secp256k1 research state

One operator view for the current decision, formal substrate, evidence, active work, and generated trust checks.

Canonical snapshot snapshot 307 ledger rows / ~268 distinct
Scope boundary. The environment maps and verifies the research boundary. It does not solve the plain secp256k1 discrete logarithm problem. Monitoring means new evidence can reopen a route; it does not mean impossibility was proved.
307
ledger rows
~268
distinct results
179
proved modules
486
corpus claims
17
routes evaluated
8
typed cells
2
generated seeds
1
completed exact toy run

Current operating state

The decision layer controls what work is justified; proof volume does not select an attack route.

Reference deployment
AUTH-HYP-M16-FIXED-TARGET-YIELD-001-20260730-01Consumed toy run

One hash-bound synthetic-toy diagnostic completed.

HYP-M16-FIXED-TARGET-YIELD-001 / TASK-026 only: 3000000 primary trials across 3 frozen E_7 toy subgroups. Terminal: CLASSIFY_AS_KNOWN_LOCAL_SIMPLIFICATION; rerun authorized: false. Native Engine selection, direct secp256k1 work, solvers, and promotion remain closed. Structural selection RS-2026-07-24-001 remains unchanged.

Research Engine v0 queue

0 selected; 0 ready. Positive toy evidence is supported, never proved; threat-model scope, route decision, and evidence remain separate.

Native queue closed
No native Engine candidate clears every scientific gate.

The native queue remains empty; the exact external TASK-026 singleton is governed by the decision substrate. A future native candidate still requires both an exact mechanism and an independent raw-artifact validator.

Typed research questions

8 mechanism/property cells; 4 decided at desk; 2 seed-eligible questions; 2 submitted; 0 quality-cleared. Typed screens, seeds, and drafts authorize nothing.

Open evidence

Can this target-property cell be decided without an ECDLP run: Construct or rule out a fully priced auxiliary-curve instance over the secp256k1 base field under the exact PKC 2016 conditions. The answer must instantiate or refute the typed construction and price every named precomputation term.

HGS-5CC94AD51AE6 · CELL-M-PKC-AUXILIARY-CURVE · R-PETIT-COMPOSED-MAPS

The first output is a bounded arithmetic construction or no-instance record plus a complete precomputation estimate, not an ECDLP experiment.

Property resolution

Can an exact desk derivation price Total construction, representation, solving, and recovery cost of the corresponding S17 system. against the declared baseline before any solver run?

HGS-3266E42A729C · CELL-M-PKC-SMOOTH-M16 · R-PETIT-COMPOSED-MAPS

This open desk-cost cell has exact input presentations, an exact set-theoretic projective-tree bridge on the stated nonsingular characteristic domain, a complete named exceptional-fiber classification, deterministic control and secp256k1 GLV recovery checks, a frozen recursive projective S17 contract, kernel-checked fixed-degree projective resultant plus literal Sylvester unit-one and end-to-end common-root theorems, the actual frozenC specialization, the exact all-stage frozen projective witness chain, an exact literal finite MvPolynomial family in guarded form, an exact affine/infinity chart-polynomial cover for the frozen stage-14 predicate after injective base change, exact necessary infinity-stratum pruning, and exact conditional infinity propagation. Each fixed InfinityMask I uses 14 - I.card affine variables, no guard equations, and fifteen H equations with degree ceilings 2/4/2; the existential cover is exact and retains [1:0]. Affine external inputs reduce the exact logical cover from 16384 masks to 987 separated masks, and nonzero endpoint determinants conditionally reduce it to 377 interior masks. TASK-025 gives the nested local reductions 377 to 129 to 69 to 36 and the independent boundary-only branch 129 to 60. Under endpoint and BalancedPropagatedRegular assumptions it proves an exact single empty-mask affine chart, not a unique witness. The direct propagation applies over any field, but the source-stage bridge still requires injective base change into an algebraically closed target and separately assumed mapped-target regularity. Symbolic nonzeroness, nonemptiness, density, probability, and genericity are not proved, and source-field computation does not automatically establish mapped regularity. The 2^14 logical masks are not enumerated or materialized, and neither are the pruned families. It is not an expanded direct S17 polynomial, an unconditional base-field descent theorem, a solver run, or evidence of independent dimensions or relations. The complete cost bridge remains open. CQ-SEMAEV-S17-SYSTEM-COST remains partial; solving cost, rank, and yield remain unpriced. The scoped result has zero_retention_success and does not justify a production mask sweep, solver run, target computation, hypothesis retention, experiment authorization, cost inference, route rejection, or route promotion.

Desk cost

Why this decision

Canonical rationale, not a claim of impossibility

  • RS-2026-07-22-001 is historical after supersession; this current decision explicitly carries forward its zero-promotion assessment.
  • The owner selected the exact S3/S4 coordinatewise C3 polynomial classification and the S4 fixed-target consequence as the sole current structural uncertainty because they can resolve the premise of the naive GLV-Semaev quotient without an attack run.
  • Exact symbolic certificates and narrowly scoped Lean covariance theorems can reduce this uncertainty while preserving the parked experiment status and every P0-P4 result.
  • A diagonal-only result is a bounded no-go for independent u_i=x_i^3 quotienting, not a lower bound for Groebner/F4, faithful Petit, or the whole R-GLV-SEMAEV route.
  • A larger stabilizer would still require an exact quotient, recovery map, orbit tags, excluded components, cost prediction, and a later decision before any externally validated solver experiment.