{
  "wallet": "5YX43snuyChA6LSCKT6z15YdSbSNXzA3shxntjLtKg5",
  "name": "bqp",
  "name_meaning": "bounded error quantum polynomial time, the class of problems a quantum computer can solve efficiently. breaking an elliptic curve key is in it. that is the whole threat in three letters.",
  "chain": "solana",
  "launch_venue": "pump.fun",
  "spec_version": 1,
  "status": {
    "genesis_job": null,
    "mint": null,
    "program_id": null,
    "signer_root": null,
    "current_rung": null,
    "note": "every null in this file is a value that only exists after a real run or a real transaction. nothing is filled in ahead of time."
  },
  "thesis": [
    "every solana address is an ed25519 public key shown in the open. the day a machine can run shor's algorithm at that size, every one of them is a published secret.",
    "the argument about when that day comes is all estimates. bqp replaces the estimate with a measurement: creator fees buy time on real quantum hardware and the coin attacks a real elliptic curve key, one bit larger at every rung.",
    "the coin itself is born from a quantum measurement. no person picks a single parameter. an ai agent writes the circuit, submits the job, reads the counts and deploys.",
    "the agent that operates it has no reusable key. it signs with hash based one time signatures, 1024 of them, and each one is gone after use."
  ],
  "roles": {
    "wallet": {
      "address": "5YX43snuyChA6LSCKT6z15YdSbSNXzA3shxntjLtKg5",
      "does": "receives pump.fun creator fees. every crank sweeps its balance above rent into the program vault. it holds nothing between cranks."
    },
    "agent": {
      "does": "writes circuits, submits jobs, posts job commitments and settlements. authority is the one time signer tree only, never an ed25519 key."
    },
    "program": {
      "does": "holds the vault, derives targets, verifies one time signatures, checks recovered scalars with its own curve arithmetic, burns or opens claims."
    },
    "crank": {
      "does": "permissionless. any account may call sweep and cross_rung. it is paid nothing and decides nothing."
    }
  },
  "quantum_genesis": {
    "summary": "one job on real hardware. 64 measured bits per shot, 4096 shots. the full histogram, not a single shot, is hashed into the seed.",
    "provider_requirements": [
      "public job id that the provider will resolve for anyone with an account",
      "raw per shot counts downloadable",
      "backend name and calibration snapshot attached to the job"
    ],
    "circuit_reference_python": [
      "from qiskit import QuantumCircuit, transpile",
      "from qiskit_ibm_runtime import QiskitRuntimeService, SamplerV2",
      "",
      "WIDTH = 64   # measured bits per shot",
      "LAYERS = 3   # entangling layers so the output is not a product state",
      "",
      "def genesis_circuit() -> QuantumCircuit:",
      "    qc = QuantumCircuit(WIDTH, WIDTH)",
      "    for layer in range(LAYERS):",
      "        for q in range(WIDTH):",
      "            qc.h(q)",
      "        start = layer % 2",
      "        for q in range(start, WIDTH - 1, 2):",
      "            qc.cz(q, q + 1)",
      "        for q in range(WIDTH):",
      "            qc.t(q)",
      "    for q in range(WIDTH):",
      "        qc.h(q)",
      "    qc.measure(range(WIDTH), range(WIDTH))",
      "    return qc",
      "",
      "def run_genesis(backend_name: str, shots: int = 4096):",
      "    service = QiskitRuntimeService()",
      "    backend = service.backend(backend_name)",
      "    isa = transpile(genesis_circuit(), backend=backend, optimization_level=1)",
      "    job = SamplerV2(mode=backend).run([isa], shots=shots)",
      "    result = job.result()",
      "    counts = result[0].data.c.get_counts()",
      "    return job.job_id(), backend_name, shots, counts"
    ],
    "seed_rule": "seed = sha256(domain | [job_id, backend, shots] | canonical_counts)",
    "what_goes_on_chain_in_the_deploy_transaction": [
      "sha256 of the job id string",
      "sha256 of the canonical counts",
      "the seed",
      "every genome field",
      "the signer root"
    ],
    "what_is_published_next_to_it": [
      "the job id in clear",
      "the raw counts file",
      "the transpiled circuit as qasm3",
      "the backend calibration snapshot"
    ],
    "check_anyone_can_run": [
      "download the counts for the job id from the provider",
      "run canonical_counts and genesis_seed",
      "compare with the seed stored in the genesis account",
      "run genome(seed) and compare every field with the genesis account"
    ],
    "result": {
      "job_id": null,
      "backend": null,
      "shots": null,
      "counts_sha256": null,
      "seed": null
    }
  },
  "genome": {
    "summary": "every tunable number in the system is read out of the genesis seed with shake256 and rejection sampling. the bounds below are the only human choices and they are fixed in this file before the job runs.",
    "bounds": {
      "compute_bps": {
        "min": 1500,
        "max": 3500,
        "meaning": "share of each rung tranche that pays for the quantum job"
      },
      "settle_bps": {
        "rule": "10000 minus compute_bps",
        "meaning": "share that is burned on a break or paid to holders on a hold"
      },
      "base_cap_lamports": {
        "min": 150000000000,
        "max": 450000000000,
        "meaning": "implied cap in lamports that trips rung 0"
      },
      "ratio_q16": {
        "min": 98304,
        "max": 163840,
        "meaning": "threshold growth per rung in Q16 fixed point, 1.5x to 2.5x"
      },
      "shots_per_job": {
        "choices": [
          4096,
          8192,
          16384
        ]
      },
      "peak_margin_q16": {
        "min": 131072,
        "max": 262144,
        "meaning": "how far above the uniform baseline the winning scalar must stand, 2x to 4x"
      },
      "signer_tree_height": {
        "fixed": 10,
        "meaning": "1024 one time leaves"
      }
    },
    "derivation_reference_python": [
      "import hashlib, json",
      "",
      "DOMAIN = b\"bqp/genome/v1\"",
      "",
      "def canonical_counts(counts: dict) -> bytes:",
      "    # counts maps measured bitstring -> number of shots, exactly as the backend returned it",
      "    items = sorted((k, int(v)) for k, v in counts.items())",
      "    return json.dumps(items, separators=(\",\", \":\")).encode()",
      "",
      "def genesis_seed(job_id: str, backend: str, shots: int, counts: dict) -> bytes:",
      "    body = canonical_counts(counts)",
      "    head = json.dumps([job_id, backend, shots], separators=(\",\", \":\")).encode()",
      "    return hashlib.sha256(DOMAIN + b\"|\" + head + b\"|\" + body).digest()",
      "",
      "def expand(seed: bytes, label: bytes, n: int) -> bytes:",
      "    return hashlib.shake_256(DOMAIN + b\"|\" + label + b\"|\" + seed).digest(n)",
      "",
      "def u64(seed: bytes, label: bytes) -> int:",
      "    return int.from_bytes(expand(seed, label, 8), \"little\")",
      "",
      "def bounded(seed: bytes, label: bytes, lo: int, hi: int) -> int:",
      "    # rejection sampling, no modulo bias",
      "    span = hi - lo + 1",
      "    limit = (1 << 64) - ((1 << 64) % span)",
      "    ctr = 0",
      "    while True:",
      "        v = u64(seed, label + b\"/\" + str(ctr).encode())",
      "        if v < limit:",
      "            return lo + (v % span)",
      "        ctr += 1",
      "",
      "def genome(seed: bytes) -> dict:",
      "    g = {}",
      "    g[\"compute_bps\"]       = bounded(seed, b\"compute_bps\", 1500, 3500)",
      "    g[\"settle_bps\"]        = 10000 - g[\"compute_bps\"]",
      "    g[\"base_cap_lamports\"] = bounded(seed, b\"base_cap\", 150, 450) * 1_000_000_000",
      "    g[\"ratio_q16\"]         = bounded(seed, b\"ratio\", 98304, 163840)   # 1.5x to 2.5x in Q16",
      "    g[\"shots_per_job\"]     = 1 << bounded(seed, b\"shots\", 12, 14)     # 4096, 8192 or 16384",
      "    g[\"peak_margin_q16\"]   = bounded(seed, b\"margin\", 131072, 262144) # 2x to 4x over uniform",
      "    g[\"signer_tree_height\"]= 10                                       # 1024 one time leaves",
      "    g[\"signer_root_salt\"]  = expand(seed, b\"signer_salt\", 32).hex()",
      "    g[\"mint_grind_seed\"]   = expand(seed, b\"mint_grind\", 32).hex()",
      "    return g",
      "",
      "def rung_threshold(g: dict, rung: int) -> int:",
      "    cap = g[\"base_cap_lamports\"]",
      "    for _ in range(rung):",
      "        cap = (cap * g[\"ratio_q16\"]) >> 16",
      "    return cap"
    ],
    "values": {
      "compute_bps": null,
      "settle_bps": null,
      "base_cap_lamports": null,
      "ratio_q16": null,
      "shots_per_job": null,
      "peak_margin_q16": null,
      "signer_root_salt": null,
      "mint_grind_seed": null
    },
    "mint_grind": {
      "rule": "candidate keypair i = ed25519 keypair from seed32 = shake256(domain | mint_grind | seed | u64le(i)). take the first i whose base58 address ends in pump.",
      "why": "the mint address is a function of the measurement. the counter i is published so the search is reproducible.",
      "counter": null
    }
  },
  "fee_flow": {
    "trigger": "trades. there is no schedule anywhere in the system.",
    "steps": [
      "a trade on the coin accrues creator fees to the wallet",
      "any crank call sweeps the wallet balance above rent into the vault",
      "the vault accumulates until a trade leaves the implied cap at or above the next threshold",
      "cross_rung freezes the vault balance as that rung's tranche and derives the target key",
      "compute_bps of the tranche pays for the job, settle_bps waits for the result",
      "key broken: settle share buys the coin from the pool and burns it in the same instruction",
      "key held: settle share becomes claimable pro rata by whoever held at the crossing slot"
    ],
    "implied_cap": "pool quote reserve in lamports times total supply divided by pool base reserve, read from the pool accounts inside cross_rung",
    "invariants": [
      "tranche = compute_paid + burned_value, or tranche = compute_paid + claimable",
      "sum of claims on a held rung never exceeds tranche minus compute_paid",
      "a rung account is written by cross_rung once, post_job once, settle once",
      "current_rung only increases, by exactly one, inside settle"
    ]
  },
  "break_ladder": {
    "summary": "rung k attacks an elliptic curve key of k + 4 bits with shor's algorithm for discrete logs on real hardware. the published table covers 4 through 16 bits. past that the same deterministic search extends it.",
    "curve_search_rule": [
      "p = largest prime with exactly n bits and p mod 4 = 3",
      "a = p minus 3",
      "b = smallest integer from 1 up for which the curve is non singular and its point count is a prime different from p",
      "generator = the point with the smallest x on the curve, taking the smaller of its two y values"
    ],
    "target_key_derivation": {
      "rule": "h = sha256('bqp/target/v1' | seed | rung | sha256(crossing transaction signature)); d = 1 + (u64le(h[0..8]) mod (q minus 1)); target = d * generator",
      "why": "the secret scalar depends on the transaction that crossed the rung, so it cannot be known before that trade lands",
      "honest_note": "the program computes d itself to build the target, so d is not secret from a classical computer. nothing on this ladder is. the point is whether the quantum hardware returns it from the circuit, which is judged by the published histogram and the peak margin."
    },
    "circuit": {
      "layout": "two exponent registers a and b in uniform superposition, one point register holding the index of a*G + b*Q, inverse quantum fourier transform on a and b, measure both",
      "oracle": "2t controlled additions of classical constant points (G, 2G, 4G, ... and Q, 2Q, 4Q, ...), each synthesised as a permutation of the enumerated curve points. the enumeration is sorted by coordinates and carries no discrete log information.",
      "math": "measured pair (j, k) concentrates on k = d * j mod q, so each usable shot votes for d = k * j^-1 mod q",
      "reference_python": [
        "import numpy as np",
        "from math import ceil, log2",
        "from collections import Counter",
        "from qiskit import QuantumCircuit, QuantumRegister, ClassicalRegister",
        "from qiskit.circuit.library import QFT, UnitaryGate",
        "",
        "# small field elliptic curve arithmetic",
        "INF = None",
        "",
        "def ec_add(P, Q, a, p):",
        "    if P is INF: return Q",
        "    if Q is INF: return P",
        "    x1, y1 = P; x2, y2 = Q",
        "    if x1 == x2 and (y1 + y2) % p == 0:",
        "        return INF",
        "    if P == Q:",
        "        lam = (3 * x1 * x1 + a) * pow(2 * y1, -1, p) % p",
        "    else:",
        "        lam = (y2 - y1) * pow(x2 - x1, -1, p) % p",
        "    x3 = (lam * lam - x1 - x2) % p",
        "    return (x3, (lam * (x1 - x3) - y1) % p)",
        "",
        "def ec_mul(k, P, a, p):",
        "    R = INF",
        "    while k:",
        "        if k & 1: R = ec_add(R, P, a, p)",
        "        P = ec_add(P, P, a, p)",
        "        k >>= 1",
        "    return R",
        "",
        "def enumerate_points(a, b, p):",
        "    # identity first, then affine points sorted by (x, y). this order does not depend on any discrete log.",
        "    pts = [INF]",
        "    for x in range(p):",
        "        rhs = (x * x * x + a * x + b) % p",
        "        for y in range(p):",
        "            if (y * y) % p == rhs:",
        "                pts.append((x, y))",
        "    return pts",
        "",
        "# the oracle: |k>|R> -> |k>|R + k*P> built from controlled constant additions",
        "def add_constant_gate(P, pts, index, a, p, width):",
        "    dim = 1 << width",
        "    U = np.zeros((dim, dim))",
        "    for i in range(dim):",
        "        if i < len(pts):",
        "            j = index[ec_add(pts[i], P, a, p)]",
        "        else:",
        "            j = i                      # padding states map to themselves",
        "        U[j, i] = 1.0",
        "    return UnitaryGate(U, label=\"add\")",
        "",
        "def build_circuit(curve, Q):",
        "    p, a, b, q = curve[\"p\"], curve[\"a\"], curve[\"b\"], curve[\"q\"]",
        "    G = (curve[\"gx\"], curve[\"gy\"])",
        "    pts = enumerate_points(a, b, p)",
        "    assert len(pts) == q",
        "    index = {P: i for i, P in enumerate(pts)}",
        "    t = ceil(log2(q)) + 1",
        "    w = ceil(log2(len(pts)))",
        "    ra = QuantumRegister(t, \"a\"); rb = QuantumRegister(t, \"b\"); rp = QuantumRegister(w, \"pt\")",
        "    ca = ClassicalRegister(t, \"ma\"); cb = ClassicalRegister(t, \"mb\")",
        "    qc = QuantumCircuit(ra, rb, rp, ca, cb)",
        "    qc.h(ra); qc.h(rb)                 # point register starts at index 0, the identity",
        "    Pg, Pq = G, Q",
        "    for i in range(t):",
        "        qc.append(add_constant_gate(Pg, pts, index, a, p, w).control(1), [ra[i], *rp])",
        "        qc.append(add_constant_gate(Pq, pts, index, a, p, w).control(1), [rb[i], *rp])",
        "        Pg = ec_add(Pg, Pg, a, p); Pq = ec_add(Pq, Pq, a, p)",
        "    qc.append(QFT(t, inverse=True, do_swaps=True), ra)",
        "    qc.append(QFT(t, inverse=True, do_swaps=True), rb)",
        "    qc.measure(ra, ca); qc.measure(rb, cb)",
        "    return qc, t",
        "",
        "# deterministic post processing, anyone can rerun it on the published counts",
        "def recover(counts, curve, Q, t, peak_margin_q16):",
        "    p, a, q = curve[\"p\"], curve[\"a\"], curve[\"q\"]",
        "    G = (curve[\"gx\"], curve[\"gy\"])",
        "    votes = Counter(); usable = 0",
        "    for bits, n in counts.items():",
        "        mb_s, ma_s = bits.split()      # qiskit prints the last classical register first",
        "        u, v = int(ma_s, 2), int(mb_s, 2)",
        "        j = round(u * q / (1 << t)) % q",
        "        k = round(v * q / (1 << t)) % q",
        "        if j == 0:",
        "            continue",
        "        d = (k * pow(j, -1, q)) % q    # state is sum |a>|b>|(a + d*b)G>, so k = d*j mod q",
        "        votes[d] += n; usable += n",
        "    if not votes:",
        "        return None, False",
        "    ranked = sorted(votes.items(), key=lambda kv: (-kv[1], kv[0]))",
        "    best, weight = ranked[0]",
        "    uniform = usable / (q - 1)",
        "    signal = (weight << 16) >= int(peak_margin_q16 * uniform)",
        "    correct = ec_mul(best, G, a, p) == Q",
        "    return best, (signal and correct)"
      ]
    },
    "success_rule": [
      "run exactly shots_per_job shots, one job, no retries on the same target",
      "post sha256 of the job id on chain before results are fetched (post_job)",
      "run recover() on the raw counts",
      "broken only if the top voted scalar opens the target on chain and its vote weight is at least peak_margin times the uniform baseline",
      "anything else is held"
    ],
    "rungs": [
      {
        "rung": 0,
        "key_bits": 4,
        "curve": {
          "form": "y^2 = x^3 + a*x + b over F_p",
          "p": 11,
          "a": 8,
          "b": 1,
          "group_order_q": 17,
          "cofactor": 1,
          "generator": {
            "x": 0,
            "y": 1
          }
        },
        "target_public_key": null,
        "target_derivation": "see break_ladder.target_key_derivation",
        "toy_circuit_registers": {
          "exponent_register_a_qubits": 6,
          "exponent_register_b_qubits": 6,
          "point_register_qubits": 5,
          "total_qubits": 17,
          "controlled_point_additions": 12
        },
        "fault_tolerant_estimate_same_bits": {
          "logical_qubits": 50,
          "toffoli_gates": 319104,
          "formula": "see references.resource_formula"
        },
        "cap_threshold_lamports": null,
        "threshold_derivation": "base_cap_lamports * ratio_q16^rung / 65536^rung, both from genome",
        "state": "unreached",
        "job_id": null,
        "counts_sha256": null,
        "recovered_scalar": null,
        "outcome": null
      },
      {
        "rung": 1,
        "key_bits": 5,
        "curve": {
          "form": "y^2 = x^3 + a*x + b over F_p",
          "p": 31,
          "a": 28,
          "b": 6,
          "group_order_q": 41,
          "cofactor": 1,
          "generator": {
            "x": 1,
            "y": 2
          }
        },
        "target_public_key": null,
        "target_derivation": "see break_ladder.target_key_derivation",
        "toy_circuit_registers": {
          "exponent_register_a_qubits": 7,
          "exponent_register_b_qubits": 7,
          "point_register_qubits": 6,
          "total_qubits": 20,
          "controlled_point_additions": 14
        },
        "fault_tolerant_estimate_same_bits": {
          "logical_qubits": 61,
          "toffoli_gates": 641278,
          "formula": "see references.resource_formula"
        },
        "cap_threshold_lamports": null,
        "threshold_derivation": "base_cap_lamports * ratio_q16^rung / 65536^rung, both from genome",
        "state": "unreached",
        "job_id": null,
        "counts_sha256": null,
        "recovered_scalar": null,
        "outcome": null
      },
      {
        "rung": 2,
        "key_bits": 6,
        "curve": {
          "form": "y^2 = x^3 + a*x + b over F_p",
          "p": 59,
          "a": 56,
          "b": 1,
          "group_order_q": 71,
          "cofactor": 1,
          "generator": {
            "x": 0,
            "y": 1
          }
        },
        "target_public_key": null,
        "target_derivation": "see break_ladder.target_key_derivation",
        "toy_circuit_registers": {
          "exponent_register_a_qubits": 8,
          "exponent_register_b_qubits": 8,
          "point_register_qubits": 7,
          "total_qubits": 23,
          "controlled_point_additions": 16
        },
        "fault_tolerant_estimate_same_bits": {
          "logical_qubits": 70,
          "toffoli_gates": 1133582,
          "formula": "see references.resource_formula"
        },
        "cap_threshold_lamports": null,
        "threshold_derivation": "base_cap_lamports * ratio_q16^rung / 65536^rung, both from genome",
        "state": "unreached",
        "job_id": null,
        "counts_sha256": null,
        "recovered_scalar": null,
        "outcome": null
      },
      {
        "rung": 3,
        "key_bits": 7,
        "curve": {
          "form": "y^2 = x^3 + a*x + b over F_p",
          "p": 127,
          "a": 124,
          "b": 57,
          "group_order_q": 109,
          "cofactor": 1,
          "generator": {
            "x": 6,
            "y": 1
          }
        },
        "target_public_key": null,
        "target_derivation": "see break_ladder.target_key_derivation",
        "toy_circuit_registers": {
          "exponent_register_a_qubits": 8,
          "exponent_register_b_qubits": 8,
          "point_register_qubits": 7,
          "total_qubits": 23,
          "controlled_point_additions": 16
        },
        "fault_tolerant_estimate_same_bits": {
          "logical_qubits": 79,
          "toffoli_gates": 1834259,
          "formula": "see references.resource_formula"
        },
        "cap_threshold_lamports": null,
        "threshold_derivation": "base_cap_lamports * ratio_q16^rung / 65536^rung, both from genome",
        "state": "unreached",
        "job_id": null,
        "counts_sha256": null,
        "recovered_scalar": null,
        "outcome": null
      },
      {
        "rung": 4,
        "key_bits": 8,
        "curve": {
          "form": "y^2 = x^3 + a*x + b over F_p",
          "p": 251,
          "a": 248,
          "b": 26,
          "group_order_q": 223,
          "cofactor": 1,
          "generator": {
            "x": 2,
            "y": 84
          }
        },
        "target_public_key": null,
        "target_derivation": "see break_ladder.target_key_derivation",
        "toy_circuit_registers": {
          "exponent_register_a_qubits": 9,
          "exponent_register_b_qubits": 9,
          "point_register_qubits": 8,
          "total_qubits": 26,
          "controlled_point_additions": 18
        },
        "fault_tolerant_estimate_same_bits": {
          "logical_qubits": 88,
          "toffoli_gates": 2782208,
          "formula": "see references.resource_formula"
        },
        "cap_threshold_lamports": null,
        "threshold_derivation": "base_cap_lamports * ratio_q16^rung / 65536^rung, both from genome",
        "state": "unreached",
        "job_id": null,
        "counts_sha256": null,
        "recovered_scalar": null,
        "outcome": null
      },
      {
        "rung": 5,
        "key_bits": 9,
        "curve": {
          "form": "y^2 = x^3 + a*x + b over F_p",
          "p": 503,
          "a": 500,
          "b": 51,
          "group_order_q": 523,
          "cofactor": 1,
          "generator": {
            "x": 1,
            "y": 7
          }
        },
        "target_public_key": null,
        "target_derivation": "see break_ladder.target_key_derivation",
        "toy_circuit_registers": {
          "exponent_register_a_qubits": 11,
          "exponent_register_b_qubits": 11,
          "point_register_qubits": 10,
          "total_qubits": 32,
          "controlled_point_additions": 22
        },
        "fault_tolerant_estimate_same_bits": {
          "logical_qubits": 99,
          "toffoli_gates": 4016882,
          "formula": "see references.resource_formula"
        },
        "cap_threshold_lamports": null,
        "threshold_derivation": "base_cap_lamports * ratio_q16^rung / 65536^rung, both from genome",
        "state": "unreached",
        "job_id": null,
        "counts_sha256": null,
        "recovered_scalar": null,
        "outcome": null
      },
      {
        "rung": 6,
        "key_bits": 10,
        "curve": {
          "form": "y^2 = x^3 + a*x + b over F_p",
          "p": 1019,
          "a": 1016,
          "b": 15,
          "group_order_q": 977,
          "cofactor": 1,
          "generator": {
            "x": 0,
            "y": 228
          }
        },
        "target_public_key": null,
        "target_derivation": "see break_ladder.target_key_derivation",
        "toy_circuit_registers": {
          "exponent_register_a_qubits": 11,
          "exponent_register_b_qubits": 11,
          "point_register_qubits": 10,
          "total_qubits": 32,
          "controlled_point_additions": 22
        },
        "fault_tolerant_estimate_same_bits": {
          "logical_qubits": 108,
          "toffoli_gates": 5578224,
          "formula": "see references.resource_formula"
        },
        "cap_threshold_lamports": null,
        "threshold_derivation": "base_cap_lamports * ratio_q16^rung / 65536^rung, both from genome",
        "state": "unreached",
        "job_id": null,
        "counts_sha256": null,
        "recovered_scalar": null,
        "outcome": null
      },
      {
        "rung": 7,
        "key_bits": 11,
        "curve": {
          "form": "y^2 = x^3 + a*x + b over F_p",
          "p": 2039,
          "a": 2036,
          "b": 1,
          "group_order_q": 2083,
          "cofactor": 1,
          "generator": {
            "x": 0,
            "y": 1
          }
        },
        "target_public_key": null,
        "target_derivation": "see break_ladder.target_key_derivation",
        "toy_circuit_registers": {
          "exponent_register_a_qubits": 13,
          "exponent_register_b_qubits": 13,
          "point_register_qubits": 12,
          "total_qubits": 38,
          "controlled_point_additions": 26
        },
        "fault_tolerant_estimate_same_bits": {
          "logical_qubits": 117,
          "toffoli_gates": 7506608,
          "formula": "see references.resource_formula"
        },
        "cap_threshold_lamports": null,
        "threshold_derivation": "base_cap_lamports * ratio_q16^rung / 65536^rung, both from genome",
        "state": "unreached",
        "job_id": null,
        "counts_sha256": null,
        "recovered_scalar": null,
        "outcome": null
      },
      {
        "rung": 8,
        "key_bits": 12,
        "curve": {
          "form": "y^2 = x^3 + a*x + b over F_p",
          "p": 4091,
          "a": 4088,
          "b": 40,
          "group_order_q": 4027,
          "cofactor": 1,
          "generator": {
            "x": 1,
            "y": 804
          }
        },
        "target_public_key": null,
        "target_derivation": "see break_ladder.target_key_derivation",
        "toy_circuit_registers": {
          "exponent_register_a_qubits": 13,
          "exponent_register_b_qubits": 13,
          "point_register_qubits": 12,
          "total_qubits": 38,
          "controlled_point_additions": 26
        },
        "fault_tolerant_estimate_same_bits": {
          "logical_qubits": 126,
          "toffoli_gates": 9842797,
          "formula": "see references.resource_formula"
        },
        "cap_threshold_lamports": null,
        "threshold_derivation": "base_cap_lamports * ratio_q16^rung / 65536^rung, both from genome",
        "state": "unreached",
        "job_id": null,
        "counts_sha256": null,
        "recovered_scalar": null,
        "outcome": null
      },
      {
        "rung": 9,
        "key_bits": 13,
        "curve": {
          "form": "y^2 = x^3 + a*x + b over F_p",
          "p": 8191,
          "a": 8188,
          "b": 3,
          "group_order_q": 8221,
          "cofactor": 1,
          "generator": {
            "x": 1,
            "y": 1
          }
        },
        "target_public_key": null,
        "target_derivation": "see break_ladder.target_key_derivation",
        "toy_circuit_registers": {
          "exponent_register_a_qubits": 15,
          "exponent_register_b_qubits": 15,
          "point_register_qubits": 14,
          "total_qubits": 44,
          "controlled_point_additions": 30
        },
        "fault_tolerant_estimate_same_bits": {
          "logical_qubits": 135,
          "toffoli_gates": 12627910,
          "formula": "see references.resource_formula"
        },
        "cap_threshold_lamports": null,
        "threshold_derivation": "base_cap_lamports * ratio_q16^rung / 65536^rung, both from genome",
        "state": "unreached",
        "job_id": null,
        "counts_sha256": null,
        "recovered_scalar": null,
        "outcome": null
      },
      {
        "rung": 10,
        "key_bits": 14,
        "curve": {
          "form": "y^2 = x^3 + a*x + b over F_p",
          "p": 16363,
          "a": 16360,
          "b": 23,
          "group_order_q": 16319,
          "cofactor": 1,
          "generator": {
            "x": 0,
            "y": 7613
          }
        },
        "target_public_key": null,
        "target_derivation": "see break_ladder.target_key_derivation",
        "toy_circuit_registers": {
          "exponent_register_a_qubits": 15,
          "exponent_register_b_qubits": 15,
          "point_register_qubits": 14,
          "total_qubits": 44,
          "controlled_point_additions": 30
        },
        "fault_tolerant_estimate_same_bits": {
          "logical_qubits": 144,
          "toffoli_gates": 15903387,
          "formula": "see references.resource_formula"
        },
        "cap_threshold_lamports": null,
        "threshold_derivation": "base_cap_lamports * ratio_q16^rung / 65536^rung, both from genome",
        "state": "unreached",
        "job_id": null,
        "counts_sha256": null,
        "recovered_scalar": null,
        "outcome": null
      },
      {
        "rung": 11,
        "key_bits": 15,
        "curve": {
          "form": "y^2 = x^3 + a*x + b over F_p",
          "p": 32719,
          "a": 32716,
          "b": 35,
          "group_order_q": 32621,
          "cofactor": 1,
          "generator": {
            "x": 1,
            "y": 5700
          }
        },
        "target_public_key": null,
        "target_derivation": "see break_ladder.target_key_derivation",
        "toy_circuit_registers": {
          "exponent_register_a_qubits": 16,
          "exponent_register_b_qubits": 16,
          "point_register_qubits": 15,
          "total_qubits": 47,
          "controlled_point_additions": 32
        },
        "fault_tolerant_estimate_same_bits": {
          "logical_qubits": 153,
          "toffoli_gates": 19710969,
          "formula": "see references.resource_formula"
        },
        "cap_threshold_lamports": null,
        "threshold_derivation": "base_cap_lamports * ratio_q16^rung / 65536^rung, both from genome",
        "state": "unreached",
        "job_id": null,
        "counts_sha256": null,
        "recovered_scalar": null,
        "outcome": null
      },
      {
        "rung": 12,
        "key_bits": 16,
        "curve": {
          "form": "y^2 = x^3 + a*x + b over F_p",
          "p": 65519,
          "a": 65516,
          "b": 76,
          "group_order_q": 65447,
          "cofactor": 1,
          "generator": {
            "x": 2,
            "y": 25056
          }
        },
        "target_public_key": null,
        "target_derivation": "see break_ladder.target_key_derivation",
        "toy_circuit_registers": {
          "exponent_register_a_qubits": 17,
          "exponent_register_b_qubits": 17,
          "point_register_qubits": 16,
          "total_qubits": 50,
          "controlled_point_additions": 34
        },
        "fault_tolerant_estimate_same_bits": {
          "logical_qubits": 162,
          "toffoli_gates": 24092672,
          "formula": "see references.resource_formula"
        },
        "cap_threshold_lamports": null,
        "threshold_derivation": "base_cap_lamports * ratio_q16^rung / 65536^rung, both from genome",
        "state": "unreached",
        "job_id": null,
        "counts_sha256": null,
        "recovered_scalar": null,
        "outcome": null
      }
    ]
  },
  "one_time_signer": {
    "summary": "the agent's only authority. winternitz one time signatures with w = 16 over sha256, 1024 leaves under one merkle root. two leaves per rung (post_job, settle), so the tree covers 512 rungs. when the last leaf is spent the signer seals and the vault can only be drained by holder claims.",
    "parameters": {
      "hash": "sha256",
      "n_bytes": 32,
      "w": 16,
      "len1": 64,
      "len2": 3,
      "len": 67,
      "tree_height": 10,
      "leaves": 1024,
      "signature_bytes": 2144,
      "auth_path_bytes": 320
    },
    "master_secret": "shake256(domain | signer_salt | seed | agent entropy). the agent entropy never leaves the agent. the salt binds the tree to this genesis.",
    "reference_python": [
      "import hashlib",
      "",
      "N = 32          # hash output bytes",
      "W = 16          # Winternitz parameter",
      "LEN1 = 64       # message digits, 256 bits in base 16",
      "LEN2 = 3        # checksum digits",
      "LEN = LEN1 + LEN2",
      "",
      "def H(*parts: bytes) -> bytes:",
      "    return hashlib.sha256(b\"bqp/wots/v1|\" + b\"|\".join(parts)).digest()",
      "",
      "def chain(x: bytes, start: int, steps: int, leaf: int, pos: int) -> bytes:",
      "    for i in range(start, start + steps):",
      "        x = H(leaf.to_bytes(4, \"little\"), pos.to_bytes(2, \"little\"), i.to_bytes(1, \"little\"), x)",
      "    return x",
      "",
      "def digits(msg32: bytes):",
      "    d = []",
      "    for byte in msg32:",
      "        d.append(byte >> 4); d.append(byte & 15)",
      "    csum = sum(W - 1 - x for x in d)",
      "    for shift in (8, 4, 0):",
      "        d.append((csum >> shift) & 15)",
      "    return d",
      "",
      "def leaf_secret(master: bytes, leaf: int, pos: int) -> bytes:",
      "    return H(b\"sk\", master, leaf.to_bytes(4, \"little\"), pos.to_bytes(2, \"little\"))",
      "",
      "def leaf_public(master: bytes, leaf: int) -> bytes:",
      "    tops = [chain(leaf_secret(master, leaf, i), 0, W - 1, leaf, i) for i in range(LEN)]",
      "    return H(b\"pk\", *tops)",
      "",
      "def sign(master: bytes, leaf: int, msg32: bytes):",
      "    return [chain(leaf_secret(master, leaf, i), 0, d, leaf, i) for i, d in enumerate(digits(msg32))]",
      "",
      "def public_from_signature(sig, leaf: int, msg32: bytes) -> bytes:",
      "    tops = [chain(s, d, W - 1 - d, leaf, i) for i, (s, d) in enumerate(zip(sig, digits(msg32)))]",
      "    return H(b\"pk\", *tops)",
      "",
      "def merkle_root(leaves):",
      "    level = [H(b\"leaf\", x) for x in leaves]",
      "    while len(level) > 1:",
      "        level = [H(b\"node\", level[i], level[i + 1]) for i in range(0, len(level), 2)]",
      "    return level[0]",
      "",
      "def merkle_path(leaves, idx):",
      "    level = [H(b\"leaf\", x) for x in leaves]; path = []",
      "    while len(level) > 1:",
      "        path.append(level[idx ^ 1])",
      "        level = [H(b\"node\", level[i], level[i + 1]) for i in range(0, len(level), 2)]",
      "        idx >>= 1",
      "    return path"
    ],
    "leaf_map": {
      "spent": null,
      "remaining": null,
      "bitmap_account_offset_bytes": null
    }
  },
  "program": {
    "framework": "anchor",
    "accounts": {
      "genesis": {
        "seeds": [
          "genesis"
        ],
        "one_per": "deployment"
      },
      "rung": {
        "seeds": [
          "rung",
          "u8 index"
        ],
        "one_per": "rung"
      },
      "vault": {
        "seeds": [
          "vault"
        ],
        "holds": "lamports only"
      },
      "claim_receipt": {
        "seeds": [
          "claim",
          "u8 rung",
          "owner pubkey"
        ],
        "one_per": "holder per held rung"
      }
    },
    "instructions": [
      "init_genesis",
      "sweep",
      "cross_rung",
      "post_job",
      "settle",
      "claim"
    ],
    "events": [
      "GenesisSet",
      "Swept",
      "RungCrossed",
      "JobPosted",
      "RungSettled",
      "Claimed"
    ],
    "state_rs": [
      "use anchor_lang::prelude::*;",
      "",
      "declare_id!(\"11111111111111111111111111111111\"); // replaced by the ground program id at deploy",
      "",
      "pub const MAX_RUNGS: usize = 64;",
      "pub const SIGNER_HEIGHT: usize = 10;",
      "pub const WOTS_LEN: usize = 67;",
      "",
      "#[account]",
      "pub struct Genesis {",
      "    pub wallet: Pubkey,              // creator fee recipient named at the top of the spec",
      "    pub mint: Pubkey,",
      "    pub job_id_sha256: [u8; 32],     // sha256 of the provider job id string",
      "    pub counts_sha256: [u8; 32],     // sha256 of canonical_counts(...)",
      "    pub seed: [u8; 32],              // genesis_seed(...)",
      "    pub compute_bps: u16,",
      "    pub settle_bps: u16,",
      "    pub base_cap_lamports: u64,",
      "    pub ratio_q16: u32,",
      "    pub shots_per_job: u32,",
      "    pub peak_margin_q16: u32,",
      "    pub signer_root: [u8; 32],       // Merkle root over 1024 one time public keys",
      "    pub leaves_spent: u16,",
      "    pub spent_bitmap: [u8; 128],     // one bit per leaf, set once, never cleared",
      "    pub current_rung: u8,",
      "    pub sealed: bool,                // true once every leaf is spent",
      "    pub bump: u8,",
      "}",
      "",
      "#[account]",
      "pub struct Rung {",
      "    pub index: u8,",
      "    pub key_bits: u8,",
      "    pub p: u64, pub a: u64, pub b: u64, pub q: u64,",
      "    pub gx: u64, pub gy: u64,",
      "    pub target_x: u64, pub target_y: u64,",
      "    pub cap_threshold_lamports: u64,",
      "    pub crossing_slot: u64,",
      "    pub crossing_signature_sha256: [u8; 32],",
      "    pub tranche_lamports: u64,",
      "    pub compute_paid_lamports: u64,",
      "    pub job_id_sha256: [u8; 32],",
      "    pub counts_sha256: [u8; 32],",
      "    pub recovered_scalar: u64,",
      "    pub outcome: Outcome,",
      "    pub holder_root: [u8; 32],       // balances at crossing_slot, used only when the break fails",
      "    pub claimed_lamports: u64,",
      "    pub bump: u8,",
      "}",
      "",
      "#[derive(AnchorSerialize, AnchorDeserialize, Clone, Copy, PartialEq, Eq)]",
      "pub enum Outcome { Unreached, Crossed, JobPosted, Broken, Held }",
      "",
      "#[error_code]",
      "pub enum BqpError {",
      "    #[msg(\"leaf already spent\")] LeafSpent,",
      "    #[msg(\"signer is sealed\")] Sealed,",
      "    #[msg(\"one time signature does not match the signer root\")] BadSignature,",
      "    #[msg(\"cap has not crossed the rung threshold\")] NotCrossed,",
      "    #[msg(\"rung is in the wrong state\")] WrongState,",
      "    #[msg(\"scalar does not open the target key\")] ScalarMismatch,",
      "    #[msg(\"curve parameters do not match the published table\")] CurveMismatch,",
      "    #[msg(\"claim proof is invalid\")] BadClaim,",
      "}"
    ],
    "curve_rs": [
      "// affine arithmetic on the toy curves. every modulus fits in 64 bits, products are taken in u128.",
      "#[inline] fn addm(x: u64, y: u64, p: u64) -> u64 { ((x as u128 + y as u128) % p as u128) as u64 }",
      "#[inline] fn subm(x: u64, y: u64, p: u64) -> u64 { ((x as u128 + p as u128 - (y % p) as u128) % p as u128) as u64 }",
      "#[inline] fn mulm(x: u64, y: u64, p: u64) -> u64 { ((x as u128 * y as u128) % p as u128) as u64 }",
      "",
      "fn powm(mut b: u64, mut e: u64, p: u64) -> u64 {",
      "    let mut r = 1u64; b %= p;",
      "    while e > 0 { if e & 1 == 1 { r = mulm(r, b, p); } b = mulm(b, b, p); e >>= 1; }",
      "    r",
      "}",
      "#[inline] fn invm(x: u64, p: u64) -> u64 { powm(x, p - 2, p) } // p is prime",
      "",
      "#[derive(Clone, Copy, PartialEq, Eq)]",
      "pub struct Pt { pub x: u64, pub y: u64, pub inf: bool }",
      "pub const O: Pt = Pt { x: 0, y: 0, inf: true };",
      "",
      "pub fn ec_add(p1: Pt, p2: Pt, a: u64, p: u64) -> Pt {",
      "    if p1.inf { return p2; }",
      "    if p2.inf { return p1; }",
      "    if p1.x == p2.x && addm(p1.y, p2.y, p) == 0 { return O; }",
      "    let lam = if p1 == p2 {",
      "        mulm(addm(mulm(3, mulm(p1.x, p1.x, p), p), a, p), invm(mulm(2, p1.y, p), p), p)",
      "    } else {",
      "        mulm(subm(p2.y, p1.y, p), invm(subm(p2.x, p1.x, p), p), p)",
      "    };",
      "    let x3 = subm(subm(mulm(lam, lam, p), p1.x, p), p2.x, p);",
      "    let y3 = subm(mulm(lam, subm(p1.x, x3, p), p), p1.y, p);",
      "    Pt { x: x3, y: y3, inf: false }",
      "}",
      "",
      "pub fn ec_mul(mut k: u64, mut pt: Pt, a: u64, p: u64) -> Pt {",
      "    let mut r = O;",
      "    while k > 0 { if k & 1 == 1 { r = ec_add(r, pt, a, p); } pt = ec_add(pt, pt, a, p); k >>= 1; }",
      "    r",
      "}",
      "",
      "pub fn on_curve(pt: Pt, a: u64, b: u64, p: u64) -> bool {",
      "    if pt.inf { return true; }",
      "    let lhs = mulm(pt.y, pt.y, p);",
      "    let rhs = addm(addm(mulm(mulm(pt.x, pt.x, p), pt.x, p), mulm(a, pt.x, p), p), b % p, p);",
      "    lhs == rhs",
      "}",
      "",
      "pub fn opens_target(d: u64, r: &Rung) -> bool {",
      "    let g = Pt { x: r.gx, y: r.gy, inf: false };",
      "    let t = Pt { x: r.target_x, y: r.target_y, inf: false };",
      "    d > 0 && d < r.q && ec_mul(d, g, r.a, r.p) == t",
      "}"
    ],
    "wots_rs": [
      "use anchor_lang::solana_program::hash::hashv;",
      "",
      "const W: u8 = 16;",
      "const TAG: &[u8] = b\"bqp/wots/v1\";",
      "const BAR: &[u8] = b\"|\";",
      "",
      "fn chain(mut x: [u8; 32], start: u8, steps: u8, leaf: u32, pos: u16) -> [u8; 32] {",
      "    let l = leaf.to_le_bytes(); let p = pos.to_le_bytes();",
      "    for i in start..start + steps {",
      "        x = hashv(&[TAG, BAR, &l, BAR, &p, BAR, &[i], BAR, &x]).to_bytes();",
      "    }",
      "    x",
      "}",
      "",
      "fn digits(msg: &[u8; 32]) -> [u8; WOTS_LEN] {",
      "    let mut d = [0u8; WOTS_LEN]; let mut csum: u16 = 0;",
      "    for (i, b) in msg.iter().enumerate() {",
      "        d[2 * i] = b >> 4; d[2 * i + 1] = b & 15;",
      "        csum += (W - 1 - d[2 * i]) as u16 + (W - 1 - d[2 * i + 1]) as u16;",
      "    }",
      "    d[64] = ((csum >> 8) & 15) as u8; d[65] = ((csum >> 4) & 15) as u8; d[66] = (csum & 15) as u8;",
      "    d",
      "}",
      "",
      "pub fn verify_one_time(",
      "    g: &mut Genesis, leaf: u32, msg: &[u8; 32],",
      "    sig: &[[u8; 32]; WOTS_LEN], path: &[[u8; 32]; SIGNER_HEIGHT],",
      ") -> Result<()> {",
      "    require!(!g.sealed, BqpError::Sealed);",
      "    let byte = (leaf / 8) as usize; let bit = 1u8 << (leaf % 8);",
      "    require!(g.spent_bitmap[byte] & bit == 0, BqpError::LeafSpent);",
      "",
      "    let d = digits(msg);",
      "    let mut acc: Vec<u8> = Vec::with_capacity(TAG.len() + 3 + 33 * WOTS_LEN);",
      "    acc.extend_from_slice(TAG); acc.extend_from_slice(BAR); acc.extend_from_slice(b\"pk\");",
      "    for i in 0..WOTS_LEN {",
      "        let top = chain(sig[i], d[i], W - 1 - d[i], leaf, i as u16);",
      "        acc.extend_from_slice(BAR); acc.extend_from_slice(&top);",
      "    }",
      "    let pk = hashv(&[&acc]).to_bytes();",
      "    let mut node = hashv(&[TAG, BAR, b\"leaf\", BAR, &pk]).to_bytes();",
      "    let mut idx = leaf;",
      "    for sib in path.iter() {",
      "        node = if idx & 1 == 0 { hashv(&[TAG, BAR, b\"node\", BAR, &node, BAR, sib]).to_bytes() }",
      "               else            { hashv(&[TAG, BAR, b\"node\", BAR, sib, BAR, &node]).to_bytes() };",
      "        idx >>= 1;",
      "    }",
      "    require!(node == g.signer_root, BqpError::BadSignature);",
      "",
      "    g.spent_bitmap[byte] |= bit;",
      "    g.leaves_spent += 1;",
      "    if g.leaves_spent as usize == 1 << SIGNER_HEIGHT { g.sealed = true; }",
      "    Ok(())",
      "}"
    ],
    "instructions_rs": [
      "#[program]",
      "pub mod bqp {",
      "    use super::*;",
      "",
      "    // called once, inside the same transaction that creates the mint",
      "    pub fn init_genesis(ctx: Context<InitGenesis>, args: GenesisArgs) -> Result<()> {",
      "        let g = &mut ctx.accounts.genesis;",
      "        g.wallet = ctx.accounts.wallet.key();",
      "        g.mint = ctx.accounts.mint.key();",
      "        g.job_id_sha256 = args.job_id_sha256;",
      "        g.counts_sha256 = args.counts_sha256;",
      "        g.seed = args.seed;",
      "        g.compute_bps = args.compute_bps;",
      "        g.settle_bps = 10_000 - args.compute_bps;",
      "        g.base_cap_lamports = args.base_cap_lamports;",
      "        g.ratio_q16 = args.ratio_q16;",
      "        g.shots_per_job = args.shots_per_job;",
      "        g.peak_margin_q16 = args.peak_margin_q16;",
      "        g.signer_root = args.signer_root;",
      "        g.bump = ctx.bumps.genesis;",
      "        emit!(GenesisSet { seed: g.seed, signer_root: g.signer_root });",
      "        Ok(())",
      "    }",
      "",
      "    // permissionless. anyone may call it on the first trade that leaves the pool above the threshold.",
      "    pub fn cross_rung(ctx: Context<CrossRung>, curve: CurveArgs, crossing_sig_sha256: [u8; 32]) -> Result<()> {",
      "        let g = &mut ctx.accounts.genesis;",
      "        let r = &mut ctx.accounts.rung;",
      "        let threshold = threshold_for(g, g.current_rung);",
      "        let cap = implied_cap_lamports(&ctx.accounts.pool, &ctx.accounts.mint)?;",
      "        require!(cap >= threshold, BqpError::NotCrossed);",
      "        require!(curve_matches_table(g.current_rung, &curve), BqpError::CurveMismatch);",
      "",
      "        r.index = g.current_rung; r.key_bits = curve.key_bits;",
      "        r.p = curve.p; r.a = curve.a; r.b = curve.b; r.q = curve.q; r.gx = curve.gx; r.gy = curve.gy;",
      "        r.cap_threshold_lamports = threshold;",
      "        r.crossing_slot = Clock::get()?.slot;",
      "        r.crossing_signature_sha256 = crossing_sig_sha256;",
      "",
      "        // target scalar comes from data nobody controlled before the crossing trade existed",
      "        let h = hashv(&[b\"bqp/target/v1\", &g.seed, &[r.index], &crossing_sig_sha256]).to_bytes();",
      "        let d = 1 + u64::from_le_bytes(h[..8].try_into().unwrap()) % (r.q - 1);",
      "        let t = ec_mul(d, Pt { x: r.gx, y: r.gy, inf: false }, r.a, r.p);",
      "        r.target_x = t.x; r.target_y = t.y;",
      "",
      "        r.tranche_lamports = ctx.accounts.vault.lamports();",
      "        r.outcome = Outcome::Crossed;",
      "        r.bump = ctx.bumps.rung;",
      "        emit!(RungCrossed { index: r.index, cap, target_x: t.x, target_y: t.y });",
      "        Ok(())",
      "    }",
      "",
      "    // signer action, spends one leaf. pays the compute share and commits to the job before results exist.",
      "    pub fn post_job(ctx: Context<SignerAction>, leaf: u32, sig: [[u8; 32]; WOTS_LEN],",
      "                    path: [[u8; 32]; SIGNER_HEIGHT], job_id_sha256: [u8; 32]) -> Result<()> {",
      "        let g = &mut ctx.accounts.genesis; let r = &mut ctx.accounts.rung;",
      "        require!(r.outcome == Outcome::Crossed, BqpError::WrongState);",
      "        let msg = hashv(&[b\"post_job\", &[r.index], &job_id_sha256]).to_bytes();",
      "        verify_one_time(g, leaf, &msg, &sig, &path)?;",
      "        let pay = (r.tranche_lamports as u128 * g.compute_bps as u128 / 10_000) as u64;",
      "        move_lamports(&ctx.accounts.vault, &ctx.accounts.compute_payee, pay)?;",
      "        r.compute_paid_lamports = pay; r.job_id_sha256 = job_id_sha256; r.outcome = Outcome::JobPosted;",
      "        Ok(())",
      "    }",
      "",
      "    // signer action, spends one leaf. the program itself checks that the scalar opens the target.",
      "    pub fn settle(ctx: Context<SignerAction>, leaf: u32, sig: [[u8; 32]; WOTS_LEN],",
      "                  path: [[u8; 32]; SIGNER_HEIGHT], counts_sha256: [u8; 32],",
      "                  recovered: u64, passed_margin: bool, holder_root: [u8; 32]) -> Result<()> {",
      "        let g = &mut ctx.accounts.genesis; let r = &mut ctx.accounts.rung;",
      "        require!(r.outcome == Outcome::JobPosted, BqpError::WrongState);",
      "        let msg = hashv(&[b\"settle\", &[r.index], &counts_sha256, &recovered.to_le_bytes(),",
      "                          &[passed_margin as u8], &holder_root]).to_bytes();",
      "        verify_one_time(g, leaf, &msg, &sig, &path)?;",
      "        r.counts_sha256 = counts_sha256; r.recovered_scalar = recovered;",
      "        let rest = r.tranche_lamports - r.compute_paid_lamports;",
      "        if passed_margin && opens_target(recovered, r) {",
      "            r.outcome = Outcome::Broken;          // the key fell: buy the coin with the rest and burn it",
      "            buy_and_burn(&ctx, rest)?;",
      "        } else {",
      "            r.outcome = Outcome::Held;            // the key held: the rest is claimable by holders at the crossing slot",
      "            r.holder_root = holder_root;",
      "        }",
      "        g.current_rung += 1;",
      "        emit!(RungSettled { index: r.index, broken: r.outcome == Outcome::Broken, recovered });",
      "        Ok(())",
      "    }",
      "",
      "    // holder claim after a held rung. leaf = sha256(owner, balance_at_crossing, total_supply_at_crossing)",
      "    pub fn claim(ctx: Context<Claim>, balance: u64, supply: u64, proof: Vec<[u8; 32]>) -> Result<()> {",
      "        let r = &mut ctx.accounts.rung;",
      "        require!(r.outcome == Outcome::Held, BqpError::WrongState);",
      "        let mut node = hashv(&[ctx.accounts.owner.key.as_ref(), &balance.to_le_bytes(), &supply.to_le_bytes()]).to_bytes();",
      "        for sib in proof.iter() {",
      "            node = if node <= *sib { hashv(&[&node, sib]).to_bytes() } else { hashv(&[sib, &node]).to_bytes() };",
      "        }",
      "        require!(node == r.holder_root, BqpError::BadClaim);",
      "        let rest = r.tranche_lamports - r.compute_paid_lamports;",
      "        let due = (rest as u128 * balance as u128 / supply as u128) as u64;",
      "        mark_claimed(&mut ctx.accounts.receipt)?;",
      "        move_lamports(&ctx.accounts.vault, &ctx.accounts.owner, due)?;",
      "        r.claimed_lamports += due;",
      "        Ok(())",
      "    }",
      "}",
      "",
      "fn threshold_for(g: &Genesis, rung: u8) -> u64 {",
      "    let mut cap = g.base_cap_lamports as u128;",
      "    for _ in 0..rung { cap = (cap * g.ratio_q16 as u128) >> 16; }",
      "    cap as u64",
      "}"
    ],
    "compute_notes": [
      "one winternitz verification is at most 67 * 15 = 1005 sha256 calls plus 10 for the path. post_job and settle each request the maximum compute budget.",
      "the signature (2144 bytes) and path (320 bytes) do not fit one transaction. they are written to a scratch account in chunks, then the instruction reads them from that account.",
      "curve checks are 64 bit modular arithmetic, a few thousand compute units at 16 bits."
    ],
    "authorities_after_deploy": {
      "upgrade_authority": "none, set to null in the deploy transaction",
      "mint_authority": "none",
      "freeze_authority": "none"
    },
    "explorer_name": {
      "goal": "the program account shows the readable name bqp on solana explorers",
      "steps": [
        "set the crate name and the anchor program name to bqp before building",
        "embed a security_txt block in the program with name set to bqp, plus project_url and source_code",
        "build with anchor's verifiable build option so the binary is reproducible",
        "deploy, then publish the idl on chain with anchor idl init using the program id and target/idl/bqp.json",
        "submit the verified build with solana verify against the public repo and commit hash",
        "only after the idl and verification are live, set the upgrade authority to none",
        "confirm on two explorers that the account header reads bqp and the idl tab lists all six instructions"
      ]
    }
  },
  "site_data_map": {
    "rule": "every value on the site is read from an account, an event, or the published job files. a null here renders as an empty slot.",
    "sources": {
      "seed_and_genome": "genesis account",
      "rung_table": "rung accounts 0 through current_rung",
      "leaf_map": "genesis.spent_bitmap",
      "vault_balance": "vault lamports",
      "histograms": "raw counts file per job id, verified against counts_sha256 before drawing",
      "break_or_hold_history": "RungSettled events"
    },
    "diagrams": [
      "circuit plate per rung: registers as horizontal rails, controlled additions as boxes, drawn from the register sizes in the rung table",
      "vote histogram per rung: one bar per scalar from recover(), winning bar marked, uniform baseline as a hairline",
      "leaf map: 32 by 32 grid, one cell per one time key, filled when its bit is set",
      "threshold ladder: computed table of rung, key bits, threshold, outcome"
    ]
  },
  "trust_model": {
    "what_the_chain_enforces": [
      "parameters equal the genome of the stored seed",
      "targets come from the crossing transaction",
      "a rung can only be called broken if the scalar really opens the target",
      "each signer leaf is used once",
      "splits and claims add up"
    ],
    "what_the_chain_cannot_see": [
      "that the counts came from quantum hardware rather than a simulator or a classical solve",
      "that the job id belongs to the circuit in this file"
    ],
    "how_that_gap_is_narrowed": [
      "the job id hash is committed before results exist",
      "the provider resolves the job id to its circuit, backend and counts for anyone",
      "post processing is deterministic and public",
      "a classical cheat would have to forge a provider job, not just a number"
    ],
    "plain_statement": "bqp proves nothing about large keys. at these sizes a laptop wins instantly. what it records is the largest key a real machine has actually returned through shor's circuit, paid for by the coin, with every run public."
  },
  "references": {
    "resource_formula": {
      "source": "Roetteler, Naehrig, Svore, Lauter, Quantum resource estimates for computing elliptic curve discrete logarithms, 2017",
      "logical_qubits": "9n + 2*ceil(log2 n) + 10",
      "toffoli_gates": "448 * n^3 * log2(n) + 4090 * n^3",
      "note": "the per rung fault tolerant numbers in this file are these formulas evaluated at the rung's bit size. they are not what the toy circuits use."
    },
    "same_formula_at_real_key_sizes": [
      {
        "key_bits": 160,
        "logical_qubits": 1466,
        "toffoli_gates": 30188436630
      },
      {
        "key_bits": 192,
        "logical_qubits": 1754,
        "toffoli_gates": 52999672669
      },
      {
        "key_bits": 224,
        "logical_qubits": 2042,
        "toffoli_gates": 85281321345
      },
      {
        "key_bits": 256,
        "logical_qubits": 2330,
        "toffoli_gates": 128748355584
      },
      {
        "key_bits": 384,
        "logical_qubits": 3484,
        "toffoli_gates": 449364531942
      },
      {
        "key_bits": 521,
        "logical_qubits": 4719,
        "toffoli_gates": 1150212175543
      }
    ],
    "recent_estimate": {
      "claim": "a march 2026 google estimate put breaking 256 bit elliptic curve cryptography at about 1,200 logical qubits",
      "reported_by": "https://bitcoinfoundation.org/news/ai-news/ai-quantum-threat/",
      "note": "far below the 2017 formula above, which is why the timeline argument restarted"
    },
    "solana_signature_scheme": "ed25519, the address is the public key",
    "post_quantum_standards": [
      "FIPS 203 ML-KEM",
      "FIPS 204 ML-DSA",
      "FIPS 205 SLH-DSA"
    ]
  },
  "build_status": "reference specification. the python and rust in this file have not been compiled, run on hardware, or audited."
}
