Elliptic Curve Elliptic Curve
ECEC 01

The curve bitcoin uses

Standfirst — one sentence stating the claim. To be written.

The curve

PROSE · SPEC §3.1 secp256k1: what it is, why bitcoin uses it, and what choosing it committed the protocol to. Source: —— · Dated: ————-——-—— · Review due: ————-——-——
EQUATION · component-specs §6 The curve equation, set as real text on a paper-2 strip, captioned EQ 1 · SECP256K1. Variables italic, operators and digits upright. Never an image.

ECDSA and Schnorr

PROSE · SPEC §3.1 What each signature scheme is, where each is used on-chain today, and what each reveals and when. The "when" is what the tracker measures. Source: —— · Dated: ————-——-—— · Review due: ————-——-——

The discrete logarithm problem

PROSE · SPEC §3.1 Why recovering a private key from a public key is hard classically, stated precisely enough that the quantum claim later is checkable rather than asserted. Source: —— · Dated: ————-——-—— · Review due: ————-——-——

What Shor's algorithm does

PROSE · SPEC §3.1 Precisely what Shor's does to the discrete log problem, and what it requires to do it. Resource estimates carry their source and their date; they move with each paper. Source: —— · Dated: ————-——-—— · Review due: ————-——-——
DIAGRAM · component-specs §6 FIG 1: key to signature to revealed public key to recovered private key. Boxes and arrows only. Terminal and exposed states take a claret border; everything else ink.

Grover's is the other half, and is routinely conflated

PROSE · SPEC §3.1 Grover's weakens SHA-256 quadratically. That is a mining and preimage question, not a key-theft question. Most coverage muddles the two, and separating them is a large part of what this page is for. Source: —— · Dated: ————-——-—— · Review due: ————-——-——