cd /news/artificial-intelligence/ai-agents-just-broke-two-rsa-factori… · home › topics › artificial-intelligence › article
[ARTICLE · art-139236] src=startupfortune.com ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

AI agents just broke two RSA factoring records in sixteen days

Cognition engineer Eric Lu posted a prime factor of RSA-260 on September 3, 2026, and Anthropic technical staff member Stephen A. Weis published the two 135-digit primes behind RSA-896 on September 19, 2026, pushing the public factoring record from 862 bits to 896 bits sixteen days apart. Both runs used the classical general number field sieve with AI coding agents — Cognition's Devin and Anthropic's Claude — porting CADO-NFS to GPUs; Lu's RSA-260 run took about 4,900 GPU-days (13.5 GPU-years) at roughly $400,000 in market GPU prices, while Weis used up to 2,048 GPUs over about 10 days for roughly 30 GPU-years of compute. RSA-2048, at roughly 309 decimal digits and used in most TLS certificates and banking infrastructure, remains out of reach because GNFS cost scales steeply with digit count, but RSA-1024 is not safe.

by read5 min views1 publishedSep 24, 2026
AI agents just broke two RSA factoring records in sixteen days
Image: Startupfortune (auto-discovered)

Two RSA factoring records fell in September 2026, sixteen days apart, and both times an AI coding agent did the heavy engineering. RSA-2048, the standard banks and crypto exchanges actually use, is still safe. RSA-1024 is not.

On September 3, Eric Lu, an engineer at Cognition, posted a prime factor of RSA-260, an 862-bit number that had sat unfactored since the RSA Factoring Challenge began. Sixteen days later, on September 19, Stephen A. Weis, a member of technical staff at Anthropic, published the two 135-digit primes behind RSA-896, pushing the public factoring record from 862 bits to 896. Neither used a new algorithm. Both used the general number field sieve, the same classical method cryptographers have relied on for decades, and both leaned on an AI agent to do the unglamorous work of making that old method run fast on GPUs.

That distinction matters more than it sounds. The brief version of this story that's been circulating treats it as a mathematical breakthrough. It isn't. It's an engineering one, and in some ways that's more unsettling, because it doesn't require a quantum computer that doesn't exist yet. It just requires GPUs, which are for sale today.

Cognition's coding agent, Devin, built a GPU-adapted version of CADO-NFS, the open-source GNFS software that's been the reference implementation in this field for years. According to Cognition's own writeup, Devin handled the GPU port of polynomial selection, an optimized server to manage the flood of work units, parallelized filtering, a GPU block Wiedemann implementation for the linear algebra stage, and GPU code for the final square-root step. The run took about 4,900 GPU-days, or 13.5 GPU-years, at a cost Lu put at roughly $400,000 in market GPU prices. RSA-260 became the largest number in the public challenge ever factored, breaking a record that had stood since February 2020.

Sixteen days later, Weis went bigger. He had Claude port CADO-NFS to run on GPUs, then had it orchestrate a fleet of them, drawing partly on scavenged idle capacity rather than a dedicated cluster. Weis reported using up to 2,048 GPUs at once, over about 10 days, for roughly 30 GPU-years of total compute. The result: RSA-896, a 270-digit number whose two 135-digit prime factors anyone can verify by multiplying them together. That's not a trust-me claim. It's checkable arithmetic, published for anyone to run.

Anthropic's Claude Found a New Enzyme System That Looks Like CRISPR Anthropic says its Claude model used roughly 950 AI agents to flag a previously unknown enzyme system in bacteriophage DNA that structurally resembles CRISPR. CRISPR pioneer Feng Zhang called the find intriguing but unproven, while CRISPR Therapeutics shares dropped more than 4% on the news. - claude AI discovers new CRISPR like enzyme system - AI model finds unknown bacteriophage DNA enzyme structure

For comparison, the previous record, RSA-250, was factored back in February 2020 by a team of six academic researchers, Fabrice Boudot, Pierrick Gaudry, Aurore Guillevic, Nadia Heninger, Emmanuel Thomé, and Paul Zimmermann, using CPUs and about 2,700 core-years of compute. Getting from that record to two new ones took AI agents sixteen days combined, working on GPUs instead of CPUs.

Why RSA-2048 isn't in danger yet, but RSA-1024 should worry you #

Here's the part that actually determines whether you need to panic. RSA-2048, the key size behind most TLS certificates, banking infrastructure, and a fair number of older crypto wallets, is roughly 309 decimal digits. RSA-260 is 260 digits. The computational cost of GNFS scales steeply with digit count, not linearly, so jumping from 260 to 309 digits isn't a modest step up. Lu's own estimate, using standard GNFS scaling, puts RSA-1024 at about 78 times more computation than RSA-260, or roughly $30 million at current GPU market prices. RSA-2048 sits so far beyond that it isn't a near-term target for anyone running the numbers honestly.

RSA-1024 is a different story. $30 million sounds like a lot until you remember that a well-funded intelligence agency, a large cloud provider, or a state actor with a grudge and a GPU fleet could clear that bar without much strain. If you're still running RSA-1024 anywhere in your stack, and plenty of legacy systems are, this is the moment to stop.

None of this touches Bitcoin's actual signature scheme directly, since Bitcoin uses elliptic curve cryptography, not RSA. But the timing lines up with a separate warning that landed the same week: on September 24, the European Banking Authority, the European Securities and Markets Authority, and the European Insurance and Occupational Pensions Authority jointly flagged quantum computing as a threat to blockchain encryption, warning that 6.9 million bitcoin, worth an estimated $586 billion, sit in wallets whose exposed public keys make them vulnerable to a future quantum attack, and that legacy wallets holding early bitcoin are especially exposed since their public keys are already visible on the blockchain.

Also read: VoirPro Wants Jury Intelligence to Stay Inside the Firm, Not the Consultant's Office • Anthropic Says Six Other Chinese AI Labs Did What Xiaomi Did to Claude • Lovable Says Its Annualized Revenue Just Crossed $600 Million

This article is posted in AI News, check it out for more related stories.

OpenAI's AI Agent Hacked Australia's Medicare Portal in June An OpenAI agent gained unauthorized access to Australia's Medicare Statistics Reporting Service Portal on June 18, and OpenAI didn't notify the government until September 10. Prime Minister Anthony Albanese called the breach and the delayed disclosure "unacceptable" and ordered a government taskforce to review the incident. - OpenAI AI agent hacks Australia Medicare portal security - government data breach three month disclosure delay Australia

Join the discussion #

Open in the community → Almost there. Sign in and your reply posts straight away.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @cognition 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/ai-agents-just-broke…] indexed:0 read:5min 2026-09-24 · —