RSA-260 factored after 35 years, cutting factoring costs tenfold
New CapabilitiesGPU-optimized sieving and AI-assisted engineering factor the largest RSA challenge number yet
Yesterday: Hacker News discussionNew here? Follow stories to track developments over time. Create a free account to get updates when stories you care about change.
Overview
Updated 1 hour agoOn September 3, 2026, Cognition engineer Eric Lu posted a 130-digit number on X with two words: "divides RSA-260." The number was a prime factor of a 260-digit composite that had stumped cryptographers for 35 years.
The factorization cost about $400,000 in GPU time and used a GPU-optimized version of the general number field sieve. It cuts factoring costs by roughly tenfold versus the previous state of the art, and it puts 1024-bit RSA keys within reach of well-funded organizations.
Why it matters
Falling factoring costs could make 1024-bit RSA keys breakable for tens of millions of dollars, forcing legacy systems to migrate sooner.
Questions about this story
Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.
No questions yet — be the first to ask.
Key Indicators
Voices
Curated perspectives — historical figures and your fellow readers.
Play
Exploring all sides of a story is often best achieved with Play.
Higher or Lower
A number from this story, against one from elsewhere in the news — guess which is bigger, then keep the chain going. 5 rounds, 3 strikes; a miss costs a strike and resets your streak.
Keyboard: ↓/L lower · ↑/H higher
0 points — sign up to put that on the leaderboard.
Connections
Sixteen names from the news. Find the four hidden groups of four. Four mistakes max.
Sign up to keep a daily streak — a new puzzle lands every day.
Exit debate?
Your progress in this debate will be lost.
- 1 Two AI personas square off on this story.
- 2 You predict who'll win each round — correct picks earn XP.
- 3 One crossfire question is yours to fire. Pick it carefully.
Couldn't generate a topic
Select Your Champions
Choose one persona for each side of the debate
DEBATE TOPIC
Choose personas with different perspectives for a more dynamic debate.
Select debater for this side:
No debate personas available right now.
Select debater for this side:
No debate personas available right now.
Who's Got This Round?
Make your prediction before the referee scores
The referee scores both sides on
Round Results
Set the Crossfire
Pick the question both personas must answer in the final round
Debate Oracle! You called every round!
Sharp Instincts! You know your debaters!
The Coin Flip Strategist! Perfectly balanced!
The Contrarian! Bold predictions!
Inverse Genius! Try betting the opposite next time!
XP Breakdown
Prediction History
People Involved
Organizations Involved
Timeline
March 1991 September 2026
-
Hacker News discussion
Latest DiscussionHacker News threads analyze the factorization and its implications for RSA security.
-
Independent confirmation
VerificationObservers confirm the factorization by dividing the published RSA-260 value by Lu's number.
-
Eric Lu posts factor of RSA-260
AnnouncementLu posts a 130-digit number on X with the words "divides RSA-260."
-
RSA-250 factored
MilestoneInternational team factors RSA-250, an 829-bit number, using the number field sieve.
-
RSA Factoring Challenge published
MilestoneRSA Laboratories publishes a list of large composite numbers to test factoring limits.
Historical Context
3 moments from history that rhyme with this story — and how they unfolded.
RSA-768 factored (2009)
A team led by Thorsten Kleinjung factored RSA-768, a 232-digit number, using the number field sieve. The computation took about two years on hundreds of machines.
Demonstrated that 768-bit RSA was breakable with sufficient resources.
Contributed to the push toward 2048-bit keys as the standard minimum.
Showed the cost curve of factoring and set expectations for how quickly records would fall.
1024-bit RSA deprecation (2013)
NIST deprecated 1024-bit RSA keys, recommending 2048-bit as the minimum for new systems. This followed earlier deprecations of 512-bit and 768-bit keys.
Organizations migrated to 2048-bit keys over several years.
Established the pattern of factoring milestones driving standards changes.
Shows how factoring progress leads to standards changes; RSA-260 could accelerate similar moves.
RSA-250 factored (2020)
An international team including Fabrice Boudot, Pierrick Gaudry, Aurore Guillevic, Nadia Heninger, Emmanuel Thomé, and Paul Zimmermann factored RSA-250, an 829-bit number, using the number field sieve on thousands of CPUs.
Set the previous record for largest RSA challenge number factored.
Established the baseline that RSA-260 would beat six years later.
The immediate predecessor record; RSA-260 is roughly three times more expensive to factor.
