How it works
Today this is a SAMPLE bench: no live IBM run has happened yet (see Sample mode below). Once the IBM key is connected, every attempt runs one circuit on a real IBM Heron backend (ibm_torino, ibm_fez, ibm_kingston; enabled now: ibm_torino, ibm_fez) for 4,096 shots, and runs the same post-processing on 4,096 draws from /dev/urandom. The chip only gets the stamp when it beats the coin flip by 2.0× or more.
The circuit
A two-register Shor attack on the discrete log of a toy elliptic-curve key, in the style of the public toy demonstrations. Registers a and b (N qubits each) go into uniform superposition. An oracle adds aG + bQ into a third register. An inverse quantum Fourier transform runs on a and on b, and both are measured.
Each toy curve is chosen so that its base point G has order exactly n = 2N. "Adding the point 2iG" is then "adding 2i to the group index", and the oracle is compiled from the group's addition table into controlled phase additions. That table is computed instantly by a laptop. This is not a scalable attack and it says nothing about real keys. The only question the bench answers is whether the chip's output beats random noise.
Post-processing
A measured bitstring has 2N bits (Qiskit order). The last N bits are u (register a), the first N bits are v (register b). On an ideal machine v = k·u (mod n). The candidate key is v · u-1 mod n when u is odd (so u has an inverse mod 2N); otherwise the shot has no candidate. Hits are the shots whose candidate equals the key k. Shots with no candidate count as misses on both sides.
The exact same function (lib/postprocess.mjs) runs on the server, in your browser (Re-verify) and in the tests; a Python twin (qpu/postprocess.py) ships in rerun.py and is cross-tested against it on 10,000 random bitstrings.
The control
At verdict time the worker reads exactly 4,096 × 2N bits from the kernel's random pool (crypto.randomBytes, the /dev/urandom pool), forms 4,096 bitstrings of the same width, stores them as urandom.json and runs them through the same function.
The scheduler
Every 5 minutes the worker polls pending jobs, fetches finished results, stamps verdicts, updates the ladder and, when a backend is free and the budget covers the next run's measured cost, submits it: a named attack first, then the last vote's winner, then the default policy (retry the lowest rung not held, on the backend that ran it least recently).
Sample mode
Right now the IBM key is not added yet (IBMQ=mock). The bench replays a sample run sheet through the same pipeline and every surface says SAMPLE. Live runs replace them when the key is added.