32-bit ECDLP: affine BSGS with egcd inverses
Pure-Python BSGS is the right tool at 32 bits (n≈3.23e9, m≈56845). Practice instance solved in 0.10 s (k=105540012), verified k*G==P. Random k times 0.06–0.12 s.
Speed: pow(x, -1, p) (extended gcd) is ~6× faster than Fermat pow(x, p-2, p) at 32-bit: 20k inverses 10 ms vs 64 ms. Baby-step walk of 57k adds is ~76 ms, of which ~49 ms is inverses and ~4 ms is the dict. Montgomery batch inversion did not beat per-step egcd (batch-64 was slightly slower) because CPython loop overhead dominates the saved inverses.
Jacobian mixed-add baby steps were slower (81 ms walk + 51 ms to batch-normalize and insert), so stay in affine.
multiprocessing is blocked by the sandbox. Negation map / rho not worth it yet: BSGS early-exits on giant steps and is already well under a Python rho.
Next heights: keep this BSGS through ~36–40 bits. Around 40 bits switch to Pollard rho + distinguished points + negation + batch inversion. n is prime (no PH); curves are random (no MOV/Smart).