Verifiable Random Functions
How VRFs produce randomness that's both unpredictable before commitment and cryptographically verifiable after — enabling fair lotteries, leader election, and on-chain randomness without trusted parties.
Why On-Chain Randomness Is Hard
Blockchains are deterministic — every node has to compute the same answer given the same inputs. Real randomness doesn't fit. But many applications need randomness: NFT trait reveals, lottery winners, game outcomes, validator selection for the next block. Using `block.timestamp` or `blockhash` is unsafe because miners can manipulate them within their slot. Every chain needs a credible answer.
What a VRF Does
A Verifiable Random Function takes an input (e.g., a block hash, a seed) and a private key, and produces two things: a pseudo-random output, and a proof that the output was correctly computed from the input and key. The output looks random to anyone who doesn't hold the private key, but anyone can verify the proof matches. So you get: unpredictable before computation, verifiable after.
Chainlink VRF — The Production Standard
Chainlink VRF is the most widely-used on-chain randomness source. A smart contract requests randomness, paying a fee in LINK. The VRF coordinator (a Chainlink oracle) computes a VRF using its private key and the contract's request, and posts the output plus proof on-chain. The contract verifies the proof and uses the output. Used by major NFT projects, on-chain games, and DAO lottery mechanisms.
- Block hashes are unsafe — miners can manipulate them
- VRFs give unpredictable output + verifiable proof
- Chainlink VRF is the production standard for EVM chains
- Used by: NFT trait reveals, lotteries, on-chain games, DAO leader election
Key Takeaways
- On-chain randomness without VRFs is unsafe — block fields are manipulable
- VRFs produce unpredictable output + verifiable proof of correctness
- Chainlink VRF is the dominant production solution
- Common uses: NFT reveals, lotteries, games, validator selection
Related Content
Related Coins
Key Terms
More Topics
Browse all 179 topicsState Pruning and Expiry
Why Ethereum's state has grown to hundreds of gigabytes, what 'archive,' 'full,' and 'light' nodes actually store, and how proposals like EIP-4444 and Verkle trees aim to keep node hardware accessible for years to come.
ECDSA vs EdDSA vs BLS
The three signature schemes you'll meet across the crypto stack — what each does well, what tradeoffs they impose, and why Ethereum uses three of them simultaneously.
zk-SNARK vs zk-STARK vs PLONK
How the three major proof-system families compare on trusted setup, proof size, prover cost, and quantum resistance — and which production rollups picked which.
Threshold Signatures and MPC
How t-of-n threshold signatures and multi-party computation let multiple parties sign together without any one holding the full key — the cryptography behind Fireblocks, Lit Protocol, and modern institutional custody.
Hash Functions Compared
SHA-256, Keccak-256, Blake3, and Poseidon — which one each chain uses, why ZK systems needed a new family of 'arithmetic-friendly' hashes, and what tradeoffs each makes.
Stealth Addresses and Confidential Transactions
Privacy primitives that hide who's receiving what — from Monero's foundational stealth addresses to Ethereum's ERC-5564 and the legal context post-Tornado-Cash.
CDP Lifecycle
How collateralized debt positions work end-to-end — minting DAI against ETH, paying stability fees, surviving liquidations, and the structural lessons from MakerDAO's Black Thursday and Liquity's no-fee model.
Perpetual Swap Mechanics
How perp futures actually work — funding rates that keep them pegged to spot, mark vs index price, insurance funds that backstop losses, and the liquidation cascades that wreck overleveraged accounts in seconds.
References & further reading
- secondary
- secondary