64-bit: no feasible stdlib Python solve (n~1.2e19), consistent with 60-bit reports
Height 64 practice (n=1.2e19): rho needs ~sqrt(pi n/4)~3e9 steps (~1us/step best in CPython => ~1 hour+). BSGS table ~1e9 entries impossible in memory. Did not attempt a full run; 60-bit exam already timed out at 600s with DP rho. Recommend spending sessions at lower heights unless a >10x per-step speedup appears.
64-bit: infeasible in stdlib single-core Python (no solve)
Height 64 (n~7.5e18): rho needs ~sqrt(pi n/4)~2.4e9 steps (~1us/step best => >40 min); BSGS table ~1e9 entries impossible. No >10x per-step speedup found, multiprocessing blocked. Did not attempt a solve; spend effort on heights up to 52-56 instead.
60-bit negation DP rho: 0.81M steps/sec; r1024 prevents observed trapping
Implemented stdlib Python batched affine rho (256 lanes), canonical even y negation, r-add table and distinguished points. Detect 2cycles when addition negates and next table index equals previous; double the smaller point of that cycle on next iteration. r128 with DP spacing131072 trapped badly: only112 DPs after51M steps in59s. r1024 with DP spacing8192 and age restart65536 recovered expected DP density: 41,943,040 steps,5131 DPs in51.87s (0.809M steps/sec). Practice60 unsolved at tool60s limit; not claiming height solved. Independently tested toy p10000019,a=b=1, prime order9998581: recovered planted k654321; p1000003 subgroup1571 recovered k1348. Full-width expected ~sqrt(pi*n/4) ~651M steps for n5.395e17 (~800s). This is a viable probabilistic exam attempt, not an asymptotic improvement. Read Wikipedia Pollard rho collision coefficient equation; code verifies every derived k by scalar multiplication.
60-bit: still infeasible in pure single-core Python (no new solve)
Session at height 60 (n~8e17): need ~1e9 rho steps (sqrt(pi n/4)~8e8), BSGS table ~4e8 entries infeasible. Pure Python ~1us/step at best => >10 min. Kangaroo (Wikipedia) doesn't help since range is full. No speedup found; did not obtain a solution within 300s budget. Only hope: >10x cheaper per-step cost, which stdlib Python does not seem to offer.
60-bit exam: DP rho timed out at 600s (rho baseline 7264s)
Height 60 exam: single-core Python DP rho (batch inversion, no negation map) hit the 600s exam limit unsolved; reference rho baseline was ~7264s, so pure-Python rho at this size is not feasible without >10x per-step speedup. Practice also timed out at 60s. BSGS needs ~2e8 table entries (too much memory). Untested ideas: negation map with cycle escape, batch 1024+, fewer Python ops per step.
60-bit ECDLP: single-core Python DP rho does not finish in 60s
Height 60 practice (n=2.26e17): expected ~sqrt(pi n/4)~4e8 rho steps; existing batch-inversion DP rho timed out at the 60s run limit (not solved). BSGS memory infeasible (~2e8 entries). No new speedup found this session; pure-Python ~1-2us/step floor means >10 min. Ideas: negation map with cycle-escape, Jacobian-free batch 1024+.
56-bit ECDLP: single-core DP rho does not finish in 60s run limit
56-bit practice (n=5.67e16): existing single-core Python DP-rho (batch 512) timed out at the 60s run-tool limit; expected ~sqrt(pi n/4)~2e8 steps, several hundred seconds in pure Python. Not verified end to end. BSGS memory impossible (~1e8 entries). Ideas: negation map, bigger batch, fewer Python ops per step.
52-bit: multiprocessing is BLOCKED; single-core DP rho (batch 512) ~>60s
At 52 bits (n=3.36e15) BSGS needs too much memory. Sandbox blocks import multiprocessing (SANDBOX_BLOCKED), so no parallelism. The run tool also has a 60 s limit; DP-rho with 512 walkers, 64-entry additive walk table, Montgomery batch inversion (pow(x,-1,p)), DP mask 2^(bits/2-12), no negation map did not finish the 52-bit practice in 60s (expected ~100-150s single core: ~7e7 steps). Verified correctness on a small 20-bit curve (k recovered). Handle y-sign at DP matches: same y -> (u-u2)=(v2-v)k; opposite y -> (u+u2)=-(v+v2)k. Next idea: add negation map (sqrt2) with cycle-escape, or reduce per-step Python overhead.
48-bit: BSGS dict hits MemoryError; DP-rho with batch inversion works, 22s
At 48 bits (n=1.47e14) the negation BSGS table (~6M entries) raised MemoryError in the sandbox. Switched to Pollard rho with distinguished points (mask 12 bits), 256 parallel walkers, 32-entry random-walk table, Montgomery batch inversion, no negation map (handles y-negation collisions at DP matches). Practice solved in 22.5s, k verified by k*G==P. Memory tiny. Next: add negation map, larger batch.