Skip to content
CheckMyPull
Trust and safetyProvably fair

Is a Mystery Box Site Rigged?
How to Tell

How to tell if a mystery box site is rigged: the red flags that matter and the provably fair check you can run yourself to prove a pull was honest.

CM
The CheckMyPull teamIndependent verifier · no operator ties
PUBLISHED 14 JUL 2026·UPDATED 14 JUL 2026·9 MIN READ

When a mystery box site feels off after a cold run, the useful question is not whether you got unlucky, but whether the site can prove the result was honest. Most worry about a rigged mystery box site comes down to one fear: that the outcome was decided against you, or changed after you clicked. On a site that runs a provably fair system, you do not have to guess. You can recompute a completed pull on your own device and see for yourself whether the result matches what the site showed. This page walks through the red flags that should make you cautious, and the one check that actually settles the question.

What people mean when they call a site rigged

"Rigged" gets used for a few different worries, and it helps to separate them, because only some are things a fairness check can answer.

The first worry is that the result itself was tampered with: that the site saw a rare item coming and quietly swapped in a common one, or aimed a bad outcome at you specifically. This is the claim provably fair was built to disprove, and it is the one you can test directly.

The second worry is broader: that the published odds are worse than stated, that a withdrawal will stall, or that the whole operation is not on solid ground. These are real concerns, but they are separate questions, and no cryptographic check settles them. Keeping the two apart is the first step to thinking clearly about whether a mystery box site is rigged.

The one check that actually settles it

A provably fair site commits to your result before you play, then lets you prove it afterward. Picture a sealed envelope. Before you open a box, the site writes its secret number on a card, seals it, and hands you a tamper proof stamp of that envelope. You cannot read the card yet, but the stamp proves it existed and cannot be swapped. When the round is done, the site opens the envelope, and you check the card against the stamp you were holding.

In real terms, the card is the server seed, a long secret string. The stamp is a hash of it, a one way fingerprint the site shows you before you play. Your pull is decided by that server seed combined with your own client seed and a nonce, a counter that ticks up with each open. Because your client seed is part of the mix, the site cannot aim a specific result at you, and because the server seed was committed in advance, the outcome was locked before you clicked.

That design gives a genuine fairness check exactly two things it can catch:

  • A result altered after the commit. You paste the revealed server seed, your client seed, and the nonce into an independent verifier, and it recomputes the outcome. If the recomputed result does not match what the site displayed, the shown result did not come from the committed inputs.
  • A seed that does not match its fingerprint. The verifier hashes the revealed server seed and compares it to the fingerprint the site published before your round. If those do not match, the site did not use the value it committed to.

If both line up, the pull was generated from inputs fixed before you played and was not changed afterward. That is a real, provable answer, and you can get it in a few seconds. If you want the full background on the mechanism, the what is provably fair guide walks through the whole flow.

Red flags that a mystery box site might be rigged

No single sign is proof on its own, but the more of these you see, the more reason to be careful before depositing. This is the practical checklist to run before you trust a new site.

  • No fairness hash before you play. A provably fair site shows you a hashed server seed up front. If nothing is committed before your round, there is nothing to check against later, and the site's own results are unfalsifiable.
  • The server seed is never revealed. The commitment is only half the system. If you can rotate your seed but the old server seed never appears, you can never complete the check. Some sites have reportedly reduced or removed seed visibility over time, so confirm the reveal actually works before you rely on it.
  • A verify button that only calls the site's own server. A real check runs on your device against an independent tool. If the only way to "verify" is a button that sends your seeds back to the same site and returns a thumbs up, you are trusting the site to grade its own work.
  • The recomputed result does not match. If you run the check and the independent outcome differs from what was displayed, or the revealed seed does not hash to the committed fingerprint, that is the clearest red flag there is. Save a screenshot of the seeds and the result.
  • No published odds at all. Fairness of the draw and honesty of the odds are separate things, but a site that hides its item probabilities entirely gives you no baseline to judge anything against.
  • Withdrawal problems reported by users. Recurring, independently reported complaints about stalled or denied withdrawals are worth weighing. Treat any single review as a signal to verify, not a verdict, and look for the same pattern across multiple named, dated sources before believing it.
  • Pressure and "guaranteed" wins. Countdown timers, a rare item framed as "due" after a cold streak, or any tool promising to predict or guarantee your next pull. These are marketing and scam patterns, not fairness signals.
  • Anonymous operator and no history. A brand new site with no traceable ownership, no contact details, and a wall of glowing reviews that all appeared at once deserves extra caution.

Work down this list before you deposit, not after a bad session. Most of it takes a couple of minutes.

Rigged, or just a cold streak?

Most people go looking for the word "rigged" right after a run of bad pulls, and it is worth being honest about what a bad run actually tells you. On a provably fair site, each open is independent. A rare item does not become "due" because you have missed it ten times, and a cold streak is not evidence of tampering on its own. Long dry spells are a normal feature of low probabilities, not a sign the site reached in and changed something.

The way to separate genuine bad luck from a rigged draw is not to count losses, it is to verify. A single verified pull that matches its committed seeds tells you that specific result was honest, regardless of how it felt. If you want to test a whole session rather than one open, comparing your actual hit rate against the site's published odds over many pulls shows whether your run sits inside normal variance or genuinely outside it. That is a math question you can answer with your own pull history, and it is a far better guide than a gut feeling after a rough hour.

How to actually run the check

You do not have to take any of this on faith. Once a server seed is revealed, paste it, your client seed, and the nonce into an independent verifier and recompute the result yourself. The tool below does exactly that, and nothing you enter is sent anywhere.

Live verifier
0 network requests

Step 1Where did you play?

Using Ripster box / upgrade: HMAC-SHA256 over clientSeed:noncedetails

HMAC-SHA256 keyed with the server seed over clientSeed:nonce. The first 8 hex characters become a 32-bit integer, divided by 2^32 and multiplied by 100 for a roll in [0, 100). Items are sorted by item ID and selected by cumulative probability: the first item whose cumulative probability is at least the roll wins.

Where to find your numbers on Ripster.gg:

  1. Before rolling, copy the Server Seed Hash from the Provably Fair modal (also recorded per roll in Account History).
  2. After the roll, open the Provably Fair modal to copy the Server Seed, Client Seed and Nonce.
  3. Change your Client Seed anytime in Account Settings; doing so reveals the current Server Seed so all past rolls become verifiable.

Source: Ripster.gg's own fairness page

Step 2Paste your numbers

Runs entirely on your device via your browser's built-in cryptography. Don't take our word for it: open DevTools → Network, click the button, and watch: zero requests.

Runs entirely in your browser. Nothing you paste is sent anywhere.

The steps are the same on any provably fair site:

  1. Before you play, copy the hashed server seed the site shows you. That is the fingerprint.
  2. Note your client seed and the nonce for the pull you want to check.
  3. After you rotate seeds, copy the revealed server seed.
  4. Paste all of it in. The verifier recomputes the outcome and checks the revealed seed against the fingerprint you saved.

If both match, the result was committed before you played and was not altered. If either fails, you have something concrete to point to. For a fuller walkthrough with each field explained, see how to verify provably fair.

One thing to be clear about: this is verification of a result you already have, not prediction of a future one. The server seed is committed before your client seed even exists, so nothing can read a future outcome in advance. Any tool that claims to forecast or guarantee your next pull is a case opening predictor scam, not a fairness tool.

What a passed check does not prove

This is why the checklist above pairs the fairness check with the other red flags. Verification is the strongest single test you have, and it is the one thing operators cannot fake, but it answers one question, not all of them. A site can pass every recompute and still be one you should approach carefully for reasons the math never touches.

The bottom line

To tell if a mystery box site is rigged, stop guessing and run the check. A provably fair site commits to your result before you play and reveals the seed afterward, so you can recompute any pull on your own device and confirm it matches. If it does, the draw was honest. If the site publishes no hash, never reveals its seed, or the numbers do not line up, you have a real reason to walk away. If unboxing has stopped feeling fun or you are chasing a loss, the responsible play page has plain guidance and support links.

FAQ
How can you tell if a mystery box site is rigged?+

The strongest test is a provably fair check you run yourself. Copy the hashed server seed the site shows before you play, then after the round paste the revealed server seed, your client seed, and the nonce into an independent verifier. If the recomputed result matches what the site displayed, the draw was honest.

Can a provably fair check prove a site is not rigged?+

It proves one thing precisely: that a completed result came from the inputs committed before you played and was not altered afterward. It catches a changed outcome or a revealed seed that does not match its fingerprint. It cannot prove the odds, solvency, or that a withdrawal will clear, so pair it with the other red flags.

Does a bad losing streak mean a mystery box site is rigged?+

No. On a provably fair site each open is independent, and a rare item never becomes due after misses. Long cold streaks are a normal feature of low probabilities, not proof of tampering. To be sure, verify a specific pull, or compare your hit rate against the published odds over many opens.

What is a red flag that a mystery box site is unfair?+

Warning signs include no fairness hash shown before you play, a server seed that is never revealed, a verify button that only calls the site's own server, no published odds, and a recomputed result that does not match. No single sign is proof, but several together are a reason to be cautious before depositing.

Is there a tool that predicts mystery box drops?+

No. The server seed is committed before your client seed even exists, so nothing can read a future outcome in advance. Any tool claiming to predict or guarantee your next pull is a scam. The honest tool works the opposite way: it verifies a result you already have, on your own device.

Sources
Keep reading
Next · Trust and safety
Case Opening Predictors Are a Scam: Here Is the Proof

Don't take an article's word for it.

Verify a roll yourself