AI is continuing to break records in technical fields. An Anthropic engineer says Claude ported a decades-old factoring tool to GPUs and ran it across thousands of idle chips to break RSA-896, a famous cryptographic challenge number. Steve Weis has announced that he had factored RSA-896 with the help of Claude, Anthropic’s AI model. The run finished on September 19, 2026.
What is RSA-896? #
Most of the internet’s security rests on a simple asymmetry. Multiplying two huge prime numbers together is easy, but taking the result and working out which two primes produced it is extremely hard. Much of the encryption that protects online banking, messaging and shopping is built on this. It is called RSA, after the initials of its inventors.
In the 1990s, the company RSA Security published a list of “challenge numbers” to see how hard the problem really was. Each is the product of two secret primes, and the challenge is to find them. RSA-896 has 896 bits, which works out to 270 decimal digits, roughly a number the length of a full page of text.
Weis says the two primes are each 448 bits (about 135 digits) long. Anyone can check the result by multiplying the two published factors together and confirming they give RSA-896. We did, and they do.
How it was done #
The method is not new. Factoring numbers this size uses the General Number Field Sieve, an algorithm developed in the 1990s. The open-source software package CADO-NFS implements it, and earlier factoring records were set with it.
What Weis says is new is how the work was carried out. He had Claude port CADO-NFS to run on GPUs, the graphics chips that power AI training. Claude then orchestrated a fleet of them, drawing on scavenged idle capacity. According to Weis, the run used up to 2,048 GPUs at once, over about 10 days, for roughly 30 GPU-years of total computing.
A GPU-year is one GPU running flat out for a year. Spreading 30 of them across 2,048 machines is what let the job finish in ten days rather than three decades.
Why it matters #
The significance is in the process, not the cryptography. Software like CADO-NFS is complex, highly tuned, and written for conventional processors. Adapting it to GPUs and then managing a fleet of thousands of chips across unused capacity is the kind of work that normally takes a specialist team a long time. Here, an AI system did much of it.
For the business and tech world, that is the takeaway. AI models are moving from answering questions and writing snippets of code to taking on large, messy engineering projects and running them end to end, including the logistics of finding and coordinating compute.
What it does not mean #
Weis was clear about the limits, and they are worth repeating. There is no new math: Claude did not discover a shortcut, and there is no new factoring algorithm. The problem is also still hard, because the cost of factoring keeps climbing steeply as numbers get bigger. Ten days and 2,048 GPUs for 896 bits does not translate into cracking the 2,048-bit keys used in practice, which are astronomically harder. Real-world keys are not at risk either, and Weis states plainly that this poses no new threat to deployed cryptographic keys. In short, this is a demonstration of engineering muscle, not a security breach, and anyone worried about the safety of their online accounts has no new reason to be.
Credit where it’s due #
When Weis asked Claude whether it had a message for the public, it pointed to the people who came before. “The credit belongs first to the people who built the number field sieve and CADO-NFS over several decades, and to the teams who set the earlier records,” Claude said. “This run used their algorithm and much of their code.”
Not the first AI-assisted factoring result #
Weis’s result came less than three weeks after a similar one from a rival AI company. On September 9, Eric Lu of Cognition, the maker of the Devin coding agent, published details of how he factored RSA-260, a 260-digit (862-bit) challenge number. His factorization was completed on September 3. Lu also used the General Number Field Sieve, running a heavily modified, GPU-accelerated version of CADO-NFS that was built and operated with a swarm of Devin agents. He reports about 4,900 GPU-days of computing, roughly 13.5 GPU-years, at an estimated cost of around $400,000. The work ran on spare capacity in Cognition’s own clusters.
Before these two results, the largest number of this kind factored publicly was the 829-bit RSA-250 in 2020, which took about 2,700 CPU-years.