The Decoder Race
— a sealed answer, read through noise
A deep quantum circuit's single loudest output dies exponentially with depth — the campaign measured that wall and published window-closed. Then a re-read of the fold's own discarded data showed every shot still whispers the hidden 40-bit answer with a few typos. Average the whispers letter-by-letter and you can read what no single shot can say. Six sealed races later, that decoder read a cryptographically-committed answer exactly, in 3.82 s, against a frozen classical floor of 1,818 s — 476× at the harshest edge, graded by three independent AI seats. Then the win's own printed expiry clause fired — by our own hand, before any submission: the "classical floor" priced simulating the circuit, and a solver attacking the planted problem's algebra reads the same sealed answer in ~0.25 ms. The decoder physics (F120) stands; the runtime advantage (F121) is retired. The full story — including why that ending makes the protocol more credible, not less — is below.
Scope: one instance family · one die per race · best-known-solver engineering race, not a complexity theorem · supersedable-by-design (a faster classical solver retires the number) · F54's brute-force wall untouched▶ FIRE SHOTS — the shout dies, the whisper survives
The hidden answer below is the actual sealed string from the winning race (revealed post-grade). Every shot of the circuit returns that answer with typos. The modal decoder needs one shot with zero typos; the shot-axis decoder lets every shot vote, bit by bit, and reads the majority. Fire shots and watch the pipeline run: a noisy shot arrives → its votes pile onto 40 running tallies → each tally climbs out of the coin-flip zone and locks. Noise model = the measured constants: per-bit bias 0.91·e−0.0029·d, ×0.75 magic tax for t=80 circuits.
⏱ THE RACE — measured, both arms
📜 SIX RACES — every fence forged from the previous miss
⊘ THE SUPERSESSION — the fence fires, and it is a finding
A Maiorana–McFarland bent function has a defining property: fix the first register and the function is linear in the second — f(x,y) = x·y ⊕ g(x). Shift it by the sealed secret s = (sx, sy) and that linearity survives: the slope of fs(0,·) in y is sx (k+1 queries), and with the circuit public — which it must be, for the simulator arm of any race to exist — the residual then yields sy (k more). Forty-one queries, a quarter of a millisecond, no quantum computer, no 2⁴⁰ search. The 1,818 s "floor" priced the cost of simulating our circuit; the correct floor for an advantage claim is the best classical method for the problem — and for this family the two differ by seven orders of magnitude.
What survives is real: the shot-axis code (F120) — hardware genuinely read a sealed 40-bit answer blind through noise at depths where the loudest single output is long dead. That is an instrument result. What does not survive is the word advantage. The protocol's final integrity test was whether we would fire the attack our own fence hypothesized, at our own trophy, before showing it to the world — and book the answer either way. We did: the fence fired, the tile came down, and the sealed-court method walks away stronger than the number it retired.