Statistics 2026–2027 · educational cryptography experiment. Scalar multiplication Q = kG is a one-way function under the discrete-log assumption — it is not a cryptographic hash function. This page demonstrates the algorithm itself, then tests that claim statistically.
Curve: y² = x³ + 7 over p = 2²⁵⁶ − 2³² − 977, standard generator G, group order n = 0xFFFFFFFF…4141. Multiplication means elliptic-curve scalar multiplication, not ordinary multiplication.
–
–
–
| bit i | value | action | R after step (x, abbreviated) |
|---|
–
A smooth textbook curve would be a lie here: secp256k1 lives over a finite field, so its “points” are scattered discrete dots. This toy curve is small enough to draw every valid point.
–
Two different operations: elliptic-curve scalar multiplication produces the public key; hashing (Keccak-256) produces the address. Conflating them is exactly the mistake §5 warns about.
Alternate base points are experimental only: H = aG means kH = (ka)G, a relabelling inside the same cyclic group — not a new kind of function. The standard Ethereum computation always uses G.
idle
x histogram
y histogram
–
k vs x (normalized)
k vs y (normalized)
–
–
–
–
| Property | ECC k → kG | Cryptographic hash |
|---|---|---|
| Deterministic | Yes | Yes |
| Easy forward | Yes | Yes |
| Hard to invert | Yes — ECDLP assumption | Yes — preimage resistance by design |
| Arbitrary-length input | No (scalar < n) | Normally yes |
| Collisions | None for distinct valid k (bijection onto subgroup) | Must exist; finding them must be infeasible |
| Avalanche | Empirically avalanche-like; not a claimed property | Commonly desired, designed-in |
| Algebraic structure | Strong: (k+1)G = kG + G | Ideally hidden |
Balanced histograms, ~50% bit frequencies and ≈0 Pearson correlation are sanity checks, not security proofs. Security of k → kG rests on the difficulty of the elliptic-curve discrete logarithm problem — a different assumption from hash-function design. “Output changes completely” does not make scalar multiplication a hash: the coordinates may look pseudorandom while the group relation stays exact.