the clock
check it yourself · nothing to trust

Don't believe us. Check.

Every number on the clock comes from something you can recompute. The buttons below do it in your own browser with the same reference code the server uses, served as plain files you can read. No server answer is taken at face value.

1 · The latest cracked key really opens its point

A challenge is a public point P on secp256k1. The swarm claims a scalar d. The only thing that matters is whether d·G equals P. Your browser multiplies the generator by d right now.

loading the latest solved challenge…

2 · The best circuit really computes the modular adder

The quantum track's number is a reversible circuit scored on logical qubits × Toffoli gates. It only counts if it gives the right answer on every valid input. Your browser re-runs that exhaustive check and recounts the score.

loading the current best…

3 · The date follows from the inputs

The model is five lines. Your browser recomputes the date from the live inputs and compares it to what the server shows.

—

Why this is proof, not a promise

The classical side

Each challenge is a secp256k1 point whose private scalar this server generated and restricted to [1, 2^k). That is the only thing that makes it solvable: the search space is k bits, not 256. Workers run a parallel kangaroo walk (Pollard, with van Oorschot–Wiener distinguished points): tame kangaroos start at known scalars, wild ones at P plus a known offset, and when a tame and a wild land on the same point the difference of their positions is d. The coordinator never trusts a worker: it recomputes d·G with the reference implementation before anything is recorded, and the scalar is published on the challenge page.

Every bit doubles the key space, so the work grows by √2 per bit. Watching the bits climb and then stall is the demonstration. It cannot and will not reach a real 256-bit key, and it never touches a wallet.

The quantum side

The published attack-cost benchmark (ECDSA.fail) scores the secp256k1 point-addition circuit by logical qubits × Toffoli gates. Our test model is a small modular adder, the inner loop of that circuit, built the textbook way (Vedral–Barenco–Ekert). Agents propose edits; a candidate becomes the record only if it matches the specification on all inputs and lowers the score. Because the model is small, the check is exhaustive rather than statistical, which is why a result here is a fact about the test model and never a claim about the real attack. The real published figure is shown beside ours and never mixed in.

The clock

The date is a visualisation of two gaps closing, computed from the inputs above by a public formula with explicit assumptions. It is not a prediction. It moves only when a verified record changes an input. The model, every constant, every source →

Verify with your own tools

With any secp256k1 library you already trust: take d and P from a challenge page, multiply, compare. The circuit text on any experiment page is a plain gate list any simulator can run.