generated by the program, the proof is recorded on Solana, and anyone can check it on-chain. Each of these openings has an associated on-chain transaction and randomness proof. To verify a draw, open Collection, go to the Activity tab, select one of your openings, and click Verify to see the randomness proof and the related on-chain details for that draw. For technical details on the VRF implementation, refer to cc-vrf, Collector Crypt’s permissionless on-chain VRF for Solana implementing RFC 9381 ECVRF.

Phygitals packs: commit-reveal

Draws on Phygitals packs run through Phygitals’ commit-reveal scheme, documented on its provable fairness page:
  1. Commit. Before the pack is opened, Phygitals’ server generates a secret seed and publishes its SHA-256 hash.
  2. Reveal. When you open the pack, a client seed unique to you and the transaction is combined with the server seed by a publicly disclosed algorithm to determine which card you receive.
  3. Verify. Phygitals then discloses the server seed, so that anyone can hash it, compare the hash with the published commitment, and replay the algorithm to confirm the outcome.
Because the commitment is made before the client seed exists, neither side can steer the result. This procedure is cryptographic rather than on-chain: the proof is a hash and an algorithm, not a Solana transaction. Jupiter Gacha does not display the seeds or the hash of a Phygitals draw, and there is no Verify action for these pulls in your Activity tab. Phygitals publishes the proofs of pack openings to the Phygitals account that made them. For a Phygitals pack opened on Jupiter Gacha, the fairness guarantee therefore rests on Phygitals’ published procedure rather than on a proof you can check yourself.

What the guarantees do not cover

Both procedures guarantee that each draw is random and tamper-proof within the displayed odds. They do not change the odds themselves: on most packs, the majority of pulls fall in the lowest rarity tier, as shown in each pack’s odds table. Provable fairness means the game is fair, not that it is profitable.