Technical Explainer

Do Wheel Spinners Use True Randomness?

By SelectAWheel Team · Published Oct 5, 2026 · 7 min read

Technical diagram comparing Math.random and crypto.getRandomValues in a browser context

If you've ever wondered whether an online wheel spinner is actually fair — or whether it could be quietly rigged to favor one entry over another — you're asking the right question. The answer depends entirely on which random number generator the tool uses behind the scenes.

In this explainer, we break down the two main approaches — Math.random() and crypto.getRandomValues() — and explain why the difference matters for classrooms, giveaways, and any context where fairness is non-negotiable.

What "Random" Actually Means in Software

Before we can compare the two, it's worth being clear about a subtle point: true randomness doesn't exist in software alone. Computers are deterministic machines. Given the same starting conditions, they produce the same outputs every time.

So when we say a tool is "random," we really mean one of two things:

  • Pseudo-random — the tool uses a mathematical algorithm that produces numbers that look random, but are technically predictable if you know the starting seed.
  • Cryptographically secure pseudo-random — the tool uses an algorithm seeded with real-world entropy (hardware timings, mouse movements, keyboard delays), making the output practically unpredictable.

The first category is fine for casual games. The second category is what you want for anything where fairness or security matters.

Approach 1: Math.random() — The Weak Default

Math.random() is the standard random function in every JavaScript environment. It's built into every browser. It's fast. And it's what most simple wheel spinners use.

Here's what happens when you call it:

// Returns a pseudo-random decimal between 0 and 1
const value = Math.random(); // e.g. 0.7234819...

// Typical use in a wheel spinner:
const index = Math.floor(Math.random() * entries.length);

The problem: Math.random() uses an internal pseudo-random algorithm with a finite seed. It's technically possible to reverse-engineer the seed by observing enough outputs — and if you know the seed, you can predict every future "random" number. This has real consequences in security-sensitive contexts, and it's why the ECMAScript specification says Math.random() is "not cryptographically secure."

For a casual game of "pick who pays for lunch," Math.random() is fine. For a $500 stream giveaway with 1,000 entries, it's a risk — small, but real.

Approach 2: crypto.getRandomValues() — The Secure Choice

crypto.getRandomValues() is the modern standard for random number generation in browsers. It's part of the Web Crypto API and produces numbers sourced from the operating system's cryptographically secure entropy pool.

Here's how SelectAWheel uses it:

function secureRandom(max) {
  if (max <= 0) return 0;
  const limit = Math.floor(4294967296 / max) * max;
  const buf = new Uint32Array(1);
  do {
    crypto.getRandomValues(buf);
  } while (buf[0] >= limit);
  return buf[0] % max;
}

There are two important details in this function that make it "fairer than fair":

  • Rejection sampling. The do/while loop discards outputs that would introduce modulo bias — a subtle but real distortion that occurs when you take a random number modulo a value that isn't a power of two. Most simple implementations skip this and end up slightly favoring low-index entries.
  • Cryptographic entropy. The crypto.getRandomValues() call itself is backed by the OS. Each call draws from high-entropy sources that an outside observer can't predict or reproduce.

The result: every entry has a mathematically verified equal chance of winning. No modulo bias. No seed predictability. No way to rig it.

Why This Matters for Real Use Cases

Classroom student selection

When you pick a student at random, the outcome is visible to twenty or thirty people. If the pattern repeats — the same three students getting picked first every week — students notice, and trust erodes. Crypto-secure randomness avoids the subtle clustering that weak RNGs can produce.

Stream giveaways and raffles

A giveaway with real prizes creates real stakes. If someone in chat suspects the wheel is rigged, you've lost them — and possibly a chunk of your community. A verifiable, cryptographically secure RNG proves you're running a fair game.

Legal and compliance contexts

Some jurisdictions have begun to require verifiable randomness for public raffles and prize draws. Using crypto.getRandomValues() gives you a defensible technical foundation if you ever need to demonstrate fairness.

How to Tell Which One a Tool Uses

You can verify any tool in about 10 seconds:

  1. Open the page. Right-click on the wheel and choose "Inspect" or press F12.
  2. Go to the Sources panel. Look for the main JavaScript file the tool loads.
  3. Search for "Math.random" and "crypto.getRandomValues". Use Ctrl+F in the source viewer. Whichever one appears in the spin logic is what the tool uses.
  4. Bonus check: if the tool uses crypto.getRandomValues but doesn't include rejection sampling, it may still have modulo bias. Look for a do/while loop nearby.

SelectAWheel uses crypto.getRandomValues() with rejection sampling. You can verify this yourself in your browser's DevTools.

The Practical Difference

For a one-time pick between two options, you won't notice any difference between the two approaches. Both will feel random.

But for 1,000+ spins, the difference becomes statistically visible. Weak RNGs can produce subtle clustering — the same few entries winning more often than they should. A crypto-secure RNG with rejection sampling produces a near-perfect uniform distribution.

If you want to see this for yourself, run our wheel 1,000 times and count how many times each entry wins. The distribution should be close to uniform. Some tools let you do this with a "verify randomness" feature; others don't expose it.

Bottom Line

Not all wheel spinners are equally random. The difference comes down to which random number generator the tool's developers chose to use. crypto.getRandomValues() is the modern, secure, and fair choice.

If you're running anything with real stakes — a classroom, a giveaway, a public raffle — it's worth checking that your tool uses it. It's a small detail that makes a big difference.

Author

SelectAWheel Team — we build and maintain the free SelectAWheel wheel spinner, which uses crypto.getRandomValues() with rejection sampling. Reach us at admin@selectawheel.com.

Try a Provably Fair Wheel Spinner

SelectAWheel uses cryptographically secure randomness with rejection sampling. Verify it yourself in DevTools.

Launch SelectAWheel →

Related Guides