Evidence
RNG & Oracles (Control, centralization, manipulation risk)
[1] Oracle signer transactions list


[2] Same signer used across multiple users/games





[3] No public instructions to run an oracle node



[4] No on-chain commit to bet (no commit–reveal)

[5] VRF not bound to block/slot





[6] Off-chain oracle generates VRF, only final posted

[7] Demonstration of re-roll risk (concept or tool)

[8] Timing gap: bet → VRF post


[9] No on-chain function to rotate oracle signers


[10] Halborn: reliance on off-chain logic

[11] Slot/Vault contract extracts show no outcome logic


[12] Data flow (RNG → off-chain → payout)

[13] No published RTP/odds per game on-chain





[14] Backend distributions

[15] No user-verifiable reproduction path (no client seed binding)



[16] Winner wallet page (5or7BF…): full TX history


[17] Kraken-funded deposits (2× >600 SOL)


[18] Micro-tx burst to gambling dApps




[19] No DeFi/NFT usage (ephemeral wallet)





[20] Timeline: Kraken → play burst → jackpot → withdraw


[21] Jackpot payout TX (sender not vault)


[22] Probability graph (Poisson) for 2 in 5,000

[23] Statement: no jackpot transparency report



[24] Vault settlement log (typical small win auto-settled)


[25] Cold reserve described (marketing)

[26] Cold reserve is a wallet, not a contract

[27] Jackpot payout not routed via vault contract

[28] No timelock/multisig on reserve


[29] No on-chain proof-of-liabilities


[30] Program marked upgradeable (BPF Loader)

[31] Upgrade authority is team-controlled


[32] No public DAO governance (no SPL governance links)

[33] No pause/override functions publicly exposed


[34] Halborn “authority transfer not enforced” fixed

[35] Settlement batching acknowledged (delay possible)



[36] Halborn scope omits RNG/oracles/game logic





[37] No public GitHub/IPFS for audited code

[38] Screenshot of “provably fair for every spin” claim

[39] Screenshot of “decentralized oracles” claim



[40] Screenshot of “non-custodial, you control funds” claim

[41] Claims vs Reality table (final)

[42] No Client seed input UI


[43] No path to reproduce outcome from seed



[44] Explorer shows logs, not pre-commit proofs

[45] Example: bet log with no player-seed binding



[46] 3 real bets with full fields (CSV)
[47] One bet timeline

[48] Admin/Reserve safety

[49] No multisig on reserve (EOA ownership)


[50] Comparision and Architecture upgrades


Last updated