Myths and strategy, tested
Modern draw nights are a chain of seals, scales, test draws and independent auditors, documented in operator procedures. The honest answer: the draws are extraordinarily well policed — and the real frauds were insiders.
"It's all rigged" is the cheapest sentence in gambling. It's also a testable claim, because major lotteries publish, or are compelled to disclose, exactly how their draws are run and checked. Read those documents and a picture emerges that most sceptics don't expect: draw night is one of the most paranoid, over-witnessed procedures in civilian life. Then read the actual fraud cases, and a second, more interesting picture emerges about where the real risk lives.
Two public documents give the flavour. The Texas Lottery Commission's internal audit of lottery drawings walks through the responsibility matrix for every draw, and the Pennsylvania Lottery's evening drawing procedures run to dozens of pages of scripted steps. Between them:
Statistical monitoring backstops the physical controls: decades of draw histories are public, and anyone — including this site — can run frequency and independence tests on them (try our randomness tester or the chi-square walkthrough on 'hot' numbers). National draw histories pass these tests boringly well.
Here is the honest part. The documented, prosecuted frauds against modern lotteries did not come from crooked balls or fixed broadcasts. They came from insiders attacking the parts the public can't see.
The definitive case is Eddie Tipton — the information-security director of the Multi-State Lottery Association itself, who planted code in the computerised random number generators used for certain games and, per the Iowa Lottery's statement at his sentencing, rigged draws across five states between 2005 and 2011 before being caught and sentenced to up to 25 years. The full story — the rootkit, the $16.5 million ticket that unravelled it — is in our companion piece, the Eddie Tipton hack. Note what the case proves in both directions: the RNG software was attackable by the one man who guarded it, and the surrounding audit-and-claims apparatus is what caught him — the suspicious anonymous claim was refused, the purchase video was published, and the whole scheme collapsed. The other recurring fraud pattern sits at the retail counter — clerks and insiders trying to steal winning tickets from customers — which again attacks the claims process, not the draw.
Are the draws rigged? No — for televised ball draws run by national and state operators, the layered controls (seals, custody logs, randomised machine selection, weighing, test draws, external auditors, live broadcast, public statistical history) make tampering somewhere between impractical and instantly visible. Nobody has ever been shown to have fixed a modern, audited, televised ball draw.
Is the system attack-proof? Also no — and the operators know it, which is why the paranoia budget exists. The realistic threat model was never "the balls are fake"; it was "someone inside touched the machinery nobody watches". That is exactly the class of attack Tipton executed against software draws, and it's the strongest practical argument for the transparency of physical machines — a trade-off we weigh properly in physical draws vs software draws.
If you suspect a draw, you don't need to trust anyone: pull the public results history for your game — Powerball's, UK Lotto's — and test it yourself. Rigging changes frequencies; frequencies are public; the maths for catching them is a century old. The most reassuring thing about modern lotteries is precisely that you're allowed to check.
Last verified: 2026-08-29