2026.08.15 06:22:19 (Mastodon 117098082438225574, Twitter 2088511601402138803) from Daniel J. Bernstein:
Looks like Aparne Gupte, Seyoon Ragavan, and Mark Zhandry have a computer-checked proof that Simon's DCP algorithm has cost/probability ratio _at least_ 2^(n/9): https://github.com/sragavan99/lean-ePrint-2026-1591-refutation For comparison, Regev's approach plus https://eprint.iacr.org/2020/168 seems to be around 2^(2n/9).