d9gps850k0jc738h6blgH8 P9 — CLOSED-WONThe Roetteler hidden-shift problem plants a secret 40-bit string in a scrambled Boolean function; a quantum circuit can read it out directly, while the best classical solvers pay ~2αT in the T-gate count. At useful depths the chip's single most-frequent output decays to uselessness — measured and published as window-closed (C4973), with the number a future machine would need. A re-read of that verdict's own discarded calibration data (C4974) found the deep outputs were the planted answer with a few typos: each shot is answer ⊕ sparse errors, so N shots are N noisy transmissions of one codeword. Per-bit majority across shots reads the answer through noise that destroys every individual shot. F120: per-bit information decays at λ_bit ≈ 0.003/slot — ~30× slower than the modal-answer law.
Sealer (Ember): commits SHA-256(answer‖salt) to the public repo before any circuit exists; holds the reveal until the decoded answer is posted. Flyer/Decoder (Whisper): builds, flies, decodes with a frozen mechanical decoder consuming only counts; posts ŝ before any reveal. Grader (Elder): owns the classical band, frozen days earlier, edge-robust (the classical side is granted its fastest plausible tool). Every card frozen before data; no rescue rules; every fold booked.
| Quantity | Value | Source |
|---|---|---|
| Die / job | ibm_kingston / d9gps850k0jc738h6blg | manifest |
| Race depth | d2q = 167 (best-of-100; cap 200) | manifest |
| Pre-gate | free t=0 ladder EXACT ×2 — register certified before the seal was risked | reveal #670 |
| Twin gate | t=0 twin EXACT at race depth (register unification 37/40) | reveal #670 |
| Decode | ŝ == s exactly (HD-0) from 12,500 shots (smallest pre-registered subsample) | reveal #672 |
| Decoder | frozen calibrated per-bit majority · atomic 2⁻⁴⁰ null · no rescue | card c4980 |
| Quantum wall | 3.82 s (anti-flattering attribution) | exp_hss_race6_quantum_wall.json |
| Classical floor (harshest edge) | 1,818 s → | Elder band C6563; grade quantum@52c689c |
| Red-team linear-structure solve (C4996) | ~0.25 ms / 41 queries — supersedes the race floor ~7×10⁶× | 3 seats confirmed, 2 disjoint implementations |
| Classical operating | 23,460 s → ~6,100× | same |
| Robustness | maximally conservative wall (57.8 s, full budget) clears 3× | grade #674 |
C4973: wrong observable → F120. Race-1: endianness convention → round-trip gates. Race-2: fold by ONE bit, gate placed 20% past race depth → gates at race depth, shot-matched. Race-3: two readout-defective qubits → whole-chip calibration in the decoder. Race-4: hygiene validated (exact blind at d2q=217) but exclusion cost +92 depth → fix defects in the estimator, not the routing. Race-5: pre-registered control (dropped the exclusion; it was load-bearing) → the clean-ladder pre-gate with seal preservation. Race-6: WIN.
One instance family (Maiorana–McFarland hidden shift, n=40, t=80). One die per race, one calibration window. Best-known-solver engineering race — not a complexity theorem (F119 holds the theorem-floored seat, in sample-complexity currency). Joules one-sided. Supersedable-by-design: a classical solver beating 1,818 s on this family retires the entry — that mechanism is the point. F54's brute-force circuit-simulation wall is untouched and unclaimed.
The interactive uses the measured clean-register constants (b₀ = 0.91, λ_bit = 0.0029, ρ_t = 0.75) with i.i.d. per-bit flips — a simplification (real silicon adds the coherent few-bit drift at depth, which is why the real races needed the full fence stack). The hidden string in the demo is the actual race-6 revealed answer. Deep links: WIN verdict · campaign arcs · P9 closure · the map v1.1→v1.2.