In 16 days this September, two AI coding agents — Devin and Claude — helped individual engineers shatter RSA factoring records that had stood for over six years. No quantum computers. No new mathematics. Just AI agents doing the GPU engineering that previously took a whole team. That barrier is now gone, and the implications for developers are immediate.
Two Records, Sixteen Days #
On September 3, Eric Lu, an engineer at Cognition, factored RSA-260 — a 260-digit, 862-bit semiprime from the original 1991 RSA Factoring Challenge. He used Cognition’s Devin AI agent to build a heavily customized, GPU-accelerated version of CADO-NFS, the open-source General Number Field Sieve software. The computation consumed about 4,900 GPU-days and cost roughly $400,000 at market rates. The previous public record, RSA-250, had been set in February 2020 and sat unbroken for six and a half years.
Sixteen days later, Anthropic engineer Steve Weis factored RSA-896 — a 270-digit, 896-bit number, pushing the public record even further. Weis used Claude to navigate the complex CADO-NFS parameter space, then orchestrated a fleet of up to 2,048 GPUs running as a low-priority job on idle Anthropic compute. Total compute: roughly 30 GPU-years over 10 days.
Claude helped navigate the parameter space of a computation that would have taken a small team of number theorists months to configure manually.
— Steve Weis, Anthropic engineer,saweis.net
Neither result used a quantum computer. Neither team discovered new mathematical shortcuts. The General Number Field Sieve algorithm is the same one cryptographers have used for decades. What changed is who can run it at scale — and how fast they can get there.
What AI Actually Did #
This is not a story about AI doing mathematics. It is a story about AI eliminating the engineering bottleneck that kept GPU-accelerated GNFS as a team sport.
Devin built out every major component of the GPU pipeline from scratch: polynomial selection, lattice sieving, the block Wiedemann linear algebra implementation, and the final square-root step. The square root alone was rebuilt three times before landing on a GPU-accelerated NTT implementation that completed in 88 minutes. Without an AI agent, you would need a team of number theorists and GPU engineers spending months to achieve the same result.
Claude’s role on RSA-896 was different but equally significant: parameter space navigation and fleet orchestration at a scale that would be tedious and error-prone to manage manually. One engineer, 2,048 GPUs, ten days. This is the pattern that matters — AI as a force multiplier for expert-level computation that one person could not previously coordinate alone.
The Security Signal: RSA-1024 Is Done #
Neither factorization threatens RSA-2048. The gap between a 896-bit number and a 2,048-bit number is not linear — factoring RSA-2048 is approximately one billion times harder than RSA-1024. Modern TLS connections, banking infrastructure, and standard web certificates are not affected.
RSA-1024 is a different matter. Eric Lu estimated that a hyperscaler or frontier AI lab could factor a 1,024-bit RSA number for around $30 million at market GPU prices. That is within reach of a well-funded intelligence agency, a large cloud provider, or a state actor with a GPU fleet. RSA-1024 has been deprecated by Microsoft, NIST, and most major standards bodies for years — but deprecated does not mean gone.
It still shows up in legacy enterprise certificates, internal PKI, IoT devices, old VPN configurations, and SSH host keys. If any of that describes your infrastructure, treat those keys as compromised.
What Developers Should Do Now #
Auditing is straightforward. Run the command below and check the reported “Server public key” bit length. For internal systems and non-HTTPS services, scan your certificate inventory. Anything at 1,024 bits or below should be rotated immediately — not scheduled, not noted for the next sprint.
openssl s_client -connect yourhost:443 2>/dev/null | grep "Server public key"
Beyond the immediate audit, post-quantum migration planning is overdue for most teams. NIST finalized three post-quantum cryptography standards in 2024 — ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) — and published a transition timeline that deprecates RSA-2048 and ECC P-256 by 2030. For teams working on US government or national security system contracts, the CNSA 2.0 compliance deadline is January 2027.
The Broader Pattern #
There is something worth sitting with in the 16-day gap between these two records. RSA challenge numbers had not been factored publicly in over six years. The barrier was not the mathematics — it was the engineering effort required to GPU-optimize a complex multi-stage computation. AI coding agents removed that barrier without changing the math at all.
The question worth asking: what other “too hard for one person” security computations are now one-person projects? Discrete logarithm problems, lattice attacks on weak key generation, collision attacks on aging hash functions — the same pattern of AI-accelerated expert-level engineering will recur. The September 2026 RSA results are a preview, not a one-off.
Audit your keys. Start the PQC conversation with your team. The math has not changed, but the cost of breaking it keeps dropping. For a structured starting point, this technical breakdown of the RSA-896 factorization covers what the computation actually involved.