Zeeka saysA commitment locks in a value now and reveals it later: hiding (it leaks nothing) and binding (you cannot change it) — the basis of sealed bids and fair randomness.
A commitment scheme is a cryptographic sealed envelope. In the commit phase you publish H(value ‖ nonce) — that is all anyone sees. In the reveal phase you open the value and nonce, and anyone recomputes the hash to confirm it matches. Two properties make it useful: hiding (the commitment exposes nothing about the value) and binding (you cannot find a different value that produces the same commitment).
The nonce matters: without it, a small set of possible values can be brute-forced by trying each one. Commitments power commit-reveal voting (so early voters cannot sway later ones), sealed-bid auctions, and randomness beacons. The demo commits to a sealed bid and shows a correct reveal passing while a tampered value fails.
Power-ups you unlock
Commit phase publishes commit = H(value ‖ nonce)
Reveal phase opens value + nonce; anyone recomputes to check
Hiding: the commitment exposes nothing about the value
Binding: no second value yields the same commitment
Used in commit-reveal voting, auctions, and randomness
The Collision attacks — common mistakes
Committing with no nonce — small value sets are brute-forceable
Reusing a nonce across commitments
Assuming a commitment alone forces the reveal (add a deadline / penalty)
Using a broken or truncated hash
Boss battleCommit to a sealed bid with a nonce, then show a correct reveal verifies and a tampered value fails.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre id="o"></pre>
<script>
// commit = H(value ‖ nonce). hiding: leaks nothing. binding: can't restate.
const H = (s)=>{ let h=2166136261>>>0; for(const c of s){ h^=c.charCodeAt(0); h=Math.imul(h,16777619); } return (h>>>0).toString(16); };
const value = 'I bid 500', nonce = 'r-83f1a9';
const commitment = H(value + '|' + nonce);
const reveal = (v,r)=> H(v + '|' + r) === commitment;
document.getElementById('o').textContent = [
'COMMIT → publish only: ' + commitment,
' (hiding: "I bid 500" is not recoverable from this)',
'REVEAL → open with value + nonce, anyone recomputes:',
' correct reveal("I bid 500","r-83f1a9") = ' + reveal('I bid 500','r-83f1a9'),
' tampered reveal("I bid 900","r-83f1a9") = ' + reveal('I bid 900','r-83f1a9'),
'binding: no second value yields the same commitment'
].join('\n');
</script></body></html>