The history of casino security has an embarrassing chapter. In 1995, Ron Harris was a principal gaming agent for the Nevada Gaming Control Board. He had oversight authority over the exact machines he decided to hack.
He rigged keno machines at the Lilly Langtry Casino to pay out false winners. He cashed tickets that shouldn't have been valid. He stole approximately 100,000 dollars across several months. He was caught because his patterns were sloppy and his luck ran out.
What's worse: Harris also tried to plan a casino robbery using his position to disable security systems. He was involved with people planning a heist. That never materialized. If it had, it would have been catastrophic.
The Mechanism
Keno is a simple game. Eighty numbered balls. Players pick numbers. Twenty balls draw. If your picks match the draw, you win. A keno machine is a terminal that runs this game and prints tickets.
Harris's job was to audit these machines. To ensure they were programmed correctly, that the draws were random, that nobody was cheating.
What Harris did: He used his access and knowledge to identify which machines could be manipulated. He then generated winning tickets from machines that were malfunctioning in ways he understood. The machines would print a ticket saying Harris won when he didn't actually pick those numbers.
He'd cash the ticket. The casino would pay. The machine would show a payout. The books would supposedly balance. But the draw never happened or was different from the recorded draw.
This worked until the Lilly Langtry's back office noticed that certain machines were paying out more frequently than the statistical model predicted. They reported it. Investigation followed. Harris was identified.
Why This Matters
Gaming control boards exist to prevent cheating by casinos and operators. The idea is an external body with authority to audit, test, and inspect. Harris proved that authority without accountability becomes its own cheating vector.
Harris had all the tools. He had access to machine source code (probably). He had authority to be in the back rooms. He had knowledge of testing procedures. He was the person who was supposed to catch exactly what he was doing.
A private security company at least has reputational incentive to stay clean. A government agency has less. Harris was relatively junior within the Gaming Control Board. Nobody above him was scrutinizing his moves with intensity. He had space to operate.
The Aftermath
Harris pleaded guilty to casino cheating and conspiracy to commit robbery. He went to prison. Nevada beefed up its oversight processes.
But the lesson stuck: internal audit of gaming systems is inadequate. You need external audit too. Not just regulatory bodies auditing operators. Operators auditing regulatory bodies.
Modern casinos now employ third-party testing labs to validate gaming systems independently. Nevada Gaming Control Board checks are one layer. IGT or Spielo or Evolution Gaming's internal testing is another layer. Independent labs certified by the state provide a third layer.
No one person can have sole authority over security. This is the clearest rule that comes from Harris.
The Crypto Angle
The Harris scandal is cited every time someone proposes "provably fair" blockchain-based gaming. The argument is: you can't trust a centralized operator. You need an external mechanism (cryptographic verification) to prove that outcomes are honest.
The Harris case is actually an argument for this. A centralized operator with a single point of failure (one gaming control agent) can be compromised. A distributed system where outcomes are verified cryptographically is harder (not impossible, but harder) to compromise.
But provably fair gambling also has weaknesses. It can prove that draws were random. It can't prove that odds are set fairly. It can't ensure operators don't disappear with customer funds. It's a different problem, not a solution to all problems.
What Sticks
The Harris case was 30 years ago. Gaming security has evolved. Machines now have multiple processors. Draws are logged. Audits are automated. The kind of manual manipulation Harris did would be much harder today.
But the principle remains: wherever there's a single point of oversight, there's a single point of failure. Reduce that point. Distribute the checking. Make it so that no one person can audit themselves.
Ron Harris was good at his job. That was the problem. He knew too much about how the system worked. He had the skills to break it. He had the access to try. He had no guardian watching the guardian.
The casino that caught him wasn't the Gaming Control Board. It was simple statistics. A machine was paying out too much. The data did the work. The oversight system failed until the data screamed loud enough that someone listened.



