Clay Mathematics Institute · announced 24 May 2000
Seven problems.
Seven million dollars.
At the turn of the millennium a group of mathematicians chose seven questions that had resisted every attempt at an answer, and attached a $1,000,000 prize to each one. A quarter of a century later, six are still open — and one of those six, as of September 2026, has a claimed proof that nobody has accepted yet.
These problems are usually explained in a language only specialists read. This page tries the opposite: every one of them gets a plain-English story and something you can actually play with. The simulations below are real — the primes, the fluid, the curves and the zeros are all being computed in your browser as you scroll.
Scroll, or pick one. Nothing here assumes maths beyond school algebra — where a technical word is unavoidable it is marked like this.
What makes a problem worth a million dollars?
Not difficulty alone. Each of these sits at a junction where a great deal of other mathematics — and in three cases, physics — is already leaning on an answer that nobody has proved. Whole research programmes begin with the words “assume the Riemann Hypothesis”. Engineers simulate fluids every day with equations we cannot prove behave. A proof would not just settle a question; it would tell us whether an enormous amount of existing work stands on rock or on sand.
How to claim one
The rules are strict and unglamorous. A solution must be published in a refereed journal of worldwide repute and then survive two years of general acceptance by the mathematical community before the Clay Mathematics Institute will even consider an award. A counterexample counts too — for most of these, disproving the statement is just as valuable as proving it.
P versus NP
If a computer can check an answer quickly, must it also be able to find one quickly?
The everyday version
Think about a hard Sudoku. Filling it in can take you an hour of trial and error. But if a friend hands you a completed grid, you can tell in under a minute whether it is right. Solving is hard; checking is easy.
That gap shows up everywhere. Fitting a delivery round into eight hours, seating 200 wedding guests so no feuding relatives share a table, packing a van, folding a protein, scheduling exams — in every case, a proposed answer can be verified almost instantly, and yet finding one seems to require sifting through an astronomical number of possibilities.
P vs NP asks whether that gap is real. Is searching genuinely harder than checking, or have we simply never found the clever shortcut?
What is actually being asked
P is the class of problems a computer can solve quickly — in polynomial time. NP is the class where a proposed solution can be checked quickly. Every problem in P is obviously in NP. The question is whether the reverse holds:
Does P = NP?
There is a twist that makes the question sharper. In 1971 Cook showed that certain problems in NP are NP-complete: universal, in the sense that a fast algorithm for any single one of them would immediately give a fast algorithm for all of them. Thousands of practical problems — from circuit design to Tetris — are now known to be NP-complete. They all stand or fall together.
Why anyone cares
Nearly all modern cryptography is a bet that P ≠ NP. Your bank's encryption works because multiplying two big primes is easy while pulling them apart again is not. If P = NP — and the algorithm were practical rather than merely polynomial — that bet collapses.
The upside would be just as vast. Optimal drug design, perfect logistics, chip layouts that cannot be improved, and mathematics itself partly automated: if verifying a proof is easy, and P = NP, then finding a proof of any theorem with a short proof becomes easy too.
Where it stands
Wide open, and most researchers expect the answer to be no. In a 2019 poll of experts, close to nine in ten said they believe P ≠ NP. What makes it so stubborn is that the field has proved several barrier theorems: entire families of proof technique have been shown, rigorously, to be incapable of settling the question. Any solution will need an idea nobody currently has.
Try it → Solve the puzzle yourself, then hit Brute force and watch a computer do it the dumb way. Then drag the size slider and see how fast “dumb” becomes impossible.
See it for yourself
You are not expected to follow these. They are here so you can see that the real thing exists, and who wrote it.
- Official The official problem statement (PDF) Stephen Cook for the Clay Mathematics Institute · the version that counts
- Survey P =? NP (PDF, 121 pages) Scott Aaronson · the best survey for a non-specialist who wants the real picture
- Clay P vs NP — problem page claymath.org · official description and background
Searching vs. checking
A pocket-sized NP problem: pick tiles that add up exactly to the target.
The Riemann Hypothesis
Primes look scattered at random. Riemann said their randomness is as tame as it could possibly be — and pinned that claim to a single vertical line.
The everyday version
Primes — 2, 3, 5, 7, 11, 13 — are the atoms of arithmetic, and they arrive on the number line with no obvious pattern. But step back far enough and a pattern appears: primes thin out at a predictable rate. Near a large number x, roughly one in every ln(x) numbers is prime.
That is the smooth trend. The interesting question is the error: how far do the actual primes wander from it? Riemann found something extraordinary. The error is not noise. It is a sum of waves — and every wave is generated by one special number, a zero of the zeta function. Add up enough of these waves and the smooth curve grows steps, and the steps land exactly on the prime numbers.
Every zero anyone has ever computed sits on one vertical line in the complex plane. Riemann guessed they all do. That guess is the hypothesis, and it is equivalent to saying the primes are distributed as evenly as they possibly could be — the error never exceeds roughly √x.
What is actually being asked
The Riemann zeta function starts as an innocent sum and is then extended to every complex number:
ζ(s) = 1 + 1/2s + 1/3s + 1/4s + …
It vanishes at the negative even integers −2, −4, −6 … (the trivial zeros, which nobody worries about). The conjecture concerns all the others:
Every non-trivial zero of ζ(s) has real part exactly ½.
Why anyone cares
Hundreds of published theorems begin “assume the Riemann Hypothesis”. An entire shadow literature exists of results that are true if it holds. Proving it would promote all of them to fact in a single stroke; disproving it would demolish them.
There is also a strange physical echo. The spacing of the zeros matches the statistics of energy levels in heavy atomic nuclei, described by random matrix theory. Nobody knows why number theory and quantum chaos should share a fingerprint.
Where it stands
Open since 1859, and Hilbert's eighth problem in 1900 as well. Hardy proved in 1914 that infinitely many zeros lie on the line; later work showed a positive proportion do. More than ten trillion zeros have been checked by computer, and every one obeys. That is powerful evidence and no proof at all — number theory has a history of patterns that hold for astronomically long and then fail.
Try it → Drag the slider from zero waves upward and watch the staircase of primes assemble itself out of the zeros. Then switch to the second tab to see the zeros themselves, found live by your browser.
See it for yourself
You are not expected to follow these. They are here so you can see that the real thing exists, and who wrote it.
- Official The official problem statement (PDF) Enrico Bombieri for the Clay Mathematics Institute · the version that counts
- Clay Riemann Hypothesis — problem page claymath.org · official description and background
- Reference Riemann hypothesis Wikipedia · unusually good, and the place to start on the consequences
Building the primes out of waves
Riemann's explicit formula, computed here from scratch — no lookup tables.
Yang–Mills Existence and Mass Gap
Light crosses the universe. The strong force stops at the edge of a proton. The theories describing them look almost identical — and nobody can prove why one of them runs out.
The everyday version
Electromagnetism has unlimited reach. You can see stars because photons, the particles of light, are massless and so can carry the force across billions of light years.
The strong nuclear force is built from a theory of the same shape — a Yang–Mills theory — and its force carriers, the gluons, are also massless in the classical equations. By the same logic it should reach across the cosmos. It does not. It dies out after about a millionth of a billionth of a metre.
The accepted explanation is that the quantum version of the theory behaves nothing like the classical one. Gluons pull on each other, tangle up, and the lightest object the theory can actually produce — a glueball — has real, positive mass. A force carried by something heavy has a short range. That minimum mass is the mass gap.
Every experiment agrees. Every supercomputer simulation agrees. There is no proof, and worse: nobody has yet managed to write down the quantum theory itself in a mathematically rigorous way in four dimensions.
What is actually being asked
For any compact simple gauge group, prove that a quantum Yang–Mills theory exists on four-dimensional space–time and has a mass gap Δ > 0.
Two demands in one. Existence: construct the theory to the standards of rigorous mathematics, satisfying the standard axioms of quantum field theory. Mass gap: show the lightest excitation above the vacuum weighs something.
Why anyone cares
This is the missing foundation under a third of the Standard Model. Physicists calculate with quantum field theory constantly and to spectacular accuracy, yet the four-dimensional theories they use have never been shown to exist as mathematical objects. A proof would also explain confinement: why no one has ever seen a lone quark.
Where it stands
Open. Rigorous constructions exist in two and three space–time dimensions; four is the hard case and the physical one. Lattice simulations compute the glueball mass to a few per cent, so the answer is not in doubt — only the proof.
Try it → Click in the field to disturb it. With the mass at zero the ripples run away forever. Nudge the mass up and watch the disturbance refuse to travel — that is a short-range force, appearing in front of you.
See it for yourself
You are not expected to follow these. They are here so you can see that the real thing exists, and who wrote it.
What a mass gap does to a field
A real wave simulation. Mass zero gives you light; mass above zero gives you the strong force.
The Hodge Conjecture
A shape carries a catalogue of its own holes. Some entries in that catalogue look as though they must come from real sub-shapes cut out by equations. Do they always?
The everyday version
This is the hardest of the seven to picture, so start with an analogy. Imagine you can only build with Lego. Someone shows you a shadow on a wall and asks: can that shadow always be cast by something you built out of Lego bricks? Sometimes obviously yes. Sometimes it looks Lego-ish — right proportions, right angles — but you cannot find the model that casts it.
In Hodge's setting the “Lego bricks” are algebraic varieties: shapes carved out by polynomial equations. The “shadows” are topological features — the holes, loops and voids of a shape, catalogued by a machinery called cohomology.
Hodge discovered that on nice shapes this catalogue splits into neat compartments, and that one particular diagonal set of compartments looks suspiciously algebraic. His conjecture: those really are the shadows of Lego models. Every such class comes from an honest sub-shape cut out by polynomials.
It is a claim that a purely analytic smell always has an algebraic source. A bridge between three fields that were not supposed to touch.
What is actually being asked
On a non-singular complex projective variety, every Hodge class is a rational combination of the classes of algebraic cycles.
The diagram on the right is the “Hodge diamond”, the actual catalogue. Its diagonal is where Hodge classes live. The conjecture says nothing on that diagonal is a mirage.
Why anyone cares
Algebraic geometry has two ways of describing a shape: by writing equations, and by counting holes. They give different information and translating between them is one of the central difficulties of the subject. The Hodge conjecture would be the strongest dictionary yet, and it feeds directly into the theory of motives — a grand unification that much of modern number theory is waiting on.
Where it stands
Open, but not untouched. The first diagonal case is a theorem — Lefschetz proved it in 1924, before Hodge even stated the general conjecture. It is also known for every shape of three or fewer complex dimensions, and in scattered families beyond. Everything after that is conjecture, and there is no consensus that it is even true.
Try it → Explore the Hodge diamonds of real shapes and click the highlighted diagonal cells. Then switch tabs and draw a loop on a doughnut to see what a “class” actually is.
See it for yourself
You are not expected to follow these. They are here so you can see that the real thing exists, and who wrote it.
The catalogue of holes
Hodge diamonds of genuine shapes, and where the conjecture lives.
The Poincaré Conjecture
If every loop you draw on a shape can be pulled tight to a point, the shape is a sphere. Proved in 2003 — by a man who then turned down the money.
The everyday version
Stretch a rubber band around an orange. Whatever way you loop it, you can always slide it around until it shrinks to a single point. Now do the same to a doughnut. A band threaded through the hole will never shrink to a point — the hole is in the way.
So “every loop shrinks” detects the difference between a sphere and a doughnut without ever measuring anything. Poincaré asked: is that test complete? If a three-dimensional shape has no holes in this sense, must it be a three-dimensional sphere?
Remarkably, the same question in five dimensions and above was answered yes in the 1960s, and in four dimensions in 1982. Three — our own — was the last and hardest case.
What is actually being asked
Every closed, simply connected 3-manifold is homeomorphic to the 3-sphere.
How it was solved
Richard Hamilton proposed the weapon in 1982: Ricci flow. Treat curvature like heat and let it diffuse. Bumps flatten, dents fill, and a lumpy shape gradually rounds itself out — exactly the way a hot spot spreads through a metal bar until the temperature is even.
The obstacle was that Ricci flow can misbehave. A shape can develop a thin neck that pinches to nothing, and the flow breaks down. Between 2002 and 2003 Grigori Perelman posted three preprints to arXiv — no journal, no fanfare — that classified every way the flow can fail and showed you can cut out each singularity, cap the ends and restart. Ricci flow with surgery. The pieces that survive are recognisable, and if the shape had no loops to begin with, only the sphere is left standing.
He proved considerably more than asked: the full Thurston geometrization conjecture, which classifies all three-dimensional shapes. Poincaré fell out as a corollary.
The ending
Perelman declined the Fields Medal in 2006 and the million dollars in 2010, saying the prize was unfair to Hamilton, whose contribution he considered no less than his own. He left research mathematics and lives quietly in Saint Petersburg. The Clay Institute used the unclaimed money to endow a Poincaré Chair for young mathematicians in Paris.
Try it → Drag to rotate. Shrink the loop on the sphere, then try the same on the doughnut. Then run Ricci flow on a lumpy blob and watch it become a perfect circle.
See it for yourself
The only problem here with an answer — and you can read the original three preprints, posted to arXiv and never submitted to a journal.
- arXiv The entropy formula for the Ricci flow and its geometric applications Grigori Perelman · November 2002 · the first of the three preprints that did it
- arXiv Ricci flow with surgery on three-manifolds Grigori Perelman · March 2003 · the second preprint
- arXiv Finite extinction time for the solutions to the Ricci flow … Grigori Perelman · July 2003 · the third and last
- Book Ricci Flow and the Poincaré Conjecture (PDF, free in full) John Morgan & Gang Tian · the 500-page verification of Perelman’s proof
- Official The official problem statement (PDF) John Milnor for the Clay Mathematics Institute
The loop test, and the flow that settled it
The one problem on this page with an answer.
Birch and Swinnerton-Dyer Conjecture
Count a curve's solutions clock by clock, prime by prime, and — supposedly — you can tell whether it has infinitely many fraction solutions without ever finding one.
The everyday version
Take an elliptic curve, say y² = x³ − 25x. Now ask an ancient question: which points on it have coordinates that are ordinary fractions?
These curves have a magic trick. Draw a straight line through two fraction points; it hits the curve in exactly one more place, and that third point is a fraction point too. So from two solutions you can manufacture a third, then a fourth, forever. Sometimes this process cycles back on itself and the curve has only finitely many solutions. Sometimes it runs away and produces infinitely many, with numerators exploding to hundreds of digits.
Which happens? There is no known method guaranteed to tell you. Birch and Swinnerton-Dyer, running one of the first computers at Cambridge in the 1960s, tried something indirect: for each prime p, count the curve's solutions on a clock face of size p. Those counts are easy — finite arithmetic. And they noticed that curves with infinitely many fraction points tend to have more solutions than average on those clock faces, consistently, forever.
The whole conjecture is that this hunch is exactly right, and quantitatively so.
What is actually being asked
Bundle all the clock-face counts into one function, the L-function L(E, s). Bundle all the fraction solutions into one number, the rank.
The rank of E over the rationals equals the order of vanishing of L(E, s) at s = 1.
In words: the number of independent infinite families of solutions equals how flat the L-function is at one specific point. A count of things you can never finish, read off from a function built entirely out of finite counts.
Why anyone cares
Elliptic curves are the workhorses of modern number theory — Wiles used them to prove Fermat's Last Theorem — and they secure a large fraction of internet traffic through elliptic-curve cryptography. BSD is also the model case for a much larger web of conjectures linking L-functions to arithmetic. It even settles a problem from the tenth century: which whole numbers can be the area of a right triangle with fraction-length sides.
Where it stands
Open, with the shallow end conquered. If the L-function vanishes to order 0 or 1, the conjecture is a theorem, by work of Gross, Zagier and Kolyvagin in the late 1980s. Combined with later results this covers a majority of all elliptic curves. Rank 2 and above remains completely open, as does the refined version predicting the exact leading coefficient.
Try it → Watch the chord-and-tangent trick generate rational points with absurd numerators, then run the original 1960s experiment yourself — the point counts really do give the rank away.
See it for yourself
You are not expected to follow these. They are here so you can see that the real thing exists, and who wrote it.
- Official The official problem statement (PDF) Andrew Wiles for the Clay Mathematics Institute · the version that counts
- Clay Birch and Swinnerton-Dyer Conjecture — problem page claymath.org · official description and background
- Data Elliptic curve 37.a1 — the rank-1 curve from the plot LMFDB · every invariant of the curve, including its rank and L-function
Making solutions out of solutions
Exact rational arithmetic, and a re-run of the computation that started it all.
Six left
It is worth sitting with how odd this list is. Two of the problems (Yang–Mills, Navier–Stokes) ask us to prove that things we already use every day are mathematically sound. Two (Riemann, Birch–Swinnerton-Dyer) say that a chaotic-looking arithmetic object is secretly controlled by a smooth analytic one. One (Hodge) claims topology and algebra agree more than we can show. One (P vs NP) asks whether creativity is fundamentally harder than criticism. And one is finished.
None of them will be solved by cleverness alone. Perelman's proof took seven years of silence and rested on twenty years of Hamilton's groundwork. If any of the remaining six falls in your lifetime, it will almost certainly be because someone built a new kind of mathematics on the way to it — and that, far more than the money, is the point of the list.
September 2026 made that concrete, and complicated it. An AI system produced a machine-checkable proof of the forced Navier–Stokes blow-up in days, on top of a multiscale technique that human mathematicians had spent two years building and that Córdoba and Martínez-Zoroa had the original idea for. The unforced problem is still open, the Clay Institute has accepted nothing, and there is a bitter argument about credit. Whatever else it is, it is a preview of how these last six are likely to go: not a lone genius in silence, but a contested pile-up of people and machines, with the interesting question being who gets the credit and whether anyone can still check the answer.