RSA-260 Was Factored on 3 September 2026 for About $400,000 of GPU Time, and NIST's RSA-2048 Dates Do Not Move

Board-ready intelligence on quantum innovation · Biomedical discovery · Post-quantum transition
The 862-bit RSA-260 fell to one engineer, part of one company cluster and 4,900 GPU-days, about $400,000 at market rates. Eric Lu's 9 September Cognition write-up says Devin coding agents built and tuned the GPU sieve across 233 sessions, 192 of them with Lu's direct participation, reports no new algorithm, and extrapolates roughly $30 million for RSA-1024 and no meaningful effect on RSA-2048.

Post-Quantum Transition

The 862-bit RSA-260 fell to one engineer, part of one company cluster and 4,900 GPU-days, about $400,000 at market rates. Eric Lu's 9 September Cognition write-up says Devin coding agents built and tuned the GPU sieve across 233 sessions, 192 of them with Lu's direct participation, reports no new algorithm, and extrapolates roughly $30 million for RSA-1024 and no meaningful effect on RSA-2048.

Published by Quentir Systems LLC · September 13, 2026 · 10 min read

In August 1977 Martin Gardner's column in Scientific American printed a 129-digit number and a short message encrypted with it, along with the estimate its authors then gave for factoring it: on the order of forty quadrillion years. In April 1994 Derek Atkins, Michael Graff, Arjen Lenstra and Paul Leyland factored RSA-129 with about 600 volunteers running roughly 1,600 computers over the internet for eight months, and read out the message: "The Magic Words are Squeamish Ossifrage". The cipher held; the estimate did not, because it assumed the factoring algorithms and the computers of 1977. RSA-129 fell to the multiple-polynomial quadratic sieve, a method developed after the column appeared, running on hardware Gardner's readers did not have.

On 3 September 2026 the 260-digit, 862-bit RSA-260 fell, thirty-five years after RSA Security published it on its 1991 challenge list. No consortium, national laboratory or quantum computer was involved. It fell to one engineer at an AI coding company, a modified open-source program, a few weeks on part of a corporate GPU cluster, and a fleet of coding agents. This post reconstructs what was announced on which date, what the 9 September write-up says the computation cost and who did the work, how that compares with the 2009 and 2020 records, and why the dates that govern RSA-2048 in production do not change.

Practical takeaway. RSA-260 is a classical result, produced with the general number field sieve and no new algorithm. Eric Lu's own estimate is 4,900 GPU-days, about $400,000 at market rates, for 862 bits; roughly $30 million for RSA-1024; and a billion times more again for RSA-2048, which he says is not meaningfully affected. NIST's draft IR 8547 proposes deprecating RSA-2048 after 2030 and disallowing it after 2035; the proposal rests on the quantum threat, and this work does not revise it. The concrete change is the extrapolated cost of breaking keys already outside policy: NIST disallowed 1,024-bit RSA for generating new signatures after 2013, and Lu's estimate, flagged as an estimate, puts an attack on one at roughly $30 million at market GPU prices, likely less with further optimization.

What Eric Lu posted on 3 September 2026, and what the press printed on 4 September

Lu's announcement on X gave the factor and little else. Scientific American's 4 September story by Peter Hall reported that Lu had offered very few details beyond a claim, "perhaps made in jest", that nothing more than "good old paper and pencil" was involved, noted conflicting reports from Devin, Cognition's own AI, and relayed a suggestion that the work may have taken at least seven months of sampling and testing primes by hand. The same story quoted Emmanuel Thomé of Inria, a member of the team that factored RSA-250, saying he expected RSA-260 to take roughly three times the computational effort of RSA-250. Checking the answer was trivial; multiplying the two 130-digit primes reproduces RSA-260. Checking the method had to wait.

The mathematician John D. Cook wrote the same day that an 862-bit modulus offers about 74 bits of security, that the 2,048-bit minimum now recommended offers about 107 by the same formula, and that breaking a 2,048-bit key would therefore take on the order of 234 times the effort spent on RSA-260. He added the necessary qualifier: the figures depend on the state of factoring algorithms and on no cryptographically relevant quantum computer existing.

What the 9 September Cognition write-up says the computation cost: 4,900 GPU-days in three stages

Six days later Cognition published "Factoring RSA-260" under Lu's name. It opens by disposing of the joke: he did not, he writes, factor RSA-260 by guessing and checking 130-digit primes by hand, and Cognition has not built a multi-thousand-qubit quantum computer either. The method was the general number field sieve, the algorithm behind every RSA challenge milestone since RSA-130 in 1996, in a heavily modified GPU port of the open-source CADO-NFS package maintained at Inria. Lu's own summary of the mathematics is the sentence that matters most for anyone who reads this as a cryptographic break: "I report essentially no algorithmic advancements — implementing lattice sieving and sparse linear system solving on GPUs required only 'good old performance engineering' to take advantage of the preposterous memory systems of the GPU."

The numbers are specific. Lu aimed Devin at a GPU replacement for CADO-NFS's CPU siever on 13 August. The RSA-260 run itself started on 18 August at 12:14 UTC and produced factors on 3 September at 01:48 UTC. Sieving ran from 22 August to 30 August, 189.5 hours of wall clock, and collected 13.85 billion raw relations, 8.3 billion of them unique, on NVIDIA GB200, GB300 and B200 nodes; the filtered matrix had 656 million rows and 98.4 billion nonzero entries. The breakdown Lu gives is 643 GPU-days for polynomial selection, 3,813 for sieving and 467 for the linear algebra, a stage in which about 7 percent of the work was lost to crashes or preemption "by more important work". In total, about 4,900 GPU-days, or 13.5 GPU-years, which he prices at about $400,000 at current market rates. He describes the whole thing as a side project on a single-digit percentage of Cognition's cluster, done while tuning the company's job scheduler. The compute was not rented for the purpose; the dollar figure is what that share of the cluster would fetch on the open market.

What Devin did across 192 sessions, and what Lu says he had to do himself

The write-up is unusually precise about the division of labor between the engineer and the agents. Lu lists what Devin handled: choosing and tuning the sieving and linear-algebra parameters, generating and optimizing polynomial selections, running the optimization loop, debugging, the processing scripts, and orchestrating the runs on the cluster. He counts 82,702 words of his own instructions in 3,328 messages across 192 of the 233 Devin sessions used for factoring, with an average of three and a peak of eighteen agents running at once; the agents themselves started 101 child sessions, 36 of which needed no intervention from him at all. Devin "needed me for executive function": setting a hierarchy of goals, keeping the agents scoped, and redirecting them when they were unproductive. His judgment is that the agents substituted for what would likely have been a multi-month effort by a team of specialized domain experts.

Two of his observations deserve more attention than the headline. First, the further the codebase moved from upstream CADO-NFS, the more confused the agents became, which he suspects has to do with CADO-NFS being present in the models' pre-training. The agents were strongest where the open-source reference already existed, a pattern that matches what the agent-assisted ECDSA.Fail circuit-optimization contest produced the same week: fast iteration on a well-documented subroutine, with the hard open questions left where they were. Second, on himself: "I share some concerns about a loss of human understanding. I did not learn as much about NFS or GPU programming as I could have expected to had I done this on my own." He offers it as a concern, and it stands as his own account of the work.

How RSA-260 compares with RSA-250 in February 2020 and RSA-768 in December 2009

RSA-768, 232 digits, was factored on 12 December 2009 by a team of thirteen led by Thorsten Kleinjung, over about two years, with computing time the authors put at almost 2,000 years of a single-core 2.2 GHz Opteron. RSA-240 and RSA-250 were factored in November 2019 and on 28 February 2020 by Fabrice Boudot, Pierrick Gaudry, Aurore Guillevic, Nadia Heninger, Emmanuel Thomé and Paul Zimmermann, using CADO-NFS and, for RSA-250, about 2,700 core-years of a 2.1 GHz Xeon Gold reference machine. Those were academic campaigns, run over months on shared university and national clusters and announced to a mailing list.

RSA-260 adds ten decimal digits and 33 bits to the 2020 result, which Thomé put at roughly three times the work; Lu's own scaling table rates RSA-250 at 0.385 times RSA-260 and, as a retrospective estimate (the 2020 team spent no such sum), prices that campaign at about $1.89 million at $0.08 per CPU core-hour, or about $159,000 had it run on today's GPUs at $3.50 per GPU-hour. What changed is the institution. One employee of a company that sells a coding agent, working a "side project" on a fraction of that company's accelerator fleet, added ten digits in about three weeks to a record that had stood for six years, with no new mathematics. The closing sentence of the write-up states the implication plainly: the barrier to entry for cryptanalytic work, and for large-scale scientific computing more broadly, is far lower than it was. In this case the cost of classical cryptanalysis was set by the GPU market and by who had idle capacity on it; Lu describes fragmented, preemptible capacity rather than a dedicated allocation, and our reading is that the organizations with that kind of spare accelerator capacity and the engineering support to exploit it are few and mostly private.

Why RSA-2048 keeps NIST's 2030 and 2035 dates, and what a 1,024-bit key now costs

Lu's own extrapolation is the one to use. RSA-1024, at 309 digits, is by standard GNFS scaling about 78 times the computation of RSA-260, which he prices at roughly $30 million at market GPU rates; his first stated takeaway is that hyperscalers or frontier AI labs could likely factor RSA-1024 numbers at that order of cost, and with more optimization probably for substantially less. His second takeaway is the sentence for anyone holding a 2,048-bit key: "RSA-2048 remains roughly a billion times harder than RSA-1024 and does not appear to be meaningfully affected by this work."

The policy dates already assume this. NIST SP 800-131A disallowed 1,024-bit RSA for generating new signatures after 2013 while allowing legacy verification of signatures already made, so the $30 million extrapolation prices an attack on keys that should no longer be signing anything, though some may still be verifying. For RSA-2048 the proposed schedule is NIST's draft IR 8547 of 12 November 2024, Transition to Post-Quantum Cryptography Standards, whose Tables 2 and 4 propose RSA at 112 bits of security strength as deprecated after 2030 and disallowed after 2035. Those proposed dates rest on the quantum attack, of which Quentir covered Craig Gidney's May 2025 resource estimate, the paper that put RSA-2048 under one million noisy qubits. A classical milestone at 862 bits, even one that arrives cheaply and with agents in the loop, does not revise the proposed 2030 and 2035 transition dates.

How Quentir Reads It

Three things changed on 3 September, and the size of the number is the least of them. The first is economic. The factoring milestones of 1994, 2009 and 2020 were public campaigns whose cost was measured in volunteer months and core-years on institutional hardware; the 2026 result is measured in dollars at a market rate for Blackwell time, and the dollars were spare capacity at a company whose business is elsewhere. When the cost of a cryptanalytic computation becomes a line on a cloud invoice, the set of organizations that can run it widens to those with suitable accelerator capacity and the engineering support to use it, which is a different thing from a purchasable factoring service, and the 1,024-bit keys that survive in old firmware and embedded devices are now priced, by a practitioner with the software in hand, at roughly $30 million by extrapolation, with his note that further optimization would likely lower it.

The second is who did the engineering. The 1977 estimate failed in 1994 because both the algorithms and the computers changed; Thomé's estimate of three times RSA-250 concerned computational effort, and on effort it held. What made that effort affordable within weeks was the GPU port, which Lu says would otherwise have been a multi-month effort by a team of specialists and was instead done by agents under one person's direction. The same acceleration ran in the other direction this month, when sixty hours of AI cryptanalysis retired the Hawk signature scheme from the NIST additional-signature process. Our reading is that attack engineering and defense engineering are both getting cheaper. The narrower finding is that this implementation improvement leaves the estimated classical attack cost of RSA-2048 prohibitive: an engineering speed-up of the kind described here does not change the order of magnitude of the estimate given above.

The third is epistemic, and Lu names it himself. The factor can be verified by anyone in a line of code; the cost figure, the GPU-day count and the account of what the agents did are self-reported by an employee of the company that sells the agents, and the author himself says he learned less of the method than he would have unaided. Quentir's Signature Report, the PQC Migration Roadmap, adds what this post does not: a fixed-scope sequence for finding and retiring the keys below RSA-2048 that an organization still holds. RSA-270, at 895 bits, is next on the list, and it will fall. The open question is who reports the invoice, and whether anyone outside the company can check it.

Sources: Eric Lu, "Factoring RSA-260", Cognition blog, 9 September 2026 (GPU-day breakdown, hardware, timeline, Devin session counts, RSA-1024 and RSA-2048 estimates, all quotations attributed to Lu); Eric Lu, announcement on X, 3 September 2026; Peter Hall, "What's the tech behind the record-breaking RSA-260 crack?", Scientific American, 4 September 2026 (the "paper and pencil" remark, the Devin reports, the Thomé estimate); John D. Cook, "New RSA number factored", 3 September 2026 (security-bit comparison); RSA numbers, Wikipedia, for the RSA-129 (April 1994), RSA-768 (12 December 2009), RSA-240 (November 2019), RSA-250 (28 February 2020) and RSA-260 (3 September 2026) entries and their cited compute figures; Atkins, Graff, Lenstra and Leyland, "The Magic Words are Squeamish Ossifrage", ASIACRYPT 1994; Kleinjung et al., "Factorization of a 768-bit RSA modulus", IACR ePrint 2010/006; Boudot, Gaudry, Guillevic, Heninger, Thomé and Zimmermann, "Comparing the difficulty of factorization and discrete logarithm: a 240-digit experiment", IACR ePrint 2020/697; NIST, IR 8547 (initial public draft), Transition to Post-Quantum Cryptography Standards, 12 November 2024, Tables 2 and 4 (RSA at 112 bits: deprecated after 2030, disallowed after 2035); NIST, SP 800-131A Rev. 2, for 1,024-bit RSA signature generation disallowed after 2013 and legacy-use verification; Guillaume Dumas, "Inside the RSA-260 Factorization", Senthorus, 12 September 2026, as a secondary reading of the same write-up. Pages checked on 13 September 2026.

Published intelligence, built to inform your own decisions. Published: September 13, 2026.

© 2026 Quentir Systems LLC
Next
Next

GPT-6 Astra Is the First OpenAI Model Rated Critical for Cyber: From the 18 August 2026 Training Pause to the 3 September System Card, and What EU AI Act Article 55 and California SB 53 Ask of It