Cool intro, I had no idea about ECC. However something is a bit lost on me: if the number of hops is the "private key" in this scenario, couldn't you just hop until you've found the endpoint? What makes this particularly difficult?
a^(xyz) = ((a^x)^y)^z
and as long as you know how to square, you can pretty much compute exponentials in log2(exponent) time.
https://media.ccc.de/v/31c3_-_6369_-_en_-_saal_1_-_201412272...