How the Hot Lotto was rigged: the security director who wrote the numbers
The man who rigged the Hot Lotto drawing was the lottery group's own information security director, and he wrote the software that picked the numbers.[1] This case file covers how he built a hidden exception into that software, how an unclaimed $16.5 million ticket gave him away, and the one control that would have stopped it.
What happened
Eddie Tipton worked in IT at the Multi-State Lottery Association, the nonprofit that runs shared games such as Powerball and Hot Lotto for member state lotteries, from 2003 until 2015.[6] He rose to information security director and helped write the code for the random number generator used in its drawings.[3][6] Starting in 2005, rigged drawings paid out in Colorado, Wisconsin, Kansas and Oklahoma, with prizes claimed by his brother, a friend in Texas and others who split the money with him.[4][5][6]
On December 23, 2010, a man in a hooded sweatshirt and ball cap bought Hot Lotto tickets at a QuikTrip in Des Moines. Six days later, on December 29, one of them matched every number in a drawing with an advertised jackpot of $16.5 million, or about $14.3 million as a lump sum.[1][2][3]
Nobody came forward for 11 months. In November 2011 a lawyer in Quebec called the Iowa Lottery with the ticket's serial number but could not explain how it was bought. On December 29, 2011, less than 2 hours before the one-year deadline, a law firm presented the ticket on behalf of a New York trust whose beneficiary was a company in Belize.[2][3] Iowa does not pay anonymous winners, and when lottery officials pressed for the names behind the trust, the claim was withdrawn in January 2012. The prize was never paid.[2][3]
How it worked
The drawing computer was supposed to be unpredictable. It took a reading from a Geiger counter measuring natural radiation in the room and used that as the starting point, or "seed," for picking numbers from nearly 11 million possible combinations.[3]
Tipton's version of the software carried an extra rule. On most days it behaved normally. But when a drawing fell on one of 3 specific dates a year, in late May, late November and late December, and on a Wednesday or Saturday evening, it quietly swapped the real seed for a predictable one.[3][5] That shrank the possible outcomes from millions to a small set that could be worked out in advance. The chosen dates tended to fall around holidays, when he was often away on vacation.[3]
Prosecutors said the altered code was loaded onto the drawing computers from a thumb drive and was designed to delete itself afterward.[1] In short, the person trusted to protect the machine was also the person who wrote its code and could change what ran on it.
How it was caught
The unclaimed ticket, not a security alert, broke the case. After the withdrawn claim, the Iowa Attorney General's office and the state Division of Criminal Investigation opened a criminal investigation.[2] In October 2014 investigators released the store surveillance clip to the public.[3]
The face was hard to see, but the voice was not. A Maine Lottery employee, an Iowa Lottery web developer and the association's own drawing manager each recognized the buyer's distinctive way of speaking as Tipton's.[3] He was arrested in January 2015 and convicted by a jury on July 20, 2015.[3] Investigators later found the altered code, and the other rigged jackpots came to light.[1][4]
What it cost
In June 2017 Tipton pleaded guilty in Iowa to ongoing criminal conduct, telling the court he wrote software with code that let him predict winning numbers.[5] He also pleaded guilty in Wisconsin to theft by fraud and computer crime.[2][4] On August 22, 2017, he was sentenced to up to 25 years in prison.[7] His brother pleaded guilty to conspiracy and served 75 days in jail, and a Texas friend pleaded guilty to a computer crime.[2][6]
The rigged prizes paid out about $2.2 million, and the brothers agreed to pay $2.2 million in restitution to the Colorado, Kansas, Oklahoma and Wisconsin lotteries.[2][6] Tipton was paroled in July 2022 after about 5 years.[8] Hot Lotto itself was retired in October 2017.[3]
The missing control
The missing control: segregation of duties. One person wrote the random number code, had the access to install and change it, and was in charge of the security meant to catch tampering, with no independent review in between.
Splitting those jobs would have stopped this or cut it short. If a second person had to review every change, the odd rule would have raised an obvious question: why does a random number generator care what day it is? If someone else built and installed the approved version, and checked that the running software matched it, a quiet swap would have stood out. The scheme lasted from 2005 to 2011 because no one other than its author was looking inside.[4][5]
What to do in your business
- List who can both make and approve changes. For payroll, vendor payments, bank details and key software, write down who can change them and who signs off. Any name that appears in both columns is a gap.
- Require a second set of eyes. Set a simple rule that changes to money-moving systems or core software need approval from someone who did not make the change, even in a 5-person office.
- Keep your tech person out of their own audit. If one employee or IT contractor runs your systems, have an outside party review access and logs once a year.
- Watch results, not just logs. Look for patterns in outcomes, such as refunds, discounts or payouts that keep landing with the same people or on the same dates.
- Make vacations real. Require people in sensitive roles to take time off while someone else covers their duties. Hidden schemes often surface when the person behind them is not there to manage them.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the Target breach happened: a vendor's billing login and the alarms nobody answered
- How the Bangladesh Bank heist happened: $81 million over SWIFT, stopped short by a typo
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- What caused the Equifax breach? An unpatched website and an expired certificate
- How the Capital One breach happened: one misconfigured cloud firewall
Facts are drawn from court records, government reports and reputable reporting, listed below. People are named only where they were convicted or spoke publicly in an official role.
- Sophos Naked Security: Insider who scammed $14.3m lottery win pleads guilty
- Iowa Lottery: Statement following Eddie Tipton sentencing
- Lottery Post: The man who cracked the lottery (republished from The New York Times Magazine)
- Colorado Attorney General via Colorado Bureau of Investigation: AG Coffman announces guilty plea of man who stole millions in multi-state lottery fraud case
- CBS Colorado: Mastermind of lottery fraud admits he rigged jackpots
- NBC News: Former lottery executive gets 25 years for rigging numbers in four states
- Time: Eddie Tipton sentenced to 25 years for lotto scam
- Axios Des Moines: Man behind largest lottery scam in U.S. history paroled from Iowa prison