Today a crazy quantum story just got wilder.
On March 31, the Google Quantum AI team published a landmark result on Shor's algorithm for elliptic curve cryptography. Technically, the paper was a bombshell: a dramatic 10x improvement over the state-of-the-art. As a stunt and wakeup call to the blockchain space, those optimisations were illustrated on secp256k1, the elliptic curve underlying Bitcoin and Ethereum signatures.
But perhaps the most striking part of the paper was sociological, not technical. Instead of following standard academic process, the optimisations were kept secret, hidden behind a zero-knowledge (ZK) proof. Google's accompanying blog post mentions they "engaged with the U.S. government". The ZK proof demonstrates the existence of algorithmic improvements without leaking details. Academic censorship with ZK, a historic first!
As a co-author of the Google paper I witnessed some of the context surrounding this censorship. To be honest, multiple aspects of that context don't sit well with me. As much as I believe the general public ought to know more, I am limited in my ability to whistleblow. Though let me be clear about one thing: the Google team's professionalism has been absolutely exemplary, and they deserve nothing but praise.
Censorship has a way of backfiring. The Streisand effect, where an attempt to bury something only draws more attention to it, is exactly what's unfolding today. First, Google's key optimisation has been rediscovered by the French. And in a thrilling turn of events, a collaborative Shor-at-home challenge just launched. The initiative, available at ecdsa[.]fail, breached a new Shor world record in a matter of hours.
Let's start with the rediscovery. Just two months after Google's paper, French quantum expert André Schrottenloher cracks the main secret optimisation. His paper, titled "Optimized Point Addition Circuits for Elliptic Curve Discrete Logarithms", landed on the arXiv today. Big congrats to André, who beat several other nerdsnipped experts to it. In a blog post also published today, Craig Gidney, the world expert on Shor optimisations, revealed that he'd been sitting on this very optimisation for a whole year under censorship pressure.
Interestingly, André missed a handful of minor optimisations, both from Google's original publication and from improvements found since. It's plausible there's still plenty of juice left to squeeze out of Shor, and this is exactly what the ecdsa[.]fail challenge is about. The verifier program developed for the ZK proof does double duty, automatically filtering for valid submissions. Dozens of compounding small and micro improvements are rolling in. As of the time of writing there's an 8.4% improvement to Google's circuit, as measured by the product of logical qubit count and Toffoli gate count. Nice!
The nerdsnipping ran deeper than anyone expected. Over the last few weeks it became clear it extended well beyond André and other quantum experts. Behind the scenes, a small army of amateurs quietly got to work. Inspired by Karpathy-style autoresearch, they turned AI on Shor. Ironically, the verifier program for the ZK proof makes an ideal reward function for AIs. The barrier to entry for this modern style of research is refreshingly low, with several non-experts, even a teenager, finding nice optimisations. Get in touch if you'd like to join a Telegram group with fellow autoresearchers :)
Part 2: neutral atoms and qday
The story doesn't end with Google. On the same day Google went public, a stealthy startup called Oratomic published its own Shor paper in a coordinated release. It made a splash, ultimately becoming the most upvoted paper on scirate[.]com, a website ranking arXiv papers.
Oratomic's claim was wild. By building on Google's logical optimisations and applying custom physical optimisations for neutral atoms, they claimed just 10K physical qubits were sufficient to run Shor's algorithm on secp256k1. That number is mind-bogglingly low.
Knowing essentially nothing about neutral atoms when Oratomic's paper landed, I was intrigued and decided to learn more about the tech. I fell straight down the rabbit hole and spent a couple hundred hours on the topic. I got a little obsessed and watched every YouTube video I could find and spoke to a bunch of experts.
My conclusion? The tech is real, very real. Even Google recently decided to start a neutral atom lab, a notable pivot from their sole focus on superconducting qubits. If you care about qday, i.e. the day a quantum computer will break the first piece of cryptography in production, neutral atoms demand your attention. I shared some of my learnings on Shor and neutral atoms in a 30min talk at the ZKProof cryptography conference. You can find it on YouTube by searching "zkproof neutral atom".
Here's an interesting observation about this duo of breakthrough papers: neither Google nor Oratomic say a word about what their results mean for qday. No timelines. Zero. Nada. That is especially baffling given that the whole point of whitehat quantum cryptanalysis is to inform qday estimations and help the general public make good decisions.
So let me attempt to partially fill the silence, similarly to what Scott Aaronson did in his April 29 post. Given everything I know, including scary non-public information, I now put the odds of qday by 2032 at 50%. 10% by 2030.
Anecdotally, the US government has its own date: 2035. Originating at the NSA and later adopted by NIST, it's when branches of the US government will be disallowed from using quantum-vulnerable cryptography. In plain language: with hindsight, that date is a joke and should be discounted entirely. I don't see how NIST avoids being forced to pull it forward by years.
Part 3: post-quantum cryptography
There are good reasons to sound the alarm today, but please do not panic. Rushing carelessly towards immature post-quantum cryptography is a recipe for disaster. IMO a good target date for migration is 2029, roughly 3.5 years out. 2029 happens to be the date selected by Google, Cloudflare, and the Ethereum Foundation.
These days most of my time goes to safely migrating Ethereum towards post-quantum cryptography as part of the broader lean Ethereum effort. There's a lot to do. We need to rip out and replace BLS signatures at the consensus layer, KZG commitments at the data layer, and ECDSA signatures at the execution layer.
The plan to get there is compelling, and is based on hash-based cryptography. Within the Ethereum Foundation we've developed a Swiss army knife called leanVM (github[.]com/leanEthereum/leanVM) powered by the magic of hash-based SNARKs. Thanks to truly exceptional work by Emile, Thomas, and others, its performance is derisked. Regarding security, leanVM is a jewel, a minimal zkVM crafted for end-to-end formal verification and maximum security.
Want to help? There are two $1M initiatives. First, the Proximity Prize (proximityprize[.]org). Solve a long-standing mathematical conjecture in coding theory, improve hash-based SNARKs, and go home a millionaire. Second, the Poseidon Initiative (poseidon-initiative[.]info), offers $1M for breaking Poseidon, the SNARK-friendly hash function.
Show more
Wyoming hanged Tom Horn in 1903 on a machine specifically designed so that no human being would have to feel responsible for killing him.
Which, given what Tom Horn did for a living, is about as tidy as history ever gets.
He was born in Missouri in 1860 and left home at sixteen. He ended up in Arizona working for the Army as a packer, scout and interpreter under the chief of scouts Al Sieber during the Apache campaigns, and he was with the column that brought Geronimo in. He also won a steer roping championship out there. Years later he wrote an autobiography that inflated most of it considerably, which was standard for the genre.
In the early 1890s he worked for the Pinkerton agency out of Denver, running down train robbers. He was extremely good at the tracking part. He was reportedly much less interested in the part where you bring a man in alive.
Then he went north to Wyoming and hired on with the big cattle outfits as a stock detective.
The job title was a formality. What the cattlemen were paying for was for suspected rustlers to stop existing, and Horn delivered that with a rifle, at long range, frequently from a couple hundred yards, with nobody around to see it. Historians credit him with the 1900 killings of Matt Rash and Isom Dart in Brown's Park and suspect him in several others.
The line most often attributed to him is, "Killing men is my specialty. I look on it as a business proposition, and I think I have a corner on the market." Whether he actually said it is argued about. It was his reputation regardless, and he did nothing to discourage it.
Then on July 18, 1901, a 14 year old boy named Willie Nickell was shot dead by a gate at Iron Mountain.
Willie was big for his age, and he was wearing his father's coat and hat. His father, Kels Nickell, was running sheep in cattle country and was in a poisonous feud with his neighbors. Nearly everyone who has looked at it since has reached the same conclusion, which is that whoever fired thought he was shooting the father.
Six months later, a deputy US marshal named Joe LeFors got Horn into an office in Cheyenne to talk about a job in Montana. He got Horn drinking. He flattered him, and let him brag, and kept nudging.
Behind a door left open a crack in the next room sat a deputy and a court stenographer named Charles Ohnhaus, writing down every word.
Somewhere in that transcript is the sentence, "It was the best shot that I ever made and the dirtiest trick I ever done."
That was the case. Everything else the prosecution had was circumstantial. He was tried in an election year, in a state that had finally had enough of cattle barons buying outcomes, and the jury convicted him.
Here is the complicated part. Most historians who have gone back through the evidence now believe Tom Horn probably did not kill Willie Nickell. There were other suspects with better motive and better opportunity. The physical case was weak, and the confession was a drunk man performing for a lawman who was steering the conversation.
He had certainly killed people. He was very likely hanged for the wrong one.
He got out of the jail in August 1903 with a pistol taken off a guard, and then could not figure out how the pistol worked. A man on the street who happened to know that model took him back into custody.
So on November 20, 1903, one day short of his 43rd birthday, they walked him out to the gallows in Cheyenne.
That gallows had been built by a local architect named James Julian. Julian had come through the Civil War, and he had thought a long time about what it does to a man to be the one personally responsible for killing another. So he engineered the person out of it.
The condemned man stood on the trapdoor. His own weight tipped a lever that opened a valve on a water tank. The water ran out of the tank into a pan below, and as it drained the balance shifted, and when enough had run the mechanism pulled the bolt and the floor opened.
Nobody pulled a lever. Nobody gave a signal. The man walked onto the platform, started the clock with his own body, and then stood there listening to water run.
For Tom Horn it took about 35 seconds.
A newspaper of the day described the machine as a device that simply compelled the condemned to commit suicide.
Tom Horn had spent his career being the instrument that wealthy men used so that they would never have to be the ones who pulled the trigger.
Wyoming killed him with a machine built on exactly the same idea.
Show more
But according to the residents of Barcelona, tourists are the real problem! Meanwhile you’ve got a foreign army invading your city.
Who’s got the stronger fan army? 👀 Cast your vote for Bad Bunny fans or Stray Kids’ #
STAY# in Round 3 of #
BBFanArmy2026#.
Vote:
Bill Gurley
@bgurley: the Army Corps of Engineers built the levees that failed in Hurricane Katrina.
It paid an outside engineering society $1 million to help investigate itself.
At Jason Calacanis's
@Jason All-In Summit, Gurley walked through what happened next. The Corps paid the American Society of Civil Engineers $1 million to join its internal review, and the ASCE team got folded into the Corps' own process instead of staying separate from it. Engineering professor Raymond Seed later wrote a 42-page report to the ASCE cataloguing every place it had blocked the investigation.
Paying an independent reviewer does not make the review independent. The check only holds if the reviewer's paycheck comes from somewhere else.
Podcast Alpha's coverage of this talk maps the same failure across five separate catastrophes, plus where Gurley applies it to COVID.
Source: All-In Podcast -
Show more
Roberto Vannacci, the former Italian army general and full-time provocateur, turned up on the shores of Lake Como by himself with no aides or handlers, hoping for an audience. An audience he got.
Show more
TRUMP JUST SENT ANOTHER STATE'S ARMY INTO TWO STATES THAT NEVER ASKED FOR IT
Four hundred Texas National Guard troops. Ordered into Illinois and Oregon. Tonight. No phone call. No coordination. Governor Pritzker found out the same way you did
"No officials from the federal government called me directly to discuss or coordinate," Pritzker said. Then he said the quiet part: "We must now start calling this what it is: Trump's Invasion"
Texas Governor Abbott confirmed it independently because apparently that's how federalism works now under Donald Trump. Governors learning about their own states from press releases
Here's the part that should make you scream. The Supreme Court already told him no on this exact thing days ago. Left the block in place. Said the government "failed to identify a source of authority that would allow the military to execute the laws in Illinois"
Second loss at the Supreme Court in four days. Even a judge appointed by his own side wrote that the administration never even tried using regular forces first
Trump lost. So what does Trump do. He doesn't stop. He just picks a new city and sends the troops anyway
That is not law enforcement. That is a man testing how many times the courts will say no before nobody stops him
Four hundred and ninety six million dollars. That is the taxpayer bill so far for shipping soldiers into Los Angeles, DC, Memphis, Portland, Chicago, New Orleans, courts blocking half of it, and Trump billing you for the privilege of being told he broke the law
Two hundred more troops sitting on standby in Texas right now costing four million dollars a month to do absolutely nothing except exist as a threat
The lawsuit over Chicago got dismissed only because Trump's own orders became "no longer operational" — legal speak for he got caught and quietly backed off
Blue state governors get treated like occupied territory. Trump gets his "invasion" theater for the cameras. Taxpayers get the invoice
This isn't border security. This isn't crime response. This is Donald Trump deciding which American cities count as enemy soil
They lost in court and did it anyway
This is only the beginning
Show more
🇳🇵 2 men crawled out of a Nepal hydropower tunnel caked in mud after 2 days underground.
The army dropped onto Rasuwa, slithered through sludge that had sealed the exit, and got them to a helicopter.
Hundreds were already out of that project. Maybe 100 are still inside.
Wednesday’s flood was a glacier coming apart on the Tibet border, not a normal monsoon afternoon.
The tunnel is not done with them.
Writer: Lucas
Show more
Another Israeli soldier arrested for insider trading
This time it's an Air Force major that got caught betting on strikes on Yemen and Iran.
This has become a common occurrence in the Israeli army.
So much that another suspect arrested in May defended himself by saying :
"The entire Israel Air Force is involved in gambling."
I wouldn't be surprised if it's close to the truth.
3 out of the 4 insider war related insider trading scandals I heard off were centered on Israeli soliders (exception being the Maduro capture incident)
I love strike markets but I wouldn't recommend playing the Israel related ones.
You are almost certainly up against insiders
Show more
Breaking: President Trump told the United Nations the U.S has 18 new weapons factories under construction. Next year's proposed defense budget jumps 42% to $1.5T
4 stocks worth watching:
Olin Corporation $OLN
*Just got a $788,361,894 contract to keep supplying the Army's bullets through 2031
L3Harris $LHX
*Building 60 new missile parts factories across Arkansas, Alabama, and Virginia to keep up with government demand
Lockheed Martin $LMT
*Got a $35,000,000,000 contract to quadruple THAAD missile production, going from 96 a year to 400
RTX $RTX
*Got a $22,900,000,000 contract to build Tomahawk missiles, going from 60 a year to over 1,000
Show more