matthew green (the most obnoxious cryptocurrency fuckboy in existence) points to a microsoft presentation as the first indication DUAL_EC_DRBG might be backdoored https://web.archive.org/web/20260410063603/http://rump2007.cr.yp.to/15-shumow.pdf
Results on extractors from x coordinates of EC points of prime curves suggest truncating off the top bitlen/2 bits is reasonable.
nobody ever says where these "results" come from but i was under the impression the top bits were the safe ones? maybe that's just for the regular finite field arithmetic and not for the fucked up elliptic curve form?
from the post at https://web.archive.org/web/20260410063603/https://blog.cryptographyengineering.com/2013/09/18/the-many-flaws-of-dualecdrbg/
While I’ll do my best to keep this discussion at a high and non-mathematical level, be forewarned that I’m probably going to fail at least at a couple of points.
he's such a fuckboy i hate him