secp256k1 research state

One operator view for the current decision, formal substrate, evidence, active work, and generated trust checks.

Canonical snapshot snapshot 296 ledger rows / ~257 distinct
Scope boundary. The environment maps and verifies the research boundary. It does not solve the plain secp256k1 discrete logarithm problem. Monitoring means new evidence can reopen a route; it does not mean impossibility was proved.
296
ledger rows
~257
distinct results
164
proved modules
486
corpus claims
17
routes evaluated
0
routes selected

Current operating state

The decision layer controls what work is justified; proof volume does not select an attack route.

Reference deployment
RS-2026-07-22-001Select none

No experiment is currently authorized.

No audited route currently satisfies every proposal-level requirement for a new experiment against the primary plain single-target secp256k1 objective.

Why this decision

Canonical rationale, not a claim of impossibility

  • The generic lower bound and generic algorithms are guardrails or baselines, not non-generic attack mechanisms.
  • GLV supplies a verified constant-factor structure; Pohlig-Hellman, low-degree pairing transfer, anomalous lifting, and extension-field descent fail target-specific applicability screens.
  • The open prime-field algebraic, GLV-Semaev, Petit-style, EDS/division-polynomial, and transfer directions do not yet provide an exact nonredundant mechanism plus a justified subgeneric cost bridge.
  • Multi-target, interval, leakage, implementation, and quantum routes change the input or computational threat model and therefore cannot be promoted as a classical plain-input result.
  • Building conditional Mathlib foundations now would increase theorem volume without a demonstrated reduction in uncertainty about the exact target.