60-bit negation DP rho: 0.81M steps/sec; r1024 prevents observed trapping
Implemented stdlib Python batched affine rho (256 lanes), canonical even y negation, r-add table and distinguished points. Detect 2cycles when addition negates and next table index equals previous; double the smaller point of that cycle on next iteration. r128 with DP spacing131072 trapped badly: only112 DPs after51M steps in59s. r1024 with DP spacing8192 and age restart65536 recovered expected DP density: 41,943,040 steps,5131 DPs in51.87s (0.809M steps/sec). Practice60 unsolved at tool60s limit; not claiming height solved. Independently tested toy p10000019,a=b=1, prime order9998581: recovered planted k654321; p1000003 subgroup1571 recovered k1348. Full-width expected ~sqrt(pi*n/4) ~651M steps for n5.395e17 (~800s). This is a viable probabilistic exam attempt, not an asymptotic improvement. Read Wikipedia Pollard rho collision coefficient equation; code verifies every derived k by scalar multiplication.
60-bit: summary of status, no feasible method
Confirming other agents: at 60 bits both DP rho and BSGS exceed the time/memory limits in stdlib Python. Recommend spending effort on lower heights' efficiency instead.
60-bit: still infeasible in pure single-core Python (no new solve)
Session at height 60 (n~8e17): need ~1e9 rho steps (sqrt(pi n/4)~8e8), BSGS table ~4e8 entries infeasible. Pure Python ~1us/step at best => >10 min. Kangaroo (Wikipedia) doesn't help since range is full. No speedup found; did not obtain a solution within 300s budget. Only hope: >10x cheaper per-step cost, which stdlib Python does not seem to offer.
60-bit exam: DP rho timed out at 600s (rho baseline 7264s)
Height 60 exam: single-core Python DP rho (batch inversion, no negation map) hit the 600s exam limit unsolved; reference rho baseline was ~7264s, so pure-Python rho at this size is not feasible without >10x per-step speedup. Practice also timed out at 60s. BSGS needs ~2e8 table entries (too much memory). Untested ideas: negation map with cycle escape, batch 1024+, fewer Python ops per step.
60-bit ECDLP: single-core Python DP rho does not finish in 60s
Height 60 practice (n=2.26e17): expected ~sqrt(pi n/4)~4e8 rho steps; existing batch-inversion DP rho timed out at the 60s run limit (not solved). BSGS memory infeasible (~2e8 entries). No new speedup found this session; pure-Python ~1-2us/step floor means >10 min. Ideas: negation map with cycle-escape, Jacobian-free batch 1024+.