When the lottery is genuinely +EV
In 2003 a geological statistician found that a scratch game's visible numbers leaked its hidden result. The interesting part is what he did next.
Most lottery "systems" fail because they try to predict a random draw. Mohan Srivastava's did not, because he was not looking at a random draw. He was looking at a printing problem.
Srivastava, a geological statistician in Toronto, picked up a tic-tac-toe scratch card in June 2003 while waiting for a large file to load. The card showed a set of visible numbers around the outside and hidden grids to be scratched; you won by completing a line.
His professional instinct was that the visible numbers could not be truly random, because the manufacturer had a constraint most people never think about: the card must be printed already knowing whether it is a winner. A scratch game's prize structure is fixed at printing — so many winners of each size per print run — and that information has to be encoded somewhere on the card. If the encoding leaks into the visible numbers, the card announces itself.
He tested it, and it did. He identified what became known as the singleton method: numbers appearing only once across the card's eight grids were disproportionately likely to be on a winning line. A card showing three singletons in a row, column or diagonal had a very good chance of being a winner. Working from the visible face alone, he could pick winners at a rate far better than chance (NPR).
This is the part worth the article.
He worked out roughly what it would earn him — sorting store stock at a few cards a minute for a modest hourly return — decided it was not worth his time compared with his actual job, and called the Ontario Lottery and Gaming Corporation to tell them.
Getting them to take him seriously reportedly took some effort. Once they did, the game was withdrawn.
Draw games and instant games fail in different ways, and conflating them is the commonest error in lottery folklore.
A draw game cannot leak. The numbers do not exist until the draw happens. There is no encoding, no manufactured artefact, no information channel — which is why every "prediction" claim about draw games is empty (lottery prediction software tested, AI lottery predictors).
An instant game is a manufactured object. The result exists before you buy it. The security question is not randomness but information leakage: does the visible face tell you anything about the concealed face? That is an engineering problem, with engineering failures.
Srivastava's find sits alongside the Cash WinFall roll-down as one of the two genuine categories of lottery exploit: rules that pay too much, and artefacts that leak. Neither involves predicting randomness, because randomness cannot be predicted.
Instant-game security is a real discipline, and the manufacturing controls that follow from cases like this include:
None of that removes the other honest problem with scratch cards, which is not security at all but arithmetic: the printed overall odds describe the full print run at the moment of printing, not the box in front of you. As big prizes are claimed, the remaining tickets get worse while the printed odds stay the same. That is the subject of why the odds printed on the back are not the odds you face, and you can work a specific game with the scratch card EV calculator using published prizes-remaining data.
1. Look at the rules and the object, not the numbers. Every documented lottery exploit came from reading a prize structure or examining a physical artefact. None came from analysing past draws.
2. Exploits are usually not worth it. Srivastava's own calculation — that sorting cards paid less than his day job — is the honest ending most of these stories lack. The Cash WinFall syndicates ran a similar margin at industrial scale for years.
3. Disclosure is the reason security improves. He could have quietly worked the flaw. He reported it, the game was pulled, and the industry's controls tightened. That is the same dynamic as responsible disclosure in software security, and it is why certified RNG testing and audit regimes exist at all.
Last verified: 2026-08-29