# NOTES_2026-08-14 — The Permanent Exposure (project memory)

The standing reference for this project. Read before touching the paper again.

## Where it stands

| Deliverable | State |
|---|---|
| `research_notes.md` | Q/stance/scope + sourced facts, dated 2026-08-14 |
| `data.py` | every number with `source` + `status` (V/V2/U) |
| `exposure_model.py` → `exposure_result.json` | draft-1 model — **SUPERSEDED** (hazard construction withdrawn) |
| `exposure_model_v2.py` → `exposure_result_v2.json` | draft-2 model (published-anchor hazard, decomposed residual, identity offense/defense) |
| `generate_figures.py` + `generate_figures_v2.py` | figures (v2 regenerates fig3/4/8) |
| `build_paper_v1.py` → `the_permanent_exposure_v1_{core,full}.pdf` | draft 1 (15/17pp) — retained unedited |
| `build_paper_v2.py` → `the_permanent_exposure_v2_{core,full}.pdf` | **current draft** (17/20pp) |
| `ATTACK_NOTES.md`, `DEFENSE_NOTES.md`, `VERDICT.md` | Phase-4 trial, complete for draft 1 |

Rebuild from scratch:
```
python3 generate_figures.py
python3 exposure_model.py            # writes exposure_result.json (v1)
python3 build_paper_v1.py            # v1 PDFs
python3 exposure_model_v2.py         # writes exposure_result_v2.json
python3 generate_figures_v2.py       # v2 figures (needs exposure_result_v2.json)
python3 build_paper_v2.py            # v2 PDFs (current)
```

## The thesis, stated precisely
On a public ledger the secret a quantum attacker needs — the public key — is
already published, permanently, the moment a coin is spent. "Harvest now, decrypt
later" is not a future capture problem for blockchains; the harvest is complete.
~a quarter to a third of BTC ($256B–$446B at $64,085) sits on exposed keys today,
incl. ~1.7M lost/unmovable coins ($109B) of which ~1.1M are Satoshi's ($70B).
Q-day is ~28–49% within 10y (GRI-2025). Migration alone can't reach zero because
the lost-coin floor (~8% of supply) is fixed. AI independently collapses the cost
of attacking the code around the cryptography (patchageddon).

## What is established, and how well
- **Permanent exposure mechanism** — solid, textbook, pre-stated by Aggarwal 2017
  and the Fed 2025 paper. NOT novel; the contribution is framing/salience.
- **Exposed-supply band (25–35%)** — solid as a band; the four estimates count
  different things (footnoted in Appendix A). USD priced consistently at $64,085.
- **Q-day timeline** — expert opinion only (GRI, n=26), about RSA-2048 as a proxy;
  resource estimates for secp256k1 disagree 25–600× (Webber vs secondary). Framed
  as trend-not-date.
- **Migration residual** — a toy model; robust claim is the *shape* (fixed floor +
  modest increment = double-digit residual), not any single %.
- **Patchageddon** — AI capability is demonstrated (Anthropic FRT 51%, A1 26/36);
  the population multiplier is the identity 10^α−1, shown honestly with sensitivity.
- **DPRK / HNDL adversary** — solid, well-sourced.
- **XCOPY / art-change question** — answered specifically: ownership stealable
  irreversibly; hash-locked (SuperRare/IPFS) art cannot be repainted by a key theft.

## What it will be attacked on, and the answers
See ATTACK_NOTES / DEFENSE_NOTES / VERDICT in full. Draft-1 verdict: 3/10 formal
model. Draft 2 rebuilt the model per the verdict's orders; all 9 orders applied
and self-checked. Remaining soft spots for a future attack:
- The near-term hazard is still a *linear* interpolation 0→10y (implies ~4%/yr);
  defensible and disclosed, but a future draft could use a convex early ramp.
- The S-curve scenario parameters remain invented (labelled as such).
- BlackRock IBIT quantum paragraph is still a paraphrase (status U) — pull verbatim
  from SEC EDGAR before putting it in quotation marks.

## Error log (corrections that must not silently revert)
1. **BTC price**: secondary quantum coverage priced at ~$100k+. TRUE price on
   2026-08-12 was **$64,085** (Fortune). All USD-at-risk figures re-derived from it.
   Do not reintroduce $100k conversions. (Glassnode's $469B assumed ~$78k.)
2. **Q-day hazard**: draft 1 SHIFTED the 2024 curve 4.9y earlier → implied a
   fabricated ~7.4% chance within 1 year. WITHDRAWN. v2 interpolates published
   GRI-2025 anchors; near-term ≈4%/1y, 19%/5y. Never re-shift a survey curve.
3. **34% vs 19%**: draft 1 prose quoted the GRI-2024 *optimistic* 10y (34%) while
   the model computed from the *central* (19%). Compare like with like only.
4. **Offense/defense "11.6×"**: it is the identity 10^α−1 with α=1.1 asserted and
   xmin irrelevant. Never present it as a measured finding; report the α-sensitivity.
5. **Art collapse**: draft 1 said "$2.9B→$23.8M, 93%" — that welds an annual to a
   quarterly figure and the true drop is 99.2%. Correct form: $2.9B (2021) → $197M
   (2024) ≈ 93% annual; Q1-2025 $23.8M labelled as a quarter.
6. **A1 date**: arXiv:2507.05558 is **July 2025**, not 2026.
7. **Deloitte reconciliation**: 4.0M headline vs 2.0+2.5=4.5M breakdown; 25% is vs
   its era's supply, not today's 19.9M. Footnoted; don't recompute its % vs 19.9M.
8. **Satoshi 1.1M ≠ lost 1.7M**: distinguish the (disputed) Satoshi block from the
   total unmovable p2pk core. Don't use interchangeably.
9. **HNDL analogy**: strictly there is no ciphertext/interception; state the
   disanalogy explicitly (it makes the blockchain case worse, not "is HNDL").

## Ship posture
Position / working paper, AI disclosed (Claude Fable 5), human owns claims, AI-on-
AI-policy conflict flagged. Venue: personal site / archive with a DOI. Keep v1 and
the trial files on the record — the retraction of draft 1's model is part of the
credential.

---

## Round 2 (drafts 3 & 4) — Ethereum & NFT deepening, 2026-08-14

**Draft 3** added: a full Ethereum treatment (account model; every signed action
exposes the key; ~55-65% of ETH vs ~30% of BTC; one key = whole vault), a
vault-at-risk distribution (counts by value tier), a deeper fine-art section
(wealth created, auction/museum validation, provenance=value, open-order/bid
range), and the near-term clock (Google/EF/Stanford 2026 <500k-qubit ECC
estimate; 2029-2030 window; 2028 framed as the early edge, no source names it).
New files: exposure_model_v3.py -> exposure_result_v3.json, generate_figures_v3.py
(figE1-E5), build_paper_v3.py.

**Draft 3 trial (ATTACK/DEFENSE/VERDICT_v3.md)** scored the NEW material harshly
— vault model 2/10 — and ordered a rebuild. **Draft 4** applied every order:
exposure_model_v4.py -> exposure_result_v4.json, generate_figures_v4.py (redoes
figE1/E2/E4), build_paper_v4.py. **Draft 4 is the current draft** (core 21pp /
full 25pp).

Rebuild round 2:
```
python3 exposure_model_v3.py && python3 generate_figures_v3.py && python3 build_paper_v3.py
python3 exposure_model_v4.py && python3 generate_figures_v4.py && python3 build_paper_v4.py
```
(generate_figures_v4 must run after generate_figures_v3, since it overwrites
figE1/E2/E4 in place; figE3/E5 come from v3.)

### Error log — round 2 (corrections that must not revert)
10. **CryptoPunks floor contradiction**: data.py had two floors (53.98 ETH "$200k+"
    Jul-2025 vs 31.7 ETH "$60k" 2026). At the $1,910 basis the current floor is
    ~$60.5k (31.7 ETH); the "$200k+" was a Jul-2025 ETH-price artifact. Reconciled
    and dated; the vault model now runs BOTH floors and reports a range. Never pick
    one floor silently again.
11. **Vault model was a two-point Pareto fit** (zero DoF) headlined with false
    precision (104/734/1698/3928). v4: floor-conditional RANGE, rounded to one
    figure (~100, ~700-1,000, etc.), labelled a bound not a count, anchor labelled
    a proxy that undercounts. Never headline three-sig-fig vault counts.
12. **Off-chain-signature overreach**: EIP-712/permit/SIWE signatures reveal the
    pubkey to the COUNTERPARTY, not the permanent public ledger. Narrowed; the
    "every active collector exposed" claim now rests on on-chain actions.
13. **Buried 0.1% dormant figure**: Ethereum's permanently-lost core is ~0.1% (EF)
    vs Bitcoin's ~8.5%. Now surfaced -> framing is "more exposed, more defensible,"
    not "simply worse." Lead exposed share with Quantum Horizon 55-60%; Deloitte
    >65% is earlier (~2021) corroboration, not "current and rising."
14. **"Irreversible" vs the recovery fork**: narrowed "irreversible" to the quiet
    single-vault theft; the recovery fork is an uncertain, contentious, mass-
    emergency-only backstop, not a personal undo.
15. **Google 2026 ECDLP paper is an arXiv preprint**, NOT peer-reviewed. Fixed
    everywhere. 20x qubit reduction is vs Litinski 2023 (~9M), not Webber. Added
    the resource-estimate-vs-machine caveat (today's hardware ~hundreds of qubits).
16. **Provenance/Mona Lisa**: NFT "original" is a socially-constructed registry
    convention (delistable, forkable, re-canonisable), not a physically fixed
    object; CC0 (XCOPY) means the thief takes the ledger entry, not the image.
    Rewrote from "the art is gone" to "a real but socially-contingent claim is
    severed." Pak's The Merge captioned as largest-by-value, a mass edition.

### Still-open / next-draft targets
- Live blue-chip holder counts (Fidenza/Ringers/Autoglyphs) still UNVERIFIED —
  pull from Dune before publication to firm the vault anchors.
- 2024-2026 cumulative NFT-theft total: Elliptic's >$100M is only through mid-2022;
  pull a fresh Chainalysis/Elliptic figure.
- BlackRock IBIT quantum paragraph still a paraphrase (status U).
