Reverse Engineering Lottery Scratch Tickets For Profit (But Not Fame)

from the scratch-and-sniff dept

Jonah Lehrer has a fantastically entertaining article in Wired about cracking scratch card lottery tickets. It kicks off with a story about Mohan Srivastava, a statistician in Toronto who quickly realized that the scratch tickets couldn’t actually be random, even if they try to give off that impression. Since the lotteries want to control how often people win, the numbers have be chosen by a careful algorithm — and if that’s the case, there’s almost always ways to reverse engineer the algorithm. With the first game he tried it on, Srivastava was able to increase his odds to the point that he could pick a “winning” card 90% of the time. He ended up alerting the Ontario Lottery and Gaming Corporation — though, he admits that he did so not for moral reasons, but because he quickly calculated that he probably wouldn’t make that much money just by gaming the system:

His next thought was utterly predictable: “I remember thinking, I’m gonna be rich! I’m gonna plunder the lottery!” he says. However, these grandiose dreams soon gave way to more practical concerns. “Once I worked out how much money I could make if this was my full-time job, I got a lot less excited,” Srivastava says. “I’d have to travel from store to store and spend 45 seconds cracking each card. I estimated that I could expect to make about $600 a day. That’s not bad. But to be honest, I make more as a consultant, and I find consulting to be a lot more interesting than scratch lottery tickets.”

Instead of secretly plundering the game, he decided to go to the Ontario Lottery and Gaming Corporation. Srivastava thought its top officials might want to know about his discovery. Who knows, maybe they’d even hire him to give them statistical advice. “People often assume that I must be some extremely moral person because I didn’t take advantage of the lottery,” he says. “I can assure you that that’s not the case. I’d simply done the math and concluded that beating the game wasn’t worth my time.”

At first the Ontario Lottery ignored him. Apparently, lots of crackpots claim to have beaten the lottery, but haven’t. So, instead, he sent a guy on the Ontario Lottery security team a package of unscratched cards, and sorted them into piles he thought were winners and losers. Apparently, he was pretty accurate, because they called him quickly after that and then pulled the game.

Of course, as often happens in these situations, the Lottery insisted that this was just a one-off error, and the rest of their games were secure. Srivastava correctly noted that was unlikely, as the chances that the ticket he’d randomly been given was the only one with a flaw seemed remote. And, even if he didn’t think it was worth his time to game the system, that’s not true for others. In fact, Srivastava notes that there are ways to profitably game the system:

I then ask Srivastava how a criminal organization might plunder the lottery. He lays out a surprisingly practical plan for what he would do: “At first glance, the whole problem with plundering is one of scale,” he says. “I probably couldn’t sort enough tickets while standing at the counter of the mini-mart. So I’d probably want to invent some sort of scanning device that could quickly sort the tickets for me.” Of course, Srivastava might look a little suspicious if he started bringing a scanner and his laptop into corner stores. But that may not be an insurmountable problem. “Lots of people buy lottery tickets in bulk to give away as prizes for contests,” he says. He asked several Toronto retailers if they would object to him buying tickets and then exchanging the unused, unscratched tickets. “Everybody said that would be totally fine. Nobody was even a tiny bit suspicious,” he says. “Why not? Because they all assumed the games are unbreakable. So what I would try to do is buy up lots of tickets, run them through my scanning machine, and then try to return the unscratched losers. Of course, you could also just find a retailer willing to cooperate or take a bribe. That might be easier.” The scam would involve getting access to opened but unsold books of tickets. A potential plunderer would need to sort through these tickets and selectively pick the winners. The losers would be sold to unwitting customers–or returned to the lottery after the game was taken off the market.

Lehrer then goes on to point out that there is statistical evidence that, at the very least, suggests that some gaming of the system has been done in various places.

Consider a series of reports by the Massachusetts state auditor. The reports describe a long list of troubling findings, such as the fact that one person cashed in 1,588 winning tickets between 2002 and 2004 for a grand total of $2.84 million. (The report does not provide the name of the lucky winner.) A 1999 audit found that another person cashed in 149 tickets worth $237,000, while the top 10 multiple-prize winners had won 842 times for a total of $1.8 million. Since only six out of every 100,000 tickets yield a prize between $1,000 and $5,000, the auditor dryly observed that these “fortunate” players would have needed to buy “hundreds of thousands to millions of tickets.” (The report also noted that the auditor’s team found that full and partial ticket books were being abandoned at lottery headquarters in plastic bags.)

Then there’s the example of a woman in Texas, Joan Ginther, who has apparently won more than $1 million from the Texas lottery four separate times. There are also some indications that organized crime groups have regularly used such lottery tickets as a way to launder money — and if they can crack the code, that makes the laundering process a lot more profitable.

Finally, the article notes that the Lottery industry around the world seems to more or less be in denial about the whole thing, frequently insisting that the new games are perfectly secure, and not even being all that aware of previous cracks and problems. The whole thing is well worth reading.

Filed Under: , ,

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “Reverse Engineering Lottery Scratch Tickets For Profit (But Not Fame)”

Subscribe: RSS Leave a comment

Usually these things are an error. Most scratch lotteries do not reveal serial numbers or other identification in the open, they are usually covered by the “scratch coat” as well. If that scratch coat is already removed, the ticket isn’t valid for redemption.

If they put an identifiable number or code in an open place, it’s an error.



“Usually these things are an error. Most scratch lotteries do not reveal serial numbers or other identification in the open, they are usually covered by the “scratch coat” as well.”

Did you read the article at all? The man can predict if a ticket will be a winner (with a very high probability apparently) without any more information than the average player can get.

It is not an error in the cards themselves. It’s an error in the way the lotteries were designed.


Re: Re: Re:

No, the left side is covered with latex when you buy it.

The flaw is that in order to add predictability, the designers probably removed too much randomness by trading off randomness for predictability and fast generation time. Apparently a pattern came out and the researcher guessed it.

It may very well be possible to reveal 72 numbers without revealing any pattern. No one can know for sure if that is true without a good mathematical analysis; however, even if it is possible to create such cards without patterns, it might not be feasible to create them economically or even to have the algorithms finish running during our lifetimes. This means that in practice the designers will take short-cuts (just like game designers take short-cuts in designing 3D games so that they perform well in real-time). It is in these short-cuts that likely patterns snuck in.


Re: Re:

No, the error is in providing too much information to work from.

If the numbers on each “card” were covered, he would not be able to make such a choice ahead of time. By leaving all the numbers exposed, they showed a large part of the game play.

If 8 of the 9 squares on each were covered (needed to be scratched before use), his method would not apply.

Basically, they put too much information out there. Usually it’s an error in exposing a serial number (as you can see the serial numbers are exposed on the bottom), but in this case, it was just exposing too much of the card to the public before they buy it.


Re: Re: Re:

Basically, they put too much information out there. Usually it’s an error in exposing a serial number (as you can see the serial numbers are exposed on the bottom), but in this case, it was just exposing too much of the card to the public before they buy it.
If you read the article you would discover that there is a reason why they expose too much information. It is marketing. The public prefers cards with some exposed information. There is no problem with exposing information if you do it right. However for some reason these companies don’t bother. It may be because the companies are lazy but it is more likely to be a compromise between security and making the game attractive to play. From the companies point of view it doesn’t really matter if a few individuals game the system – all they are doing is taking a little more money from the other players (who are onto a loser anyway). The companies control exactly how many winning tickets are printed so it doesn’t affect their finances directly at all.


I agree with Richard

By exposing some of the information (numbers), the marks (the poor losers) think they have a chance of winning. They are involved in the process.

Having the word LOSER (or similar) covered in latex, ends the experience a lot faster, and thus there is not enough fantasy (read: addiction) involved.

My sister buys 20 lottery tickets a week; she says it’s fun (thrilling) to get near-misses because it makes her heart race. Oh sure, she’s one $600 – $900 before, but after several months worth of buying tickets at a cost of $1 to $2 each. [Do the math] Break Even.

In conclusion, it’s a scam. The lottery is stacked against the player.


Re: Re:

I doubt they label most cards publicly starting from 1.

It’s rather easy to attach a random numerical id to each ticket so that only those with the central computer mapping can know if the tic-tac-toe or other game pieces on that physical card with a given id matches what corresponds to that id on the central computer.


Re: Re: Re:

t’s rather easy to attach a random numerical id to each ticket so that only those with the central computer mapping can know if the tic-tac-toe or other game pieces on that physical card with a given id matches what corresponds to that id on the central computer.

Easy yes – but amazingly these organisations rarely bother!

Re: Re: Re:

How dare you point out my stupidity! Being a part of the teeming masses of the ignorant, anonymous internet horde, I am justifiably outraged at your characterization of my useless posting habits. You have left me no option but to attempt a lame insult, thereby also announcing my intention to fail to learn from my mistakes, and to take absolutely no action to correct my glaring intellectual shortcomings.

Keep ’em coming.


Re: Re: Re:

“Chris, can you stick your “fixes” somewhere else?”

Wait, were you suggesting that he take note of your annoyance and specifically adjust his behavior when replying to you, but with anyone else he should feel free to comment however he wishes?

Damned decent of you! I’m writing your name down to remember this one for my future comments as well. Thank you indeed, er, Anonymous Coward!


Josh in CharlotteNCsays:


Things may have changed in the ~10 years since I worked as a clerk, but I doubt it. Scratch offs had a bar code on the back that was used to redeem the tickets. Even though that barcode was unique to each ticket and psuedo-random, it would not be impossible to crack.

The key to beating any gambling game is not to win all the time (that just generates attention), but more than your ‘fair’ share.


“People often assume that I must be some extremely moral person because I didn’t take advantage of the lottery,”

He could be extremely short-sighted. This particular game might not have been worth his while, but another game with higher payouts and a similar flaw might have been in the future.

But what I don’t get is how you’re supposed to be able to examine scratchoff tickets to figure out which ones would pay off. They’re usually behind the counter in big rolls and I don’t think they’d let you go through them all looking for a winner.



Usually you can see the sequential number of at least one ticket for that pack. Depending on the how the dispenser is set up this is either the next to be sold or has one or two to be sold before it.

Knowing this you can have a general idea where in the sequence of that pack. When I worked at a convenience store in high school the more frequent players would pick up on patterns and wouldn’t buy cards in certain ranges. I’m pretty sure these players weren’t using math to determine this (cause they could easily do the math and realize they were spending more then they were winning) but rather by noticing trends.

As for the original article, I can’t imagine anyone would accept the return of lottery tickets after a sale especially out of order.


I think that people are missing the point.

He doesn’t use anything about the numbering of the tickets. He doesn’t use any other identifying information. He uses the MECHANIC of the ticket and information that you can glean from MECHANIC. The mechanic of the game was such that any time numbers appeared a single time on a card and that those singles appeared in a row/column, the card was substantially more likely to be a winner than not.



Yes, and the lottery company made a mistake by revealing too much information “pre-buy”. If those boxes had 8 of 9 numbers covered, exposing only the center on each card, it wouldn’t have changed anything, but would have revealed less.

By putting that much information out there (72 numbers, and 64 combinations) they provided way too much information, more than enough for people to be able to determine patterns.

Yes, it is ALSO a failing in their methods for encoding the cards, but the real error was in giving the buyer too much information before purchase.


Re: Re:

> Yes, it is ALSO a failing in their methods for encoding the cards, but the real error was in giving the buyer too much information before purchase.

Well, not exactly because the designers wanted to tease the players. They want to reveal all of that information.

The game could have very likely been created correctly by revealing lots of information, maintaining the winning ratio desired, yet not having the design flaw it had.


Re: Re:

but the real error was in giving the buyer too much information before purchase.

It wasn’t an error.

Cards with more information sell better – and neither the lottery company nor the store loses from people gaming the system. From the company’s point of view the extra sales are a win – and the losses from people gaming the system are born by someone else. (The other players – who are basically paying a stupidity task anyway.)

So from the companies point of view this is all fine provided it doesn’t get too much media attention.


The ticket they showed in the article is very unlike any tickets I have seen here in NY. They cover both sets of numbers so you don’t see the grid or you numbers until you scratch them

Check out he following for examples

Werner Van Bellesays:

I thought they were 'real' random.

You start your article with the claim that a statistician realized the random numbers were not really random, but generated by an algorithm. I have also been thinking about this and came to the conclusioon that the smartest thing one could was to use, which samples noise and generates random numbers like that. Then it becomes much more difficulty to track/seed the sequence of pseudorandom numbers.

Chronno S. Triggersays:

Re: I thought they were 'real' random.

The algorithm they’re using isn’t failing at creating random numbers, as all computers do, it’s succeeding at creating the illusion of random numbers.

They cannot use a truly random number generator because they must control how many win and how many lose. If they used one then they can output tickets that win more money then lost. There’s also the chance that none of the tickets win and everyone gets pissed off and you don’t sell any more. They must create a happy medium to keep people coming back.

That’s where the problem lies. Any computer controlled random number generator can be cracked. There is a pattern even if we don’t see it. That’s what this guy did, he cracked the pattern. And from the statistics posted here, it seems others may have in the US as well.


Re: Re: I thought they were 'real' random.

> Any computer controlled random number generator can be cracked. There is a pattern even if we don’t see it.

To clarify, the problem was not in generating pseudo-random numbers. The generators can be made to be very good. The problem was in the higher level rules used to generate the game pieces. Having perfectly random numbers to work with would not have saved the day because the flaw was in not using the random stream of numbers sufficiently.

An example of a high level rule that stinks is: pick the upper row on the first board to win for all the winning tickets. Also, make sure these numbers are 1,2, and 3 (and of course appear within the 24 hidden ones). Note that no randomness was used here.

Now, even if you do everything else right (other numbers look random, you have exactly the number of winners you want, etc), at some point quickly “someone” is going to realize that all the winning tickets have exactly 1 2 3 on the very top of the first tic-tac-toe game.

This is a major flaw that is trivially exploitable once you see the (obvious) pattern. The pattern would be suggest to probably almost anyone by merely looking carefully at 2 winning cards side by side.

Note, how this major flaw had nothing to do with the PRNG. It was a flaw in the compromise the designers struck between using PRNG on the one hand and making non-random decisions on the other (in their attempt to create predictability of total winnings).

That is what happened with the 2003 tic-tac-toe. The flaw was not that obvious, but it was a design flaw of the game generation algorithm and not a PRNG flaw.


Re: Re: Re: I thought they were 'real' random.

They want more than just predictability of total winnings.

There are cryptographically secure PRNGs that will do that for you easily enough,

They want tickets that give people the illusion that they are about to win every time. This sucks them in to buying more tickets- which is the lottery companies main aim.

Doing that whilst remaining secure is much harder – and as I commented above – security doesn’t matter too much to the company (provided they can avoid bad publicity).

Werner Van Bellesays:

Re: Re: I thought they were 'real' random.

What a heap of bullocks. I have 1’000’000’000 tickets printed and I need 50 winners. I thus need only 50 random numbers between 1 and 1’000’000’000. If they are created based on thermal noise there is very little you can do to predict those 50 numbers.

Clearly they didn’t use such an algorithm but that is not because the technology exists but rather stupidity from their side.


I wonder if what he is doing is illegal. He isn’t modifying the card. He is simply reading information observable to anyone. Heck he doesn’t even need to touch the card to pick a winner.

Yeah, I think this falls into “counting cards in a casino” territory. He’s not cheating or using anything other than his brainpower to determine the odds, so it’s not illegal.

Bruce Edigersays:

Re: Nice twist ;0

That one’s easy: “No.”

And yes, I’ve watched the show a few times. Enough to know that they’re making it up as they go along. Nobody on earth is as expert as that curly-haired dweed is. Pick any three shows, and nobody is as expert in those 3 fields as he is, much less all of them.

Lotto Alert | New York (NY) Lottery results | Feeding Lottery Results Daily

Get your custom alerts to your smartphone. Manage your lottery tickets, daily numbers, quick picks, and more. Don’t miss a Jackpot again. Buy your tickets online or through your phone.

What if you could scan your lottery ticket into your mobile phone?!
We’ll you can using the Lott Alert mobile app.
Scan it, store it, and set the alert system to let you know when you win, didn’t win. It can alert you to the next drawing and jackpot amounts. You can even get an Alert when the Powerball or Mega Millions goes over super large amounts.
visit for more information.
Lotto Alert is an App for your iPhone, iPad or Android phone to store your Lottery ticket and provide alerts when you win and remind you of drawings before it’s too late.

texas lottery

A lottery is a form of gambling which involves the drawing of lots for a prize.Lottery is outlawed by some governments, while others endorse it to the extent of organizing a national or state lottery. It is common to find some degree of regulation of lottery by governments. At the beginning of the 20th century, most forms of gambling, including lotteries and sweepstakes, were illegal in many countries, including the U.S.A. and most of Europe.

the lottery results

Al Campbellsays:

Reverse Engineering gag

Where I formerly worked (a we had barcode scanners to produce and read our labels. One day I heard a co-worker approaching, I grabbed some scratch off lottery tickets and scanned the bar code. The reader beeped and displayed a number on the screen. She took one look and said “What are you up to?” I said “Nothing”. “I want to know exactly what you are doing or I’ll have you reported to the police” Needless to say, she looked pretty dumb with her accusations. She wanted a piece of the alledged action.

Anonymous Ninjasays:


I realize this is a 3 year old article (if you can call it an article.) But.. all you have done is use an entire page to summarize another article on another website.. and then suggest that “its a worthwhile read.” To which I say, I already fu?king read it, and was looking for more information on the topic, learn to fu?king stop failing at succeeding at creating, d0uchebag

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop ┬╗

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...
Older Stuff
13:40 It's Great That Winnie The Pooh Is In The Public Domain; But He Should Have Been Free In 1982 (Or Earlier) (35)
12:06 Norton 360 Now Comes With Crypto Mining Capabilities And Sketchy Removal Process (28)
10:45 Chinese Government Dragnet Now Folding In American Social Media Platforms To Silence Dissent (14)
10:40 Daily Deal: The 2022 Ultimate Cybersecurity Analyst Preparation Bundle (0)
09:29 A Fight Between Facebook And The British Medical Journal Highlights The Difficulty Of Moderating 'Medical Misinformation' (9)
06:29 Court Ruling Paves The Way For Better, More Reliable Wi-Fi (4)
20:12 Eighth Circuit (Again) Says There's Nothing Wrong With Detaining Innocent Minors At Gunpoint (15)
15:48 China's Regulatory War On Its Gaming Industry Racks Up 14k Casualties (10)
13:31 Chinese Government Fines Local Car Dealerships For Surveilling While Not Being The Government (5)
12:08 Eric Clapton Pretends To Regret The Decision To Sue Random German Woman Who Listed A Bootleg Of One Of His CDs On Ebay (29)
10:44 ICE Is So Toxic That The DHS's Investigative Wing Is Asking To Be Completely Separated From It (29)
10:39 Daily Deal: The 2022 Complete Raspberry Pi And Arduino Developer Bundle (0)
09:31 Google Blocked An Article About Police From The Intercept... Because The Title Included A Phrase That Was Also A Movie Title (24)
06:22 Wireless Carriers Balk At FAA Demand For 5G Deployment Delays Amid Shaky Safety Concerns (16)
19:53 Tenth Circuit Denies Qualified Immunity To Social Worker Who Fabricated A Mother's Confession Of Child Abuse (35)
15:39 Sci-Hub's Creator Thinks Academic Publishers, Not Her Site, Are The Real Threat To Science, And Says: 'Any Law Against Knowledge Is Fundamentally Unjust' (34)
13:32 Federal Court Tells Proud Boys Defendants That Raiding The Capitol Building Isn't Covered By The First Amendment (25)
12:14 US Courts Realizing They Have A Judge Alan Albright Sized Problem In Waco (17)
10:44 Boston Police Department Used Forfeiture Funds To Hide Purchase Of Surveillance Tech From City Reps (16)
10:39 Daily Deal: The Ultimate Microsoft Excel Training Bundle (0)
09:20 NY Senator Proposes Ridiculously Unconstitutional Social Media Law That Is The Mirror Opposite Of Equally Unconstitutional Laws In Florida & Texas (25)
06:12 Telecom Monopolies Are Exploiting Crappy U.S. Broadband Maps To Block Community Broadband Grant Requests (7)
12:00 Funniest/Most Insightful Comments Of 2021 At Techdirt (17)
10:00 Gaming Like It's 1926: Join The Fourth Annual Public Domain Game Jam (6)
09:00 New Year's Message: The Arc Of The Moral Universe Is A Twisty Path (33)
19:39 DHS, ICE Begin Body Camera Pilot Program With Surprisingly Good Policies In Place (7)
15:29 Remembering Techdirt Contributors Sherwin And Elliot (1)
13:32 DC Metro PD's Powerful Review Panel Keeps Giving Bad Cops Their Jobs Back (6)
12:11 Missouri Governor Still Expects Journalists To Be Prosecuted For Showing How His Admin Leaked Teacher Social Security Numbers (39)
10:48 Oversight Board Overturning Instagram Takedown Of Ayahuasca Post Demonstrates The Impossibility Of Content Moderation (10)
More arrow
This site, like most other sites on the web, uses cookies. For more information, see our privacy policy. Got it