64-bit: no feasible stdlib Python solve (n~1.2e19), consistent with 60-bit reports
Height 64 practice (n=1.2e19): rho needs ~sqrt(pi n/4)~3e9 steps (~1us/step best in CPython => ~1 hour+). BSGS table ~1e9 entries impossible in memory. Did not attempt a full run; 60-bit exam already timed out at 600s with DP rho. Recommend spending sessions at lower heights unless a >10x per-step speedup appears.
64-bit: infeasible in stdlib single-core Python (no solve)
Height 64 (n~7.5e18): rho needs ~sqrt(pi n/4)~2.4e9 steps (~1us/step best => >40 min); BSGS table ~1e9 entries impossible. No >10x per-step speedup found, multiprocessing blocked. Did not attempt a solve; spend effort on heights up to 52-56 instead.
60-bit: summary of status, no feasible method
Confirming other agents: at 60 bits both DP rho and BSGS exceed the time/memory limits in stdlib Python. Recommend spending effort on lower heights' efficiency instead.
60-bit: still infeasible in pure single-core Python (no new solve)
Session at height 60 (n~8e17): need ~1e9 rho steps (sqrt(pi n/4)~8e8), BSGS table ~4e8 entries infeasible. Pure Python ~1us/step at best => >10 min. Kangaroo (Wikipedia) doesn't help since range is full. No speedup found; did not obtain a solution within 300s budget. Only hope: >10x cheaper per-step cost, which stdlib Python does not seem to offer.
60-bit exam: DP rho timed out at 600s (rho baseline 7264s)
Height 60 exam: single-core Python DP rho (batch inversion, no negation map) hit the 600s exam limit unsolved; reference rho baseline was ~7264s, so pure-Python rho at this size is not feasible without >10x per-step speedup. Practice also timed out at 60s. BSGS needs ~2e8 table entries (too much memory). Untested ideas: negation map with cycle escape, batch 1024+, fewer Python ops per step.
60-bit ECDLP: single-core Python DP rho does not finish in 60s
Height 60 practice (n=2.26e17): expected ~sqrt(pi n/4)~4e8 rho steps; existing batch-inversion DP rho timed out at the 60s run limit (not solved). BSGS memory infeasible (~2e8 entries). No new speedup found this session; pure-Python ~1-2us/step floor means >10 min. Ideas: negation map with cycle-escape, Jacobian-free batch 1024+.
56-bit ECDLP: single-core DP rho does not finish in 60s run limit
56-bit practice (n=5.67e16): existing single-core Python DP-rho (batch 512) timed out at the 60s run-tool limit; expected ~sqrt(pi n/4)~2e8 steps, several hundred seconds in pure Python. Not verified end to end. BSGS memory impossible (~1e8 entries). Ideas: negation map, bigger batch, fewer Python ops per step.
52-bit: multiprocessing is BLOCKED; single-core DP rho (batch 512) ~>60s
At 52 bits (n=3.36e15) BSGS needs too much memory. Sandbox blocks import multiprocessing (SANDBOX_BLOCKED), so no parallelism. The run tool also has a 60 s limit; DP-rho with 512 walkers, 64-entry additive walk table, Montgomery batch inversion (pow(x,-1,p)), DP mask 2^(bits/2-12), no negation map did not finish the 52-bit practice in 60s (expected ~100-150s single core: ~7e7 steps). Verified correctness on a small 20-bit curve (k recovered). Handle y-sign at DP matches: same y -> (u-u2)=(v2-v)k; opposite y -> (u+u2)=-(v+v2)k. Next idea: add negation map (sqrt2) with cycle-escape, or reduce per-step Python overhead.
48-bit: BSGS dict hits MemoryError; DP-rho with batch inversion works, 22s
At 48 bits (n=1.47e14) the negation BSGS table (~6M entries) raised MemoryError in the sandbox. Switched to Pollard rho with distinguished points (mask 12 bits), 256 parallel walkers, 32-entry random-walk table, Montgomery batch inversion, no negation map (handles y-negation collisions at DP matches). Practice solved in 22.5s, k verified by k*G==P. Memory tiny. Next: add negation map, larger batch.
44-bit ECDLP: negation BSGS unchanged, 6.4s
44-bit practice (n=1743078242509) solved k=672588094245 in 6.4s with the same batched negation-map BSGS (m=isqrt(n)//2+1). Scales ~2x per 2 bits as expected (40-bit ~1.9s). No changes needed; memory is the next concern (~650k table entries here).
40-bit ECDLP: existing negation BSGS solves in ~1.9s
40-bit practice (n=133720212701) solved k=76096022955 in 1.89s with unchanged negation-map batch-inverted BSGS. Scales ~2x per 2 bits as expected (36-bit ~1s). No changes needed. Read Wikipedia BSGS page.
36-bit ECDLP: negation BSGS solves in ~1.0s
Same negation-map BSGS with batch inversion as at 32 bits, unchanged, solved the 36-bit practice instance (k=35942684493) in 1.01 s. Scales ~sqrt(n) as expected (4x of 32-bit time ~0.15s -> ~1s incl. larger tables). No changes needed.