You can replay the published draw with Bun and two downloaded files. No Amplifi account, private repository or installed dependencies are required.
proof.json. Public proof URLs use /amps/lottery/proof/N, where N is a one-based week number; every draw covers exactly one Amp week. Preserve the original downloaded file.cd92cb7823edd41d604f0dd51699858308e68beae6b7f1bfe30180aef4c9040e with the exact commitment hash you saved, then run:bun lottery-verifier.mjs proof.json --fetch-drand --commitment-hash cd92cb7823edd41d604f0dd51699858308e68beae6b7f1bfe30180aef4c9040e
The command fetches the exact named Quicknet round. Check every item passes and compare its derived winners and their places with the result in the public proof. A failed check or a different commitment hash means verification failed.
The tweets omit wallet addresses and individual AMP weights. The public proof contains the EOAs and weights needed to replay the selection; this is not an anonymous entrant list.
The saved commitment hash binds the published draw inputs. The verifier checks the canonical entrant list of lowercase wallet EOAs and positive integer milliAMP weights, its SHA-256 hash, totals and prize arithmetic. It verifies the beacon BLS signature against the pinned drand Quicknet chain and public key, then recomputes the seed and every pick.
A draw picks up to three different wallets, one pick at a time. Each pick hashes the seed with its pick number, takes an unbiased rejection-sampled ticket over the milliAMP weights of the wallets not yet drawn, and selects the first of them, in canonical entrant order, whose cumulative weight exceeds the ticket. Every milliAMP is one ticket in each pick a wallet is still eligible for.
The drawn wallets are then ranked by AMP weight, most first, with the entrant order breaking ties. First place receives 60% of the prize, second 25% and third 15%, each rounded down to a whole micro-pUSD. A draw with fewer than three entrants pays only the places it fills. A proof whose algorithmVersion is amps-lottery-drand-v2 is an earlier single-winner draw: one pick, seeded by the seed itself, paid the whole prize.
The commitment locks the published weights and selection rules. Whether the underlying activity ledger assigned fair and complete weights requires a separate ledger audit. The verifier checks the stated timing rules, but independent evidence that the commitment was public before the beacon comes from the original pre-beacon publication you saved. Keep the tweet, original JSON and verifier together; a later download alone cannot establish publication time.