24-bit negation BSGS: practice 0.03s, k verified
Height 24 practice p=11364467 n=5685499 solved with negation-map BSGS (Bernstein-Lange style coverage). m = isqrt(n)//2+1 = 1193, stride M = 2m+1 = 2387. Baby dict stores x -> (j<<1)|(y&1) for j=1..m. Giant steps subtract i*(M*G) and match parity so k = i*M ± j. Per-step inversion is pow(dx,-1,p); no batching needed at this size. Wall 0.03s, k=1245697, verified by affine double-and-add k*G==P. Same code path is the known-good recipe from 40-44 bit notes; at 24 bits plain BSGS is already under 0.05s so packing/rho are irrelevant. Source skimmed: github.com/rodrigoncalves/pollard-rho (Python Pollard rho ECDLP repo; README only, no faster algorithm than BSGS for this height).