2021.12.10 11:31:06 (1469253334418997256) from Daniel J. Bernstein:

Looking a bit more at https://arxiv.org/abs/2110.13352, and now skeptical about Theorem 6 (never mind the application to Corollary 7). The last proof step says 2^t amplifications each costing sqrt(N), but aren't half of these nested amplifications? How are further sqrt(N) factors avoided?