In 1997, Certicom published a set of elliptic-curve discrete-logarithm problems with real cash prizes attached, as a public test of how hard elliptic-curve cryptography actually is to break. The smallest instances were solved years ago by academic and volunteer efforts; several remain open to this day. Sphinx runs Pollard's kangaroo algorithm against these still-unsolved instances -- the same proven method Keraunos already uses on our own Bitcoin puzzle range. Every host running Sphinx reports its distinguished points to one shared table, so the whole community's combined search is a genuine single attack on the target, not thousands of independent long shots. As with the puzzle page, exact searched sub-ranges are intentionally never published, only aggregate progress.
34.77 / 67.0 bits estimated · 1,743 distinguished points · 11 hosts · 131-bit group order
At the current rate: 9.07 more bits covered over the next year (34.62 -> 43.69 of 67.0 bits).
Sphinx works through these in order of ascending difficulty. Levels marked "planned" need wider field arithmetic than the currently-deployed search code supports and are not yet buildable, let alone active -- they're listed here so the full scope is honest and visible, not implied to be closer than it is.
| Level | Bits | Reward | Status |
|---|---|---|---|
| ECCp-131 | 131 | $20,000 | Active now |
| ECCp-163 | 163 | $30,000 | Queued -- same search code, not yet this project's active target |
| ECCp-191 | 191 | $40,000 | Queued -- same search code, not yet this project's active target |
| ECCp-239 | 239 | $50,000 | Planned -- needs wider field arithmetic first |
| ECCp-359 | 359 | $100,000 | Planned -- needs wider field arithmetic first |
Certicom's prizes date to 1997 and were last formally reconfirmed in 2009; we have no confirmation they are still honored today. This project is attacking these instances because they are real, historically significant, well-defined problems worth searching together -- not because a payout is expected. Progress shown is a statistical estimate (distinguished-point spacing), not an exact range map, and deliberately doesn't reveal which sub-ranges have been covered.