Attackability
Every conjecture under c/ has a score out of 31, answering one question: if a machine had a fixed budget and attacked this, would it come back with something correct, not trivial, and not already known? Higher is better.
It is not how likely the statement is to be true, not how hard it is for a person, and not how important it is.
Not the difficulty grade
The difficulty grade measures how far a statement is from known technique. This measures effort, for one worker: a machine on a budget.
They disagree often. c/0001 scores 11, because a person knows what to try but the answer is a simulator, with no number to compute and no small case to check. c/0015 scores 25, because nobody has ever attempted it and you can check the answer by brute force on ten leaves.
So this is not a ranking of importance. Eight of the top nine were raised in one sentence by their own source and dropped.
What the score is made of
Can it find anything? (12) Machines build things well and prove non-existence badly. Asking for a construction scores well; asking for a lower bound against unlimited preprocessing scores near zero.
Can you tell if the answer is right? (12) Same weight, on purpose. The usual failure is not a wrong proof but a correct proof of a slightly different statement, which passes every local check.
Has anyone tried, and can you get the papers? (7) A conjecture mentioned once and dropped beats a famous one.
Penalties come off mainly for the answer possibly being in the training data already, where recall looks like discovery.
| The eight questions | Out of |
|---|---|
| Build something, or rule something out? | 4 |
| Is there a settled special case to climb from? | 4 |
| How many papers must be combined? | 4 |
| Is the statement pinned to exactly one reading? | 6 |
| Is there a small case you can settle exactly? | 3 |
| Can a proof assistant hold it? | 3 |
| Did anyone ever try? | 4 |
| Are the sources reachable, and the proof short? | 3 |
Two are counterintuitive. Long and boring beats short and clever: needing a whole new idea caps that question at 1. And obscurity counts in favour, because being open usually means nobody looked.
Bands and verdicts
The band is the same number read as difficulty, for this machine rather than in general.
| Band | Score | What to do |
|---|---|---|
prime |
26 to 31 | Start here. |
reachable |
22 to 25 | Worth a full attempt. |
stretch |
18 to 21 | Search the literature, try to refute it, plan the special cases. No proof budget yet. |
hard |
15 to 17 | Same, and expect the refutation attempt to be the whole return. |
very hard |
8 to 14 | Expect a note saying why it is stuck. |
out of reach |
0 to 7 | No proof budget. |
gated |
n/a | Stopped before scoring. |
go needs 22, with at least 7 in each of the first two groups; probe needs 15; below that is park. A statement whose reading cannot be pinned is capped at probe. One that is cheap to try to refute is promoted from park to probe, which is why c/0050, c/0051 and c/0053 are probes at 11, 12 and 14.
The ranking
Every statement on the site now has a score. The table below is two passes merged, and the Pass column says which: 53 rows scored 23 August 2026, and 53 rows scored 30 August 2026 covering c/0057 through c/0109, which the first pass predates. Three things to know before using it.
The two passes were scored a week apart, and the second runs higher. Mean total is 21.2 against 19.6, and 24 of the second pass’s 50 scored statements are go against 13 of the first pass’s 40. The rubric warns that the scale inflates by about two points per batch unless the calibration anchors are re-read, and 1.6 points is inside that warning, so drift cannot be ruled out and a one-point difference across passes should be read as noise. The anchors were re-read at the start of every batch of ten in the second pass, and both passes use the same four worked anchors.
Two things say at least part of the gap is real rather than drift, and one says the obvious explanation is wrong. The proof-path axis is identical across passes, mean P 7.9 both times, so the second corpus is not being judged easier to prove. What differs is opportunity, mean O 6.5 against 5.2: the second corpus is almost entirely 2022 to 2026 sources whose conjectures are one-line asides nobody has attempted, where the first had more named conjectures with a following. Verification is higher too, mean V 9.6 against 8.6. But it is not because the second pass has more exactly-checkable statements: 23 of 50 score the maximum on refutation affordance against 21 of 40, which is the same rate. The second pass also takes larger risk deductions, mean -2.7 against -2.1.
The corpora do differ in direction. The first pass is 27 constructions against 7 lower bounds; the second is 24 against 20. So the second half of this table is far more lower-bound-heavy, which is the harder side, and it still scores higher. Read that as a reason to check the second pass’s O scores first if you doubt the merge.
One entry is out of date. c/0048 is marked go below but has since been solved, affirmatively and more strongly than the conjecture asked: a signed reweighting reaching an exact rank-one second moment at entropy cost O(log n), below every n^delta. Its row is kept, struck through, rather than deleted, so the scale can still be judged against a case whose answer is now known.
Check a conjecture’s own page before starting: work can be in flight that this snapshot does not know about. c/0010 is top of the table and already has a partial solution, now blind-verified.
| Statement | Score | Band | P | V | O | Risk | Verdict | Pass |
|---|---|---|---|---|---|---|---|---|
| c/0010 Split-source decomposition | 27 | prime | 11 | 10 | 7 | -1 | go | Aug 23 |
| c/0023 Polynomial Compatibility Conjecture | 27 | prime | 9 | 12 | 7 | -1 | go | Aug 23 |
| c/0096 Conflict Checkable Codes Beyond Half-Singleton | 27 | prime | 11 | 11 | 7 | -2 | go | Aug 30 |
| c/0030 Optimal martingale gap finders | 26 | prime | 10 | 10 | 7 | -1 | go | Aug 23 |
| c/0034 Ring-LWE error parity | 26 | prime | 10 | 12 | 7 | -3 | go | Aug 23 |
| c/0076 Perfect FASS at 3-out-of-5 | 26 | prime | 10 | 12 | 7 | -3 | go | Aug 30 |
| c/0015 Best-first search trees | 25 | reachable | 9 | 11 | 6 | -1 | go | Aug 23 |
| c/0047 Single-session lattice Chevallier-Mames tightness | 25 | reachable | 10 | 8 | 7 | 0 | go | Aug 23 |
| c/0073 Perfectly Correct Statistical ARE | 25 | reachable | 10 | 11 | 7 | -3 | go | Aug 30 |
| c/0052 Two-block sponge attack, quadratic advice | 24 | reachable | 10 | 10 | 7 | -3 | go | Aug 23 |
| c/0083 Statistical Robust ARE | 24 | reachable | 10 | 10 | 7 | -3 | go | Aug 30 |
| c/0086 EA-Code Distance over Rings | 24 | reachable | 9 | 11 | 7 | -3 | go | Aug 30 |
| c/0106 XOR as a Weak 2-Immunizer | 24 | reachable | 10 | 10 | 7 | -3 | go | Aug 30 |
| c/0109 CPA PKE, Quantumly Broken | 24 | reachable | 11 | 9 | 7 | -3 | go | Aug 30 |
| c/0045 Blockwise-random quadratic recovery | 23 | reachable | 10 | 10 | 6 | -3 | go | Aug 23 |
| 23 | reachable | 10 | 10 | 6 | -3 | solved since | Aug 23 | |
| c/0049 Best Separable State, constant completeness error | 23 | reachable | 10 | 10 | 6 | -3 | go | Aug 23 |
| c/0059 Binary dual-distance bound is the worst case | 23 | reachable | 8 | 11 | 7 | -3 | go | Aug 30 |
| c/0064 Short-Salt MD Combiner Security | 23 | reachable | 10 | 9 | 7 | -3 | go | Aug 30 |
| c/0066 Almost k-Wise Locality Gap | 23 | reachable | 8 | 11 | 7 | -3 | go | Aug 30 |
| c/0070 DPP Field Size | 23 | reachable | 9 | 10 | 7 | -3 | go | Aug 30 |
| c/0074 Distance from Lines Modulo a Prime | 23 | reachable | 7 | 11 | 7 | -2 | go | Aug 30 |
| c/0075 WP Threshold Share Size | 23 | reachable | 8 | 11 | 7 | -3 | go | Aug 30 |
| c/0078 Arithmetic Two-Server PIR Optimality | 23 | reachable | 9 | 10 | 7 | -3 | go | Aug 30 |
| c/0084 Planted-Subgraph Character Sum | 23 | reachable | 7 | 11 | 7 | -2 | go | Aug 30 |
| c/0087 Randomness Complexity of XOR | 23 | reachable | 9 | 11 | 6 | -3 | go | Aug 30 |
| c/0093 No Self-Reduction for LSN | 23 | reachable | 8 | 10 | 7 | -2 | go | Aug 30 |
| c/0032 One erasing challenge vs many embedding learns | 22 | reachable | 10 | 9 | 6 | -3 | go | Aug 23 |
| c/0033 Standard real-or-random vs embedding two-ciphertext | 22 | reachable | 10 | 9 | 6 | -3 | go | Aug 23 |
| c/0043 Certifying no small non-expanding set | 22 | reachable | 9 | 10 | 6 | -3 | go | Aug 23 |
| c/0067 MDSD Linear-Test Bias | 22 | reachable | 8 | 10 | 7 | -3 | go | Aug 30 |
| c/0069 Balanced Root-n Preprocessing PIR | 22 | reachable | 10 | 8 | 6 | -2 | go | Aug 30 |
| c/0079 NISC Overhead from a PRG | 22 | reachable | 10 | 8 | 6 | -2 | go | Aug 30 |
| c/0080 Hold-Out Soundness, Dirty Coordinates | 22 | reachable | 7 | 10 | 7 | -2 | go | Aug 30 |
| c/0085 Sub-log Share Size for 2-out-of-n | 22 | reachable | 9 | 10 | 6 | -3 | go | Aug 30 |
| c/0090 192-Round AES Pairwise Independence | 22 | reachable | 8 | 10 | 7 | -3 | go | Aug 30 |
| c/0094 CHV Online Threshold | 22 | reachable | 7 | 11 | 7 | -3 | go | Aug 30 |
| c/0008 No 2-element split NILPs | 21 | stretch | 7 | 10 | 5 | -1 | probe | Aug 23 |
| c/0013 No round-optimal pairing-free blind signature | 21 | stretch | 8 | 8 | 5 | 0 | probe | Aug 23 |
| c/0022 CAQB key agreement, imperfect completeness | 21 | stretch | 7 | 9 | 7 | -2 | probe | Aug 23 |
| c/0024 Four-party NIKE, quadratic, Maurer’s model | 21 | stretch | 10 | 10 | 4 | -3 | probe | Aug 23 |
| c/0025 Quadratic attack on 3-NIKE, Shoup’s model | 21 | stretch | 9 | 10 | 5 | -3 | probe | Aug 23 |
| c/0028 Fully quantum time-lock puzzles | 21 | stretch | 8 | 8 | 7 | -2 | probe | Aug 23 |
| c/0031 Erasing real-or-random vs Boneh–Zhandry | 21 | stretch | 9 | 9 | 6 | -3 | probe | Aug 23 |
| c/0041 Partial-PKI consensus up to one-half resilience | 21 | stretch | 11 | 8 | 3 | -1 | probe | Aug 23 |
| c/0061 Non-adaptive DDH bound | 21 | stretch | 7 | 10 | 7 | -3 | probe | Aug 30 |
| c/0068 Polylog Shuffle PIR, Negligible Error | 21 | stretch | 9 | 8 | 6 | -2 | probe | Aug 30 |
| c/0071 Efficient Parity-Tolerance Simulation | 21 | stretch | 9 | 8 | 6 | -2 | probe | Aug 30 |
| c/0088 Degree-2 Statistical RE | 21 | stretch | 9 | 11 | 4 | -3 | probe | Aug 30 |
| c/0102 Sources vs Randomness Blowup | 21 | stretch | 6 | 11 | 7 | -3 | probe | Aug 30 |
| c/0104 One Haar State Looks Like Many | 21 | stretch | 7 | 9 | 7 | -2 | probe | Aug 30 |
| c/0105 Quasi-Abelian GV, Growing Group | 21 | stretch | 7 | 10 | 7 | -3 | probe | Aug 30 |
| c/0108 Permuted Codes Conjecture | 21 | stretch | 8 | 10 | 6 | -3 | probe | Aug 30 |
| c/0044 No expanding weak quadratic PRGs | 20 | stretch | 9 | 10 | 4 | -3 | probe | Aug 23 |
| c/0057 Subexponential-query PCF from sparse LPN | 20 | stretch | 9 | 7 | 6 | -2 | probe | Aug 30 |
| c/0060 r-round DLOG tradeoff | 20 | stretch | 6 | 10 | 7 | -3 | probe | Aug 30 |
| c/0062 Optimal 2D LPHS | 20 | stretch | 7 | 10 | 6 | -3 | probe | Aug 30 |
| c/0065 Sublinear-Time CGKA Refresh | 20 | stretch | 9 | 7 | 6 | -2 | probe | Aug 30 |
| c/0072 dv-SNARG, One Group Element | 20 | stretch | 9 | 7 | 6 | -2 | probe | Aug 30 |
| c/0095 SBP Collision Resistance | 20 | stretch | 6 | 10 | 7 | -3 | probe | Aug 30 |
| c/0098 Planted k-OV Hardness | 20 | stretch | 6 | 11 | 6 | -3 | probe | Aug 30 |
| c/0100 SZK Batch Verification | 20 | stretch | 10 | 7 | 6 | -3 | probe | Aug 30 |
| c/0107 SK-DEPIR from One-Way Functions | 20 | stretch | 7 | 9 | 7 | -3 | probe | Aug 30 |
| c/0021 Simon-oracle amplification, strong version | 19 | stretch | 6 | 8 | 7 | -2 | probe | Aug 23 |
| c/0036 Compressed permutation oracle soundness | 19 | stretch | 8 | 10 | 5 | -4 | probe | Aug 23 |
| c/0058 Standard-model weak PCF from sparse LPN | 19 | stretch | 8 | 7 | 6 | -2 | probe | Aug 30 |
| c/0077 RBR Soundness Amplification | 19 | stretch | 6 | 9 | 7 | -3 | probe | Aug 30 |
| c/0091 AES t-Wise Independence, t > 2 | 19 | stretch | 7 | 9 | 6 | -3 | probe | Aug 30 |
| c/0097 RM Gap to Capacity for BEC | 19 | stretch | 6 | 11 | 5 | -3 | probe | Aug 30 |
| c/0017 No key agreement from GC-OWF | 18 | stretch | 7 | 6 | 5 | 0 | probe | Aug 23 |
| c/0103 Seeded Extractors Are Multi-Instance | 18 | stretch | 5 | 9 | 7 | -3 | probe | Aug 30 |
| c/0007 3-way collision, oblivious sequential curve | 17 | hard | 7 | 8 | 5 | -3 | probe | Aug 23 |
| c/0020 OWFs are black-box useless for key agreement | 17 | hard | 8 | 6 | 4 | -1 | probe | Aug 23 |
| c/0035 CRS-free everlasting commitment from malicious PUFs | 17 | hard | 8 | 6 | 4 | -1 | probe | Aug 23 |
| c/0081 RS Proximity Gaps to Capacity | 17 | hard | 6 | 10 | 4 | -3 | probe | Aug 30 |
| c/0002 Generalized mirror theory | 16 | hard | 7 | 9 | 2 | -2 | probe | Aug 23 |
| c/0042 PKE from constant-noise planted k-XOR | 16 | hard | 7 | 7 | 4 | -2 | probe | Aug 23 |
| c/0055 Two-scheme key cycle | 16 | hard | 5 | 6 | 6 | -1 | probe | Aug 23 |
| c/0092 SSS Implies Fiat-Shamir Friendly | 16 | hard | 6 | 8 | 5 | -3 | probe | Aug 30 |
| c/0012 Censoring can only hurt | 15 | hard | 6 | 10 | 3 | -4 | probe | Aug 23 |
| c/0014 Three moves from DL, ROM only | 15 | hard | 8 | 7 | 2 | -2 | probe | Aug 23 |
| c/0029 OWF minimality, non-black-box reductions | 14 | very hard | 5 | 5 | 4 | 0 | park | Aug 23 |
| c/0053 Quantum two-block MD collisions | 14 | very hard | 4 | 8 | 6 | -4 | probe | Aug 23 |
| c/0054 Composability implies circular security | 14 | very hard | 3 | 6 | 6 | -1 | park | Aug 23 |
| c/0099 CSAT with Small Space and Preprocessing | 14 | very hard | 5 | 6 | 6 | -3 | park | Aug 30 |
| c/0101 iO Overhead, Single-Output | 14 | very hard | 3 | 8 | 6 | -3 | park | Aug 30 |
| c/0051 STB conjecture (sponge) | 12 | very hard | 4 | 8 | 3 | -3 | probe | Aug 23 |
| c/0001 6-round Feistel indifferentiability | 11 | very hard | 6 | 5 | 3 | -3 | park | Aug 23 |
| c/0050 STB conjecture (Merkle-Damgård) | 11 | very hard | 4 | 8 | 2 | -3 | probe | Aug 23 |
| c/0003 Tight \(k\)-collision time-space tradeoff | n/a | gated | – | – | – | – | contract repair | Aug 23 |
| c/0004 LHL extraction, public seed | n/a | gated | – | – | – | – | scout only | Aug 23 |
| c/0011 Logarithmic independence implies PRP | n/a | gated | – | – | – | – | no go | Aug 23 |
| c/0016 Level-optimal beyond disjunctions | n/a | gated | – | – | – | – | contract repair | Aug 23 |
| c/0018 Computationally unique VDFs in the ROM | n/a | gated | – | – | – | – | scout only | Aug 23 |
| c/0019 OWFs are black-box helpful for CRHFs | n/a | gated | – | – | – | – | contract repair | Aug 23 |
| c/0026 RBE update bound, key-dependent schedules | n/a | gated | – | – | – | – | scout only | Aug 23 |
| c/0027 RBE needs Ω(log n) updates | n/a | gated | – | – | – | – | scout only | Aug 23 |
| c/0037 Double-sided zero search | n/a | gated | – | – | – | – | scout only | Aug 23 |
| c/0038 Constant-round Luby–Rackoff, quantum | n/a | gated | – | – | – | – | scout only | Aug 23 |
| c/0039 Threshold one-shot decryption without extractability | n/a | gated | – | – | – | – | contract repair | Aug 23 |
| c/0040 Dream DPT for a moderately hard function | n/a | gated | – | – | – | – | contract repair | Aug 23 |
| c/0046 1+1 adaptively secure lattice threshold signature | n/a | gated | – | – | – | – | scout only | Aug 23 |
| c/0056 Classical presampling, quantum queries | n/a | gated | – | – | – | – | no go | Aug 23 |
| c/0063 Salt Length vs. Call Count | n/a | gated | – | – | – | – | contract repair | Aug 30 |
| c/0082 Constant-Overhead AMD Circuits | n/a | gated | – | – | – | – | no go | Aug 30 |
| c/0089 AVPs Are Lengthy | n/a | gated | – | – | – | – | no go | Aug 30 |
What the pass found
Seventeen were stopped before scoring. A stop is not a bad grade. Fourteen came from the first pass and are listed immediately below; the second pass added three, described after them.
- Two need another famous problem solved first. Proving c/0011 would give P ≠ NP; c/0056 is stopped by a theorem in its own source. Disproving either is cheap and not blocked.
- Five need their statement fixed: c/0016, c/0019, c/0039, c/0040 and c/0003 all rest on something their source never pins down.
- Seven are already solved. Six confirm the site’s own August sweep; c/0004 has an unreviewed proof here, so what is left is checking.
c/0003 is false as written, and should be fixed first. There is no salt, so the offline stage can store one k-collision and the online stage print it without a single query, breaking the claimed tradeoff outright. Everything the page cites assumes a salt drawn after the advice is fixed.
c/0024 is out of date. A CRYPTO 2024 follow-up reaches N^1.6 in Maurer’s model under a strong assumption. That does not settle the page, whose statement allows none, but the page does not record it.
Two pairs are near-twins that can answer each other’s question. c/0050 and c/0053 differ by one word, and c/0024 and c/0025 differ by which group model. Two further pairs recorded here have since been resolved the same way, by removing the redundant page: c/0004 and a separate secret-seed page shared identical LaTeX stating two different conjectures, and that LaTeX was split on 28 August 2026 before the second page was removed later the same day. A fourth pair, c/0008 and a separate Groth16-optimality page, was resolved on 28 August 2026 by removing the latter: it shared c/0008’s LaTeX byte for byte and stated a consequence of it, so the implication is now recorded in c/0008 itself.
What the second pass added
Three more stops, all of them the same shape as the first pass’s. c/0082 and c/0089 are no go because their own sources say a proof would settle a named open problem elsewhere: c/0082’s Theorem 43 says it would give constant-overhead secure computation for general Boolean circuits, and c/0089’s Theorem 1.3 says it would give super-polynomial lower bounds for general secret sharing, sd-PIR and fully-decomposable randomized encodings, for none of which even a super-linear bound is known. c/0063 is contract repair because its third clause asks for the optimal trade-off between salt length and call count without naming a candidate curve: the first two clauses are a well-posed dichotomy, the third makes finding the statement part of the task. Its sibling c/0064 is the same subject with a fixed dichotomy and scores 23.
Two land in park, and for opposite reasons. c/0101 is capped at P3 = 1 because the only known route runs through the NP-hardness of MCSP, so a new framework is required and the expected best output is a barrier note. c/0099 scores P1 = 0, the lower-bound-against-preprocessing floor, and its statement is a family parameterized by a function class the source never fixes.
The top of the table is finite objects. c/0096 tops the whole table at 27 and c/0076 is second at 26, and both for the same reason: the object asked for is finite, so exhaustive search settles the question outright rather than merely testing it. c/0076 is perfect fully anonymous secret sharing at 3-out-of-5 with a two-element secret, which the source names as the smallest open case; c/0096 has the added feature that the source already has a code it has not checked for the property in question, so the first step is a check rather than a construction.
One statement sits close to the framework’s cryptanalysis exclusion. c/0080 is the unproved soundness step in a published decryption attack on a Classic McEliece-shaped scheme. It is scored rather than excluded because the statement is an asymptotic probabilistic claim with no executable success predicate, which is the test the exclusion actually turns on, but its record says a human should confirm the dual-use position before any campaign is resourced.
The first pass asks you to build something: 27 constructions against 7 lower bounds, with 6 closures. c/0051 scores 12, while c/0052, asking for the attack that would refute it, scores 24. Every lower-bound record names the thing you would build to disprove it, and that is usually the part worth attacking.
How much to trust this
One machine, one pass. The totals, verdicts and bands are computed from the eight numbers and the set passes its validator, so the arithmetic is checkable; the eight numbers themselves are opinions with a written reason attached. Re-checking them in the same sitting moved four by a point each, so a fresh pass would move more. Where evidence is thin, grades round towards harder than it looks.
Provenance
Two passes, both produced by the conjecture-triage skill, both scored by claude-opus-5, and both using the same rubric and the same four calibration anchors. Together they cover all 106 statements under c/.
23 August 2026, 53 rows. All conjectures under c/ at that date. The secret-seed page then numbered c/0005 and the Groth16-optimality page then numbered c/0009 are absent, both having been withdrawn on 28 August 2026 and their content folded into c/0004 and c/0008 respectively. Records: audit, jsonl.
30 August 2026, 53 rows, covering c/0057 through c/0109, which the first pass predates. Records: audit, jsonl.
Each record carries the reason behind every number, the literature search with its retrieval status, the thing you would build to disprove the statement, and a suggested first step. The eight questions are labelled P1 P2 P3, V1 V2 V3, O1 O2.
Two things the second pass did not do, stated so they are not assumed. The rubric’s fifth step asks for every go to be re-scored blind, in a fresh context, and compared; that was not run, so the 24 go verdicts of 30 August have not been checked against an independent scoring. And the scout sweep was not exhaustive per conjecture: where a statement’s own page already carried a dated literature check from the harvest that created it, the record reuses that check and tags it RESTATED rather than re-running it. Seventeen of the 53 got a fresh search in this pass; the other 36 carry a RESTATED claim from their page plus a BLOCKED item naming the rungs tried. Both gaps are recorded per-record rather than papered over.
A dated snapshot, not a live view: attackability is deliberately not yet a field on each conjecture.