Pull to refresh
Logo
RSA-260 factored after 35 years, cutting factoring costs tenfold

RSA-260 factored after 35 years, cutting factoring costs tenfold

New Capabilities

GPU-optimized sieving and AI-assisted engineering factor the largest RSA challenge number yet

Yesterday: Hacker News discussion

Overview

Updated 1 hour ago

On September 3, 2026, Cognition engineer Eric Lu posted a 130-digit number on X with two words: "divides RSA-260." The number was a prime factor of a 260-digit composite that had stumped cryptographers for 35 years.

The factorization cost about $400,000 in GPU time and used a GPU-optimized version of the general number field sieve. It cuts factoring costs by roughly tenfold versus the previous state of the art, and it puts 1024-bit RSA keys within reach of well-funded organizations.

Why it matters

Falling factoring costs could make 1024-bit RSA keys breakable for tens of millions of dollars, forcing legacy systems to migrate sooner.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

$400K
Estimated cost of factorization
About 4,900 GPU-days at current market prices.
4,900
GPU-days of computation
Breakdown: 643 in polynomial selection, 3,813 in sieving, 467 in linear solving.
10x
Cost reduction vs previous state of the art
The GPU lattice siever factors numbers at lower cost than prior public implementations.
35
Years RSA-260 remained unfactored
Published in 1991, solved in September 2026.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

Play

Exploring all sides of a story is often best achieved with Play.

Most of these play right now — no account needed. Sign up to save scores, keep a streak, and unlock Debate and Predict. Log in Sign Up
Predict 3 ways this could play out. Back the one you believe — contrarian picks score more when a scenario has a resolution date. Log in to play

People Involved

Organizations Involved

Timeline

March 1991 September 2026

5 events Latest: Yesterday
Tap a bar to jump to that date
  1. Hacker News discussion

    Latest Discussion

    Hacker News threads analyze the factorization and its implications for RSA security.

  2. Independent confirmation

    Verification

    Observers confirm the factorization by dividing the published RSA-260 value by Lu's number.

  3. Eric Lu posts factor of RSA-260

    Announcement

    Lu posts a 130-digit number on X with the words "divides RSA-260."

  4. RSA-250 factored

    Milestone

    International team factors RSA-250, an 829-bit number, using the number field sieve.

  5. RSA Factoring Challenge published

    Milestone

    RSA Laboratories publishes a list of large composite numbers to test factoring limits.

Historical Context

3 moments from history that rhyme with this story — and how they unfolded.

December 2009

RSA-768 factored (2009)

A team led by Thorsten Kleinjung factored RSA-768, a 232-digit number, using the number field sieve. The computation took about two years on hundreds of machines.

Then

Demonstrated that 768-bit RSA was breakable with sufficient resources.

Now

Contributed to the push toward 2048-bit keys as the standard minimum.

Why this matters now

Showed the cost curve of factoring and set expectations for how quickly records would fall.

2013

1024-bit RSA deprecation (2013)

NIST deprecated 1024-bit RSA keys, recommending 2048-bit as the minimum for new systems. This followed earlier deprecations of 512-bit and 768-bit keys.

Then

Organizations migrated to 2048-bit keys over several years.

Now

Established the pattern of factoring milestones driving standards changes.

Why this matters now

Shows how factoring progress leads to standards changes; RSA-260 could accelerate similar moves.

February 2020

RSA-250 factored (2020)

An international team including Fabrice Boudot, Pierrick Gaudry, Aurore Guillevic, Nadia Heninger, Emmanuel Thomé, and Paul Zimmermann factored RSA-250, an 829-bit number, using the number field sieve on thousands of CPUs.

Then

Set the previous record for largest RSA challenge number factored.

Now

Established the baseline that RSA-260 would beat six years later.

Why this matters now

The immediate predecessor record; RSA-260 is roughly three times more expensive to factor.

Sources

(4)