Attackability

Every conjecture under c/ has a score out of 31, answering one question: if a machine had a fixed budget and attacked this, would it come back with something correct, not trivial, and not already known? Higher is better.

It is not how likely the statement is to be true, not how hard it is for a person, and not how important it is.

Not the difficulty grade

The difficulty grade measures how far a statement is from known technique. This measures effort, for one worker: a machine on a budget.

They disagree often. c/0001 scores 11, because a person knows what to try but the answer is a simulator, with no number to compute and no small case to check. c/0015 scores 25, because nobody has ever attempted it and you can check the answer by brute force on ten leaves.

So this is not a ranking of importance. Eight of the top nine were raised in one sentence by their own source and dropped.

What the score is made of

Can it find anything? (12) Machines build things well and prove non-existence badly. Asking for a construction scores well; asking for a lower bound against unlimited preprocessing scores near zero.

Can you tell if the answer is right? (12) Same weight, on purpose. The usual failure is not a wrong proof but a correct proof of a slightly different statement, which passes every local check.

Has anyone tried, and can you get the papers? (7) A conjecture mentioned once and dropped beats a famous one.

Penalties come off mainly for the answer possibly being in the training data already, where recall looks like discovery.

The eight questions Out of
Build something, or rule something out? 4
Is there a settled special case to climb from? 4
How many papers must be combined? 4
Is the statement pinned to exactly one reading? 6
Is there a small case you can settle exactly? 3
Can a proof assistant hold it? 3
Did anyone ever try? 4
Are the sources reachable, and the proof short? 3

Two are counterintuitive. Long and boring beats short and clever: needing a whole new idea caps that question at 1. And obscurity counts in favour, because being open usually means nobody looked.

Bands and verdicts

The band is the same number read as difficulty, for this machine rather than in general.

Band Score What to do
prime 26 to 31 Start here.
reachable 22 to 25 Worth a full attempt.
stretch 18 to 21 Search the literature, try to refute it, plan the special cases. No proof budget yet.
hard 15 to 17 Same, and expect the refutation attempt to be the whole return.
very hard 8 to 14 Expect a note saying why it is stuck.
out of reach 0 to 7 No proof budget.
gated n/a Stopped before scoring.

go needs 22, with at least 7 in each of the first two groups; probe needs 15; below that is park. A statement whose reading cannot be pinned is capped at probe. One that is cheap to try to refute is promoted from park to probe, which is why c/0050, c/0051 and c/0053 are probes at 11, 12 and 14.

The ranking

Every statement on the site now has a score. The table below is two passes merged, and the Pass column says which: 53 rows scored 23 August 2026, and 53 rows scored 30 August 2026 covering c/0057 through c/0109, which the first pass predates. Three things to know before using it.

The two passes were scored a week apart, and the second runs higher. Mean total is 21.2 against 19.6, and 24 of the second pass’s 50 scored statements are go against 13 of the first pass’s 40. The rubric warns that the scale inflates by about two points per batch unless the calibration anchors are re-read, and 1.6 points is inside that warning, so drift cannot be ruled out and a one-point difference across passes should be read as noise. The anchors were re-read at the start of every batch of ten in the second pass, and both passes use the same four worked anchors.

Two things say at least part of the gap is real rather than drift, and one says the obvious explanation is wrong. The proof-path axis is identical across passes, mean P 7.9 both times, so the second corpus is not being judged easier to prove. What differs is opportunity, mean O 6.5 against 5.2: the second corpus is almost entirely 2022 to 2026 sources whose conjectures are one-line asides nobody has attempted, where the first had more named conjectures with a following. Verification is higher too, mean V 9.6 against 8.6. But it is not because the second pass has more exactly-checkable statements: 23 of 50 score the maximum on refutation affordance against 21 of 40, which is the same rate. The second pass also takes larger risk deductions, mean -2.7 against -2.1.

The corpora do differ in direction. The first pass is 27 constructions against 7 lower bounds; the second is 24 against 20. So the second half of this table is far more lower-bound-heavy, which is the harder side, and it still scores higher. Read that as a reason to check the second pass’s O scores first if you doubt the merge.

One entry is out of date. c/0048 is marked go below but has since been solved, affirmatively and more strongly than the conjecture asked: a signed reweighting reaching an exact rank-one second moment at entropy cost O(log n), below every n^delta. Its row is kept, struck through, rather than deleted, so the scale can still be judged against a case whose answer is now known.

Check a conjecture’s own page before starting: work can be in flight that this snapshot does not know about. c/0010 is top of the table and already has a partial solution, now blind-verified.

Statement Score Band P V O Risk Verdict Pass
c/0010 Split-source decomposition 27 prime 11 10 7 -1 go Aug 23
c/0023 Polynomial Compatibility Conjecture 27 prime 9 12 7 -1 go Aug 23
c/0096 Conflict Checkable Codes Beyond Half-Singleton 27 prime 11 11 7 -2 go Aug 30
c/0030 Optimal martingale gap finders 26 prime 10 10 7 -1 go Aug 23
c/0034 Ring-LWE error parity 26 prime 10 12 7 -3 go Aug 23
c/0076 Perfect FASS at 3-out-of-5 26 prime 10 12 7 -3 go Aug 30
c/0015 Best-first search trees 25 reachable 9 11 6 -1 go Aug 23
c/0047 Single-session lattice Chevallier-Mames tightness 25 reachable 10 8 7 0 go Aug 23
c/0073 Perfectly Correct Statistical ARE 25 reachable 10 11 7 -3 go Aug 30
c/0052 Two-block sponge attack, quadratic advice 24 reachable 10 10 7 -3 go Aug 23
c/0083 Statistical Robust ARE 24 reachable 10 10 7 -3 go Aug 30
c/0086 EA-Code Distance over Rings 24 reachable 9 11 7 -3 go Aug 30
c/0106 XOR as a Weak 2-Immunizer 24 reachable 10 10 7 -3 go Aug 30
c/0109 CPA PKE, Quantumly Broken 24 reachable 11 9 7 -3 go Aug 30
c/0045 Blockwise-random quadratic recovery 23 reachable 10 10 6 -3 go Aug 23
c/0048 Signed rank-one reweighting below the square root 23 reachable 10 10 6 -3 solved since Aug 23
c/0049 Best Separable State, constant completeness error 23 reachable 10 10 6 -3 go Aug 23
c/0059 Binary dual-distance bound is the worst case 23 reachable 8 11 7 -3 go Aug 30
c/0064 Short-Salt MD Combiner Security 23 reachable 10 9 7 -3 go Aug 30
c/0066 Almost k-Wise Locality Gap 23 reachable 8 11 7 -3 go Aug 30
c/0070 DPP Field Size 23 reachable 9 10 7 -3 go Aug 30
c/0074 Distance from Lines Modulo a Prime 23 reachable 7 11 7 -2 go Aug 30
c/0075 WP Threshold Share Size 23 reachable 8 11 7 -3 go Aug 30
c/0078 Arithmetic Two-Server PIR Optimality 23 reachable 9 10 7 -3 go Aug 30
c/0084 Planted-Subgraph Character Sum 23 reachable 7 11 7 -2 go Aug 30
c/0087 Randomness Complexity of XOR 23 reachable 9 11 6 -3 go Aug 30
c/0093 No Self-Reduction for LSN 23 reachable 8 10 7 -2 go Aug 30
c/0032 One erasing challenge vs many embedding learns 22 reachable 10 9 6 -3 go Aug 23
c/0033 Standard real-or-random vs embedding two-ciphertext 22 reachable 10 9 6 -3 go Aug 23
c/0043 Certifying no small non-expanding set 22 reachable 9 10 6 -3 go Aug 23
c/0067 MDSD Linear-Test Bias 22 reachable 8 10 7 -3 go Aug 30
c/0069 Balanced Root-n Preprocessing PIR 22 reachable 10 8 6 -2 go Aug 30
c/0079 NISC Overhead from a PRG 22 reachable 10 8 6 -2 go Aug 30
c/0080 Hold-Out Soundness, Dirty Coordinates 22 reachable 7 10 7 -2 go Aug 30
c/0085 Sub-log Share Size for 2-out-of-n 22 reachable 9 10 6 -3 go Aug 30
c/0090 192-Round AES Pairwise Independence 22 reachable 8 10 7 -3 go Aug 30
c/0094 CHV Online Threshold 22 reachable 7 11 7 -3 go Aug 30
c/0008 No 2-element split NILPs 21 stretch 7 10 5 -1 probe Aug 23
c/0013 No round-optimal pairing-free blind signature 21 stretch 8 8 5 0 probe Aug 23
c/0022 CAQB key agreement, imperfect completeness 21 stretch 7 9 7 -2 probe Aug 23
c/0024 Four-party NIKE, quadratic, Maurer’s model 21 stretch 10 10 4 -3 probe Aug 23
c/0025 Quadratic attack on 3-NIKE, Shoup’s model 21 stretch 9 10 5 -3 probe Aug 23
c/0028 Fully quantum time-lock puzzles 21 stretch 8 8 7 -2 probe Aug 23
c/0031 Erasing real-or-random vs Boneh–Zhandry 21 stretch 9 9 6 -3 probe Aug 23
c/0041 Partial-PKI consensus up to one-half resilience 21 stretch 11 8 3 -1 probe Aug 23
c/0061 Non-adaptive DDH bound 21 stretch 7 10 7 -3 probe Aug 30
c/0068 Polylog Shuffle PIR, Negligible Error 21 stretch 9 8 6 -2 probe Aug 30
c/0071 Efficient Parity-Tolerance Simulation 21 stretch 9 8 6 -2 probe Aug 30
c/0088 Degree-2 Statistical RE 21 stretch 9 11 4 -3 probe Aug 30
c/0102 Sources vs Randomness Blowup 21 stretch 6 11 7 -3 probe Aug 30
c/0104 One Haar State Looks Like Many 21 stretch 7 9 7 -2 probe Aug 30
c/0105 Quasi-Abelian GV, Growing Group 21 stretch 7 10 7 -3 probe Aug 30
c/0108 Permuted Codes Conjecture 21 stretch 8 10 6 -3 probe Aug 30
c/0044 No expanding weak quadratic PRGs 20 stretch 9 10 4 -3 probe Aug 23
c/0057 Subexponential-query PCF from sparse LPN 20 stretch 9 7 6 -2 probe Aug 30
c/0060 r-round DLOG tradeoff 20 stretch 6 10 7 -3 probe Aug 30
c/0062 Optimal 2D LPHS 20 stretch 7 10 6 -3 probe Aug 30
c/0065 Sublinear-Time CGKA Refresh 20 stretch 9 7 6 -2 probe Aug 30
c/0072 dv-SNARG, One Group Element 20 stretch 9 7 6 -2 probe Aug 30
c/0095 SBP Collision Resistance 20 stretch 6 10 7 -3 probe Aug 30
c/0098 Planted k-OV Hardness 20 stretch 6 11 6 -3 probe Aug 30
c/0100 SZK Batch Verification 20 stretch 10 7 6 -3 probe Aug 30
c/0107 SK-DEPIR from One-Way Functions 20 stretch 7 9 7 -3 probe Aug 30
c/0021 Simon-oracle amplification, strong version 19 stretch 6 8 7 -2 probe Aug 23
c/0036 Compressed permutation oracle soundness 19 stretch 8 10 5 -4 probe Aug 23
c/0058 Standard-model weak PCF from sparse LPN 19 stretch 8 7 6 -2 probe Aug 30
c/0077 RBR Soundness Amplification 19 stretch 6 9 7 -3 probe Aug 30
c/0091 AES t-Wise Independence, t > 2 19 stretch 7 9 6 -3 probe Aug 30
c/0097 RM Gap to Capacity for BEC 19 stretch 6 11 5 -3 probe Aug 30
c/0017 No key agreement from GC-OWF 18 stretch 7 6 5 0 probe Aug 23
c/0103 Seeded Extractors Are Multi-Instance 18 stretch 5 9 7 -3 probe Aug 30
c/0007 3-way collision, oblivious sequential curve 17 hard 7 8 5 -3 probe Aug 23
c/0020 OWFs are black-box useless for key agreement 17 hard 8 6 4 -1 probe Aug 23
c/0035 CRS-free everlasting commitment from malicious PUFs 17 hard 8 6 4 -1 probe Aug 23
c/0081 RS Proximity Gaps to Capacity 17 hard 6 10 4 -3 probe Aug 30
c/0002 Generalized mirror theory 16 hard 7 9 2 -2 probe Aug 23
c/0042 PKE from constant-noise planted k-XOR 16 hard 7 7 4 -2 probe Aug 23
c/0055 Two-scheme key cycle 16 hard 5 6 6 -1 probe Aug 23
c/0092 SSS Implies Fiat-Shamir Friendly 16 hard 6 8 5 -3 probe Aug 30
c/0012 Censoring can only hurt 15 hard 6 10 3 -4 probe Aug 23
c/0014 Three moves from DL, ROM only 15 hard 8 7 2 -2 probe Aug 23
c/0029 OWF minimality, non-black-box reductions 14 very hard 5 5 4 0 park Aug 23
c/0053 Quantum two-block MD collisions 14 very hard 4 8 6 -4 probe Aug 23
c/0054 Composability implies circular security 14 very hard 3 6 6 -1 park Aug 23
c/0099 CSAT with Small Space and Preprocessing 14 very hard 5 6 6 -3 park Aug 30
c/0101 iO Overhead, Single-Output 14 very hard 3 8 6 -3 park Aug 30
c/0051 STB conjecture (sponge) 12 very hard 4 8 3 -3 probe Aug 23
c/0001 6-round Feistel indifferentiability 11 very hard 6 5 3 -3 park Aug 23
c/0050 STB conjecture (Merkle-Damgård) 11 very hard 4 8 2 -3 probe Aug 23
c/0003 Tight \(k\)-collision time-space tradeoff n/a gated contract repair Aug 23
c/0004 LHL extraction, public seed n/a gated scout only Aug 23
c/0011 Logarithmic independence implies PRP n/a gated no go Aug 23
c/0016 Level-optimal beyond disjunctions n/a gated contract repair Aug 23
c/0018 Computationally unique VDFs in the ROM n/a gated scout only Aug 23
c/0019 OWFs are black-box helpful for CRHFs n/a gated contract repair Aug 23
c/0026 RBE update bound, key-dependent schedules n/a gated scout only Aug 23
c/0027 RBE needs Ω(log n) updates n/a gated scout only Aug 23
c/0037 Double-sided zero search n/a gated scout only Aug 23
c/0038 Constant-round Luby–Rackoff, quantum n/a gated scout only Aug 23
c/0039 Threshold one-shot decryption without extractability n/a gated contract repair Aug 23
c/0040 Dream DPT for a moderately hard function n/a gated contract repair Aug 23
c/0046 1+1 adaptively secure lattice threshold signature n/a gated scout only Aug 23
c/0056 Classical presampling, quantum queries n/a gated no go Aug 23
c/0063 Salt Length vs. Call Count n/a gated contract repair Aug 30
c/0082 Constant-Overhead AMD Circuits n/a gated no go Aug 30
c/0089 AVPs Are Lengthy n/a gated no go Aug 30

What the pass found

Seventeen were stopped before scoring. A stop is not a bad grade. Fourteen came from the first pass and are listed immediately below; the second pass added three, described after them.

  • Two need another famous problem solved first. Proving c/0011 would give P ≠ NP; c/0056 is stopped by a theorem in its own source. Disproving either is cheap and not blocked.
  • Five need their statement fixed: c/0016, c/0019, c/0039, c/0040 and c/0003 all rest on something their source never pins down.
  • Seven are already solved. Six confirm the site’s own August sweep; c/0004 has an unreviewed proof here, so what is left is checking.

c/0003 is false as written, and should be fixed first. There is no salt, so the offline stage can store one k-collision and the online stage print it without a single query, breaking the claimed tradeoff outright. Everything the page cites assumes a salt drawn after the advice is fixed.

c/0024 is out of date. A CRYPTO 2024 follow-up reaches N^1.6 in Maurer’s model under a strong assumption. That does not settle the page, whose statement allows none, but the page does not record it.

Two pairs are near-twins that can answer each other’s question. c/0050 and c/0053 differ by one word, and c/0024 and c/0025 differ by which group model. Two further pairs recorded here have since been resolved the same way, by removing the redundant page: c/0004 and a separate secret-seed page shared identical LaTeX stating two different conjectures, and that LaTeX was split on 28 August 2026 before the second page was removed later the same day. A fourth pair, c/0008 and a separate Groth16-optimality page, was resolved on 28 August 2026 by removing the latter: it shared c/0008’s LaTeX byte for byte and stated a consequence of it, so the implication is now recorded in c/0008 itself.

What the second pass added

Three more stops, all of them the same shape as the first pass’s. c/0082 and c/0089 are no go because their own sources say a proof would settle a named open problem elsewhere: c/0082’s Theorem 43 says it would give constant-overhead secure computation for general Boolean circuits, and c/0089’s Theorem 1.3 says it would give super-polynomial lower bounds for general secret sharing, sd-PIR and fully-decomposable randomized encodings, for none of which even a super-linear bound is known. c/0063 is contract repair because its third clause asks for the optimal trade-off between salt length and call count without naming a candidate curve: the first two clauses are a well-posed dichotomy, the third makes finding the statement part of the task. Its sibling c/0064 is the same subject with a fixed dichotomy and scores 23.

Two land in park, and for opposite reasons. c/0101 is capped at P3 = 1 because the only known route runs through the NP-hardness of MCSP, so a new framework is required and the expected best output is a barrier note. c/0099 scores P1 = 0, the lower-bound-against-preprocessing floor, and its statement is a family parameterized by a function class the source never fixes.

The top of the table is finite objects. c/0096 tops the whole table at 27 and c/0076 is second at 26, and both for the same reason: the object asked for is finite, so exhaustive search settles the question outright rather than merely testing it. c/0076 is perfect fully anonymous secret sharing at 3-out-of-5 with a two-element secret, which the source names as the smallest open case; c/0096 has the added feature that the source already has a code it has not checked for the property in question, so the first step is a check rather than a construction.

One statement sits close to the framework’s cryptanalysis exclusion. c/0080 is the unproved soundness step in a published decryption attack on a Classic McEliece-shaped scheme. It is scored rather than excluded because the statement is an asymptotic probabilistic claim with no executable success predicate, which is the test the exclusion actually turns on, but its record says a human should confirm the dual-use position before any campaign is resourced.

The first pass asks you to build something: 27 constructions against 7 lower bounds, with 6 closures. c/0051 scores 12, while c/0052, asking for the attack that would refute it, scores 24. Every lower-bound record names the thing you would build to disprove it, and that is usually the part worth attacking.

How much to trust this

One machine, one pass. The totals, verdicts and bands are computed from the eight numbers and the set passes its validator, so the arithmetic is checkable; the eight numbers themselves are opinions with a written reason attached. Re-checking them in the same sitting moved four by a point each, so a fresh pass would move more. Where evidence is thin, grades round towards harder than it looks.

Provenance

Two passes, both produced by the conjecture-triage skill, both scored by claude-opus-5, and both using the same rubric and the same four calibration anchors. Together they cover all 106 statements under c/.

23 August 2026, 53 rows. All conjectures under c/ at that date. The secret-seed page then numbered c/0005 and the Groth16-optimality page then numbered c/0009 are absent, both having been withdrawn on 28 August 2026 and their content folded into c/0004 and c/0008 respectively. Records: audit, jsonl.

30 August 2026, 53 rows, covering c/0057 through c/0109, which the first pass predates. Records: audit, jsonl.

Each record carries the reason behind every number, the literature search with its retrieval status, the thing you would build to disprove the statement, and a suggested first step. The eight questions are labelled P1 P2 P3, V1 V2 V3, O1 O2.

Two things the second pass did not do, stated so they are not assumed. The rubric’s fifth step asks for every go to be re-scored blind, in a fresh context, and compared; that was not run, so the 24 go verdicts of 30 August have not been checked against an independent scoring. And the scout sweep was not exhaustive per conjecture: where a statement’s own page already carried a dated literature check from the harvest that created it, the record reuses that check and tags it RESTATED rather than re-running it. Seventeen of the 53 got a fresh search in this pass; the other 36 carry a RESTATED claim from their page plus a BLOCKED item naming the rungs tried. Both gaps are recorded per-record rather than papered over.

A dated snapshot, not a live view: attackability is deliberately not yet a field on each conjecture.