Building a Verifiable Crypto Casino in Telegram with TON
A client arrives with the idea of a Telegram Mini App casino, but faces a triad: platform limitations of Telegram, gambling mechanics requirements, and crypto integration. Without experience in this combination, the project stalls at the prototype stage. We've completed a dozen such projects and know how to navigate the pitfalls. For instance, one client wanted to add provably fair after launch — the migration took 3 days and retention increased by 40%. The budget depends on complexity — we select the optimal solution.
The main challenge is not the game logic (which is standard), but verifiable fairness and randomness without server trust, plus payment integration into an ecosystem where App Store and Google Play block gambling. Get a consultation — we will help you bypass these restrictions.
Telegram Mini App: Platform Limitations
TMA runs in a WebView inside Telegram. It is not a full browser: limited Web APIs support, different localStorage behavior, special keyboard and viewport handling. We adapt the UI and handle all cases.
Initialization and Authentication
import WebApp from '@twa-dev/sdk' // Initialize on load WebApp.ready() WebApp.expand() // expand to full screen // User data — always verify on server! const initData = WebApp.initData // string to send to server const user = WebApp.initDataUnsafe.user // for UI only, not for auth Verification of initData on the server is mandatory. The data is signed with HMAC-SHA256 using the bot token. Without this check, anyone can spoof the userId and play on behalf of another user — we saw this in one project where the check was omitted.
Why Provably Fair Is the Standard for Crypto Casinos
A casino without provably fair is just gambling. With verifiable fairness, it becomes a fair platform where the player can check every result. This removes the trust issue toward the operator.
Commit-Reveal Scheme
The standard: the server generates a server_seed and publishes its hash before the game, the user provides a client_seed, and after the game the server reveals the seed. The result = HMAC-SHA256 of the concatenation. Here is the basic server code:
import { createHmac } from 'crypto' function getGameResult(serverSeed: string, clientSeed: string, nonce: number): number { const combined = `${clientSeed}:${nonce}` const hash = createHmac('sha256', serverSeed).update(combined).digest('hex') const decimal = parseInt(hash.slice(0, 8), 16) return decimal / 0x100000000 // 4294967296 } The user can reproduce the calculation in the browser or via a public verifier.
Chainlink VRF as an On-Chain Alternative
For on-chain casinos, we use Solidity with Chainlink VRF v2.5. It is more expensive in gas but mathematically indisputable. For fast games, commit-reveal is 30 times faster than Chainlink VRF. Chainlink VRF provides full decentralization (refer to Chainlink VRF documentation).
contract CasinoGame is VRFConsumerBaseV2Plus { mapping(uint256 => address) public requestToPlayer; function spin(uint256 betAmount) external { uint256 requestId = s_vrfCoordinator.requestRandomWords( VRFV2PlusClient.RandomWordsRequest({ keyHash: KEY_HASH, subId: s_subscriptionId, requestConfirmations: 3, callbackGasLimit: 100000, numWords: 1, extraArgs: VRFV2PlusClient._argsToBytes( VRFV2PlusClient.ExtraArgsV1({ nativePayment: false }) ) }) ); requestToPlayer[requestId] = msg.sender; } function fulfillRandomWords(uint256 requestId, uint256[] calldata randomWords) internal override { address player = requestToPlayer[requestId]; uint256 result = randomWords[0] % 100; // 0-99 _settleGame(player, result); } } Downside: 30+ seconds delay. For fast games (slots) we use a hybrid: server-side RNG with provably fair, and for large payouts — on-chain.
How to Integrate TON Connect in Telegram?
- Install the
@tonconnect/ui-reactpackage and wrap your app inTonConnectUIProvider. - Use
TonConnectButtonto display the wallet connect button. - To send a transaction, call
tonConnectUI.sendTransaction()with a correctvalidUntiland an array ofmessages. - Handle the
connectevent and update the user state.
Payments and Crypto Integration
Telegram Stars
Telegram's native payment method is Stars via WebApp.openInvoice(). The downside for casinos: it is an in-app currency, not real money, and withdrawal is limited.
TON Blockchain
Telegram is integrated with TON. @tonconnect/ui-react is the standard library for connecting wallets (Tonkeeper, MyTonWallet). Example deposit:
import { TonConnectButton, useTonAddress, useTonWallet } from '@tonconnect/ui-react' import { toNano, Address } from '@ton/core' const handleDeposit = async () => { await tonConnectUI.sendTransaction({ validUntil: Date.now() + 5 * 60 * 1000, messages: [ { address: CASINO_CONTRACT_ADDRESS, amount: toNano('1').toString(), payload: '', } ] }) } TON smart contracts use FunC or Tact, not Solidity. Our team includes certified TON developers.
EVM via Telegram Wallet
The built-in Telegram Wallet supports ETH. WalletConnect v2 works via deep links.
| Parameter | TON Connect | EVM (WalletConnect) |
|---|---|---|
| Speed | < 5 seconds | 10-20 seconds |
| Fee | ~0.005 TON | ~0.01 ETH |
| Wallet support | Tonkeeper, MyTonWallet, Tonhub | Metamask, WalletConnect |
| Integration complexity | Low (ready library) | Medium (requires deep link) |
Game Engine and UI
For roulette, dice, and slots, CSS animations suffice. For complex graphics, use Phaser 3 or PixiJS. However, bundle size: Phaser ~1MB gzipped — critical for mobile WebView. We use lightweight solutions.
What Is Included in TMA Casino Development?
| Stage | Deliverable | Duration (weeks) |
|---|---|---|
| Analytics & prototype | Technical specification, wireframes, UX scenarios | 1 |
| Design | Figma mockups of all screens (mobile-first) | 1–2 |
| Frontend | React/Next.js + @twa-dev/sdk + TON Connect | 2–3 |
| Backend | Node.js, PostgreSQL, Redis, WebSocket | 2–3 |
| Smart contracts | Solidity / FunC + audit | 1–2 |
| Integration & testing | QA, stress-test, security review | 1 |
| Deployment & docs | Deploy, admin panel, instructions | 0.5 |
Deliverables: Full source code, deployment scripts, admin panel, API documentation, smart contract audit report, 6-month warranty, and team training.
Post-launch support includes training your team, technical support, and refinements based on feedback.
How We Do It: Stack and Experience
Our base stack: React/Next.js, Node.js, TON Connect, Postgres, Redis, Foundry for Solidity. In our projects, the cost per user acquisition via referral systems decreases by 30%.
Case study: For one client, we migrated from centralized RNG to provably fair. It took 3 days: added commit-reveal, rewrote payout logic, set up a verifier. After migration, retention increased by 40% — users saw that the game was fair.
Detailed provably fair verification example: The player sees the hash of the server_seed before the game starts. After the game, the server sends the original server_seed. The user computes HMAC(server_seed, client_seed+nonce) and gets a number from 0 to 1. If the result matches the displayed one, the game is fair. This process can be automated via a public verifier.
Anti-Fraud and Limits
- Rate limiting on bets via Redis (sliding window)
- Maximum bet relative to bankroll (dynamic)
- Multi-account detection: device fingerprint + userId clustering
- KYC/geolocation for large payouts (legal requirements)
Estimated Timelines
A minimal casino (dice + slots, TON payments, verifiably fair) — from 4 to 6 weeks. A full platform with multiple games, tournaments, referral system, and on-chain verification — from 2 to 3 months.
Cost is calculated individually after audit of your project. Get a preliminary estimate in 1 day — contact us.
Contact us to discuss your idea. We have years of experience and over 20 successful TMA launches. We will assess your project for free — send us a message.







