Crack the key that was never really random

AES-256, RSA-4096 — the biggest algorithms available — and none of it matters if the key comes from a source with only a few thousand possible values. You never see the secret seed, only a published one-way commitment to it. Can you still recover the exact key, using nothing but the server's own functions, run for real in your browser?

The only thing that ever left the server:

What you compute (real expand()/commit(), looped for real):

Recovered key

Verifier A — the real deployment's actual seed source

commit(expand(seed)) == published commitment ?

Verifier B — the design's intended 2128 keyspace

same functions, projected onto a true random seed