Solia saysCommit-reveal hides intent through one block: users publish H(value, nonce) first, then reveal value+nonce later — front-runners cannot copy what they cannot see.
If a vote, bid, or random seed is visible in the mempool, anyone can copy it. Commit-reveal splits the transaction in two phases. In the commit phase you publish H(value, nonce) — a hash that hides both. In the reveal phase you publish value + nonce; the contract checks the hash matches and records the value. The mempool sees commitments only, so front-runners cannot extract what they need to copy.
The pattern powers sealed-bid auctions, MEV-resistant voting, and on-chain randomness via collective commit-reveal. The demo commits two votes, verifies correct reveals, and rejects a tampered one.
Power-ups you unlock
Phase 1 (commit): publish H(value, nonce)
Phase 2 (reveal): publish value + nonce; contract checks hash
Mempool sees only hashes during commit phase
Front-runners cannot copy a value they cannot see
Used in sealed bids, voting, randomness
The Reentrancy Reaper attacks — common mistakes
Committing without a nonce (small value sets get brute-forced)
Failing to enforce a reveal deadline (commitments never resolve)
Not slashing non-reveals (free option to abstain)
Reusing nonces across commitments
Boss battleCommit two votes with different nonces and show correct reveals verify while a tampered reveal fails.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre id="o"></pre>
<script>
const H = (v, n) => { let h=2166136261>>>0; for(const c of (v+'|'+n)){ h^=c.charCodeAt(0); h=Math.imul(h,16777619); } return (h>>>0).toString(16); };
const aliceCommit = H('vote=A', 'nonce-alice');
const bobCommit = H('vote=B', 'nonce-bob');
const reveal = (commit, vote, nonce) => H(vote, nonce) === commit;
document.getElementById('o').textContent = [
'COMMIT phase (mempool sees only hashes):',
' alice → ' + aliceCommit,
' bob → ' + bobCommit,
' (front-runner cannot tell which vote is which)',
'',
'REVEAL phase:',
' alice reveals "vote=A", nonce-alice → ' + reveal(aliceCommit, 'vote=A', 'nonce-alice'),
' bob reveals "vote=B", nonce-bob → ' + reveal(bobCommit, 'vote=B', 'nonce-bob'),
' tampered reveal "vote=B" with alice nonce → ' + reveal(aliceCommit, 'vote=B', 'nonce-alice') + ' (rejected)'
].join('\n');
</script></body></html>