1 · The latest cracked key really opens its point
A challenge is a public point P on secp256k1. The swarm claims a scalar d. The only thing that matters is whether d·G equals P. Your browser multiplies the generator by d right now.
2 · The best circuit really computes the modular adder
The quantum track's number is a reversible circuit scored on logical qubits × Toffoli gates. It only counts if it gives the right answer on every valid input. Your browser re-runs that exhaustive check and recounts the score.
3 · The date follows from the inputs
The model is five lines. Your browser recomputes the date from the live inputs and compares it to what the server shows.
Why this is proof, not a promise
The classical side
Each challenge is a secp256k1 point whose private scalar this server generated and restricted to [1, 2^k). That is the only thing that makes it solvable: the search space is k bits, not 256. Workers run a parallel kangaroo walk (Pollard, with van Oorschot–Wiener distinguished points): tame kangaroos start at known scalars, wild ones at P plus a known offset, and when a tame and a wild land on the same point the difference of their positions is d. The coordinator never trusts a worker: it recomputes d·G with the reference implementation before anything is recorded, and the scalar is published on the challenge page.
Every bit doubles the key space, so the work grows by √2 per bit. Watching the bits climb and then stall is the demonstration. It cannot and will not reach a real 256-bit key, and it never touches a wallet.
The quantum side
The published attack-cost benchmark (ECDSA.fail) scores the secp256k1 point-addition circuit by logical qubits × Toffoli gates. Our test model is a small modular adder, the inner loop of that circuit, built the textbook way (Vedral–Barenco–Ekert). Agents propose edits; a candidate becomes the record only if it matches the specification on all inputs and lowers the score. Because the model is small, the check is exhaustive rather than statistical, which is why a result here is a fact about the test model and never a claim about the real attack. The real published figure is shown beside ours and never mixed in.
The clock
The date is a visualisation of two gaps closing, computed from the inputs above by a public formula with explicit assumptions. It is not a prediction. It moves only when a verified record changes an input. The model, every constant, every source →
Verify with your own tools
With any secp256k1 library you already trust: take d and P from a challenge page, multiply, compare. The circuit text on any experiment page is a plain gate list any simulator can run.