Skip to main content
Audits
Duel.com/Dashboard

Duel.com

Certified · Active

Duel.com certification

Certified

PF-2026-DUEL

10 in-house games met the certification criteria under Framework v1.0.

Certified by
ProvablyFair.org
Issued
June 8, 2026
Next review
June 8, 2027
Audit period
March–May 2026
Read the certification scope
Verify a bet

Duel.com holds PF-2026-DUEL certification under Framework v1.0

Certified
June 8, 2026
Audit period
March–May 2026
Next review
June 8, 2027
Scope
10 in-house games
10 / 10Games validated
53,475Original audit · live bets
253MSimulation rounds
151Integrity checks
Why trust these results?

You don't have to trust us. You can check our work.

10 repositories

All 10 game repositories publish the code, data and checks. Re-run the suite locally.

Browse all 10 repositories
01

Game audit matrix

Open a game to inspect its full audit, test results and source repository.

Showing 10 games
5 metrics
GameRNG modelLive betsSimsSimulated RTPProven RTPResult
PlinkoHMAC-SHA2568,10027M99.917%99.9%Pass
DiceHMAC-SHA2566,70098M99.922%99.9%Pass
MinesHMAC-SHA2567,05024M99.904%99.9%Pass
KenoHMAC-SHA2565,10040M99.970%99.9%Pass
BeefHMAC-SHA2566,4504M99.147%99.2%Pass
Crash1 findingHMAC-SHA256
+ drand
1,1005M99.872%99.9%Pass
Castle RouletteHMAC-SHA256
+ drand
1,3505M100.007%100.0%Pass
Video Poker1 findingHMAC-SHA2565,40010M— †99.9%Pass
BlackjackHMAC-SHA2566,00010M99.467%99.4296%Pass
Groomer's Van2 findingsHMAC-SHA256
→ PCG32
6,22530M100.06%99.9720%Pass
Game / resultLive betsSimsSim. RTPProven RTPRNG model
PlinkoPass8,10027M99.917%99.9%HMAC-SHA256
DicePass6,70098M99.922%99.9%HMAC-SHA256
MinesPass7,05024M99.904%99.9%HMAC-SHA256
KenoPass5,10040M99.970%99.9%HMAC-SHA256
BeefPass6,4504M99.147%99.2%HMAC-SHA256
CrashPass1 finding1,1005M99.872%99.9%HMAC-SHA256 + drand
Castle RoulettePass1,3505M100.007%100.0%HMAC-SHA256 + drand
Video PokerPass1 finding5,40010M99.9%HMAC-SHA256
BlackjackPass6,00010M99.467%99.4296%HMAC-SHA256
Groomer's VanPass2 findings6,22530M100.06%99.9720%HMAC-SHA256 → PCG32

RTP values apply to each report’s tested configuration and strategy. Simulated RTP is a Monte Carlo estimate; proven RTP is our own derivation from the published rules. † Video Poker’s return depends on strategy; only its optimal-play proof is shown.

4 input-validation findings across 3 gamesNo fairness failuresView disclosures →
02

Audit verdict

Five independently tested control areas underpin the certification.

All 5 control areas passed10 games · independently verified
DeterminismPass

All 10 games fully reproducible — every outcome recomputable from (serverSeed, clientSeed/drand, nonce, state)

RNG IntegrityPass

HMAC-SHA256 with bias-free rejection sampling across all games; 2 games (Crash, Castle Roulette) additionally bind drand public beacon

Live ↔ Verifier ParityPass

100% match — 53,475 / 53,475 live bets reproduced exactly against an independent verifier

RTP ValidationPass

253M simulated rounds across all games; every theoretical RTP independently re-derived from first principles and matched within statistical tolerance

Fairness IntegrityPass

151 game integrity checks · 147 pass · 4 findings — all at the API input-validation layer, none affecting outcome determinism, RTP, or payout integrity · no fairness failures

Read the executive summary →
03

Findings & disclosures

Four input-validation findings were disclosed to Duel. No fairness failure was recorded.

147Passed checksOf 151 integrity checks
4Disclosed findingsAcross 3 game reports
0Fairness failuresRNG, RTP and payout integrity
Game / countInput validation findingEvidence
Video Poker1 finding

Malformed payloads receive an HTTP 200 response.

View probes
Groomer's Van2 findings

Malformed payloads receive an HTTP 200 response, including game-specific request probes.

View probes
Crash1 finding

Auto-cashout values above the theoretical maximum crash point are accepted.

View probes

These findings concern API request validation. The audited cryptographic core, RNG, RTP derivation and payout logic operated correctly. Reproducible probes are published in Section 5 of each affected game report.

04

Audit process

Each game followed the same framework, with an independent implementation and captured live bets.

March–May 2026PF Framework v1.0
  1. 01InitiatedScope & specification
  2. 02Bet CaptureLive bets recorded
  3. 03Parity TestingIndependent replay
  4. 04RTP Simulation253M rounds
  5. 05Integrity Testing151 checks
  6. 06Certification8 June 2026
Covers Duel’s 10 in-house games

RNG, reproducibility, RTP and payout integrity within game logic. Platform finances, licensing, infrastructure, third-party titles and promotional programs are outside this audit.

Full audit scope ↗
05

Transparency & verification

Inspect the code, reproduce the audit or check a result from its disclosed inputs.

Open source

Reproduce the audit

Every game has a public repository with its verifier, captured dataset and simulation harness.

  1. Choose a game repository
  2. Clone the audited commit & install
  3. Run npm test
Browse all 10 repositories ↗Reproduction guide & prerequisites ↗
Independent verifier

Verify a single bet

Recompute a game result from its revealed seeds and public inputs using the independently audited implementation.

Open ProvablyFair verifier
Duel’s own verifier ↗Operator-run tool. Listed separately from the independent ProvablyFair verifier.
Want the complete audit context?

Read the methodology, scope and conclusions in the executive summary.

Executive summary →