BitBOINC

BitBOINC

Sphinx: Certicom ECC Challenge progress

In 1997, Certicom published a set of elliptic-curve discrete-logarithm problems with real cash prizes attached, as a public test of how hard elliptic-curve cryptography actually is to break. The smallest instances were solved years ago by academic and volunteer efforts; several remain open to this day. Sphinx runs Pollard's kangaroo algorithm against these still-unsolved instances -- the same proven method Keraunos already uses on our own Bitcoin puzzle range. Every host running Sphinx reports its distinguished points to one shared table, so the whole community's combined search is a genuine single attack on the target, not thousands of independent long shots. As with the puzzle page, exact searched sub-ranges are intentionally never published, only aggregate progress.

1
challenge(s) actively being searched
5
unsolved Certicom levels tracked
$240,000
combined nominal reward, still open

Active search

ECCp-131 · $20,000

34.77 / 67.0 bits estimated · 1,743 distinguished points · 11 hosts · 131-bit group order

At the current rate: 9.07 more bits covered over the next year (34.62 -> 43.69 of 67.0 bits).

Every Certicom level this project tracks

Sphinx works through these in order of ascending difficulty. Levels marked "planned" need wider field arithmetic than the currently-deployed search code supports and are not yet buildable, let alone active -- they're listed here so the full scope is honest and visible, not implied to be closer than it is.

LevelBitsRewardStatus
ECCp-131 131 $20,000 Active now
ECCp-163 163 $30,000 Queued -- same search code, not yet this project's active target
ECCp-191 191 $40,000 Queued -- same search code, not yet this project's active target
ECCp-239 239 $50,000 Planned -- needs wider field arithmetic first
ECCp-359 359 $100,000 Planned -- needs wider field arithmetic first

Certicom's prizes date to 1997 and were last formally reconfirmed in 2009; we have no confirmation they are still honored today. This project is attacking these instances because they are real, historically significant, well-defined problems worth searching together -- not because a payout is expected. Progress shown is a statistical estimate (distinguished-point spacing), not an exact range map, and deliberately doesn't reveal which sub-ranges have been covered.