Google Hid Its Quantum Recipe. A Bunch of Amateurs Beat It.
Google used a zero-knowledge proof to show it had found a more resource-efficient quantum attack, without publishing the circuit. Yukon turned the problem into an open competition where agents build on each other's submissions — and the field beat Google's result by more than 60%.
The video won't play here. Listen to the audio instead:
The argument · tap a timestamp to hear it
Google gives the proof, not the circuit
Google published a paper claiming a more resource-efficient quantum approach than the previous state of the art for breaking the secp256k1 elliptic curve — the basis of Bitcoin's and Ethereum's public-key cryptography. But Google did not publish the approach; it used a zero-knowledge proof to demonstrate that it does possess such an approach. Soubhik points out the consequence: if you want to prepare for Q-day, you have to know what approaches will appear, how to harden systems, what the defences are; if you don't understand any of that, you are not prepared for Q-day. Not publishing the quantum circuit is the main consequence here.
— Soubhik DebThe competition is not solo work, it is a relay
ecdsa.fail is not played by everyone doing the work locally and then submitting. The platform backend runs the same verifier Google used; through a command-line interface you have your agent read the competition details and other people's submissions, then build directly on top of someone else's approach. Soubhik says this is how research actually works: you build on each other's experience, not like an Olympic event where everyone submits independently. Anna says she had assumed it was PvP, everyone finishing on their own machine and submitting to compete; Soubhik confirms it is not. This multi-user automated-research framework produced enormous acceleration, because you don't have to rediscover everything yourself.
— Soubhik DebThree breakthroughs: externalising, mining, starting over
Soubhik sees three big breakthroughs. The first was externalising the environment and letting people outside the company take part — one team member who had not been involved in internal testing spent roughly $5,000 on a codex subscription the day before internal testing and made a huge jump that the lead engineer could not understand. The second was mining French's work, building on it and surpassing Google's result within two weeks. After that the chart was almost a plateau for two months. The third came in mid-August: Teddy, from Starkware, went back to the starting point of the competition, summarised all the techniques into a knowledge review, and then built from scratch rather than on other people's ideas, ultimately proposing the NSD ping-pong technique, which pushed the approach from 49% better than Google to 57% better, and now past 60%.
— Soubhik DebIf the question is posed wrong, there is no competition
Soubhik says many problems are posed incorrectly — that is, badly formulated. He gives the example: ‘Build me a quantum computer’ — that problem is too big, we don't know what it is. But if you break it down, you find that the problem state of ecdsa.fail is one of its subproblems. You need to split the big problem into a series of well-formulated subtasks, then run automated research on each subtask. Another example is the proximity gap conjecture: EF committed a $1 million prize, but the original statement is binary — you either prove it or you don't — and it is hard to write a verifier for it. Later Alexander Hicks and Gako wrote a simple verifier for one specific instance of the conjecture, and that is what became the better.codes competition.
— Soubhik DebAn algebraic geometer broke 64 bits in hours
better.codes has two bounds: the lower bound is the soundness bound, the upper bound is the attack bound. The lower bound had been stuck at the Johnson bound for years. On August 21 the competition was stuck at 63.99 bits, and 64 bits is the Johnson bound for this specific instance. Then there was no progress for 6 days; the chart was a straight line. Until August 28, when the team contacted Bartosz from ECDSA — a Polish mathematician specialising in algebraic geometry, not a cryptographer at all, who had never heard of the problem. Within a few hours of joining he pushed the result from 63.99 to 64.0101 bits, breaking the Johnson bound for the first time. The technique he used was some combination of algebraic geometry, because he had already been using his own codex subscription to do algebraic geometry work, and he probably applied algebraic geometry methods to this problem.
— Soubhik DebOne breakthrough detonated a 30-year open problem
After Bartosz broke 64.01 bits, the whole circle blew up, with Ariel Gabizon, Kobi and others discussing it on Twitter. The story did not end there: a few days later, some cryptographers had a bigger problem in coding theory that had been open for 30 years — proving a certain soundness bound. Within days three papers appeared claiming inspiration from the method used to break the Johnson bound. Soubhik says nobody could have predicted this; this is open innovation and collaborative research, and it still looks very early: people are starting to realise that problems they thought would not be solved for a long time can at least be pushed forward and improved.
— Soubhik DebDomain experts guide agents on GitHub
On the hish tiling problem, Yukon piloted a discussion-format feature. The whole process is in the CLI; you don't even need to think or prompt your agent. While doing research the agent searches for information in the hills and formulates strategies locally, and at the same time uploads discussions to a GitHub forum. Other agents read those discussions, and domain experts like Bartosz answer by hand, and the agents read those answers — so the domain expert is effectively steering the automated-research network. Soubhik says this is exactly what they want: a domain expert should see where the automated-research network has got to on his problem statement, then use his best intuition to steer it and leave clues about what to explore.
— Soubhik DebYukon wants to be an AI-native research institution
Soubhik says Yukon's vision is to grow into an AI-based research institution, imitating three features of traditional research institutions: research means building at a higher level on each other's ideas; the originators of ideas must be credited; and even failed ideas should be recognised, because one success may come out of a thousand failures. What AI changes is that the whole research lifecycle accelerates from months or years to days. They are implementing a partial credit system so people can give each other credit for ideas, including negative credit — failed ideas also earn credit. They also want a system that helps you decompose a badly formulated problem into a series of well-formulated subproblems.
— Soubhik DebIn their own words · checked verbatim
And the downside of that is that if you want to protect yourself from Qday, you have to know what schemes are going to emerge, how to harden the system against it, what are the defense mechanisms, right? And if you don't have an understanding of that, it's bad, like you're not ready for Qday.
Soubhik Deb6:08
You can access failed ideas, not just successful applications, failed applications. Sometimes in research , something fails because something else is missing, but then some successful trick comes along, you put them together, and you definitely get a huge improvement.
Soubhik Deb13:08
He is an expert in algebraic geometry. He is not a cryptographer at all. He had never heard of this problem.
Soubhik Deb40:15
We really see Yukon developing as an AI-based scientific institution.
Soubhik Deb53:20
one of the leading participants in ECDSA. Fail is a landscape designer . Wow. There's another guy who's a farmer, but now they have an additional hobby, they were involved in EC, and now they know a lot about quantum circuits
Soubhik Deb1:01:24
Figures
| ecdsa.fail improvement over Google's approach | 2.6x | 10:08 |
| Prize money the platform pays out per week | $10,000 | 15:09 |
| Spent by a team member on a codex subscription the day before internal testing | about $5,000 | 11:08 |
| Johnson bound where better.codes got stuck | 64 bits | 39:15 |
| Result after Bartosz's breakthrough | 64.0101 bits | 39:15 |
| Current record on the hish tiling problem | about 4.9881 layers | 45:18 |
| lighter.fast optimisation factor | more than 10.5x | 36:15 |
| lighter.fast initial prize pool | about 15,000 illuminated tokens | 36:15 |
| lighter.fast final prize pool | 25,000 tokens | 36:15 |
| snark.fast improvement on Apple Silicon | more than 3x | 19:11 |
Glossary
- Q-day
- The day quantum computers can break existing cryptography.
- Johnson bound
- A classical upper bound in coding theory on the soundness of error-correcting codes.
- proximity gap
- A conjecture in coding theory about the proximity of codewords; EF once put a $1 million prize on it.
- NSD ping-pong
- A quantum-circuit optimisation technique proposed by Teddy in ecdsa.fail.
- MLX
- Apple's machine-learning framework for running models on Apple Silicon.
- Dark Bloom
- An IEN Labs project that plugs idle Mac hardware into a network to serve inference.
How to listen
Founders and researchers following AI for science, ZK cryptography and open innovation mechanisms — especially those who want to understand how automated-research competitions get organised.
The sponsor read and the opening guest background can be skipped; start at 4:07.