Quoting, to re-read later.
Basically the simple-version is:
* wixiplay uses a unique server-seed per bet (and thus unique server-seed-hash per bet)
* To verify a bet, you need to record the sever-seed-hash *BEFORE* you bet (that way you know they didn't change the server seed in response to your bet)
* To get the the server-seed hash you have to go out of your way and specifically request it, for that bet
---
So what this means, is wixiplay knows if you're able to verify the bet or not. If you're not able to verify the bet, it has free-reign to undetectably cheat!
--
If BitwiseOperator played 523 coin-flips and only won 199, his maths is probably correct (I don't actually know off-hand to do that calculation, so I tried to simulate it. After 200 million simulations, it appears to only happen every 1 in ~5 million times, so it's definitely an (expected) real freak occurrence. )
Combined with the fact they're using a *totally pointless* nonce , makes me feel like they're trying to (maliciously?!) pass their system off their system as a traditional provably fair (which it's definitely not).