pull down to refresh

I think that's a good breakdown, though I wouldn't necessarily call the labs "good actors" -- just actors that are more incentivized to disclose progress.

It's a legitimate question of whether the incentive to hide progress gets larger the closer you actually get to CRQC.

Regardless, though, I think for a surprise attack to actually happen we'd need a few things to converge:

  • The secret attacker(s) are significantly further ahead in progress than any disclosers
  • The secret attacker(s) would be willing to break their secrecy in order to attack bitcoin

... Right?