In March 1991, RSA Laboratories published a 260-digit number with a cash prize for anyone who could factor it into two primes. The bounty program ended in 2007, but the number—RSA-260—remained unfactored for 35 years. On September 3, 2026, at 01:48 UTC, it was finally split into two 130-digit primes whose product exactly reproduces the original. FactorDB now shows status FF (fully factored). The people behind it: Cognition researcher Eric Lu and his Devin, the signature AI coding agent from the company of the same name. Cognition published the methodology on September 9, 2026.
First, the important clarifications: no quantum computer was involved, and there was essentially no algorithmic advancement. Ledger CTO Charles Guillemet stated plainly that no quantum computer was involved, and Eric Lu's blog describes the work as "essentially no algorithmic advancements"—just "good old performance engineering" on top of the General Number Field Sieve (GNFS), moving several bottlenecks onto GPUs. Conventional engineering accomplished what 35 years of effort had not. That is the real story here.
The math: multiplying is easy, un-multiplying is not
Multiplying two large primes takes a second; recovering the primes from the product is a different order of difficulty entirely. All RSA encryption bets on this asymmetry. GNFS is the fastest known classical method for such factorizations, running in four relay stages:
1. Polynomial selection — 643 GPU-days; one candidate chosen from 83.55 million 2. Lattice sieving — 3,813 GPU-days (7.9 days wall-clock); 13.85 billion raw relations, 8.3 billion after deduplication (~80% of total cost) 3. Linear algebra — 467 GPU-days; a 656M × 656M sparse matrix with 98.4 billion nonzero entries 4. Square root — after three Devin rewrites, GPU NTT produced the factors in 88 minutes
Total wall-clock time for RSA-260 was 15.6 days. The methodology in one sentence: deeply modify CADO-NFS (the open-source INRIA tool behind the RSA-240 and RSA-250 records) and move everything possible onto GPUs. The CPU lattice sieve las was replaced by a GPU version glas, exploiting GPU memory bandwidth for the pseudo-random array accesses; linear algebra used a GPU block Wiedemann saturating NVLink and InfiniBand; polynomial selection borrowed optimized kernels from msieve.
Division of labor between human and agents
At 00:11 PT on August 13, 2026, Eric Lu gave Devin its first instruction: build a drop-in GPU replacement for CADO-NFS's CPU lattice sieve. Then he went to sleep. By the time he woke up, Devin had iterated for another 7 hours on its own and the GPU version already beat the CPU version.
Over the next three weeks: 233 Devin sessions, peaking at 18 concurrent, of which 101 were sub-sessions Devin opened itself and 36 ran fully without human intervention. Eric sent 3,328 messages (82,000 words) and spent 14,450 ACU. His self-described role: setting goals, building benchmarks, and correcting drift—admitting his understanding of these components is roughly that of "a mid-level car enthusiast" with limited grasp of the underlying math.
Before attacking RSA-260, the team warmed up on C155, C157, C173, C175, C190, and C201 (including two fully randomized control numbers), cutting 190-digit factorization time from 11,443 seconds to just over 3 hours.
The numbers
| Record | Date | Bits | Compute | Who | |---|---|---|---|---| | RSA-250 | Feb 2020 | 829 | ~2,700 CPU core-years | Boudot et al. (6 people) | | RSA-260 | Sep 2026 | 862 | ~4,923 GPU-days ≈ 13.5 GPU-years ≈ $410K | Eric Lu + Devin |
Moving from RSA-250 to RSA-260 added only 33 bits but roughly tripled the difficulty (by RSA-250 team member Thomé's estimate, "roughly three times"). Notably, RSA-240 fell in November 2019 and RSA-250 in February 2020, then nothing for six years. A key cost saver: the GPUs were idle fragments of Cognition's own training cluster—leftover capacity the scheduler couldn't assign to main tasks. Lattice sieving splits naturally into 632,499 small tasks of about ten minutes each, preemptible at will—a perfect fit for idle LLM-cluster capacity.
A textbook-grade hoax
Before the methodology was published, a rumor circulated that RSA-260 had been factored "by hand." Eric's colleague Sean joked that Eric had spent his 7 months at the company hand-computing random primes—effort beating talent. Aggregator accounts took it seriously, and Scientific American's September 4 report relayed it half-doubtingly with an absurd "at least 7 months of calculation" estimate. Cognition's September 9 blog debunked it: contrary to the lore, he did not do it by hand-computing 130-digit primes, and Cognition has not built a multi-thousand-bit quantum computer. SciAm subsequently added an editor's note. A news story about AI, and the first thing to fail was the human information chain. Fitting.
Do you need to rotate your RSA keys?
No. Eric's own estimate: factoring one RSA-1024 key costs roughly $30 million at current prices—within reach of hyperscale cloud providers and frontier AI labs (though NIST has banned 1024-bit RSA for new systems since 2013; this news just put a price tag on an old warning). RSA-2048 is roughly 91.2 billion times harder than RSA-1024, and per the blog it "does not appear to be meaningfully affected by this work." Your 2048-bit key is the same key it was before.
On the quantum side: the largest number reliably factored by Shor's algorithm on real quantum hardware remains 21 (= 3 × 7). The classical record moved forward another notch; quantum computing is still standing in 2012.
Caveats, stated openly
- No algorithmic innovation—the author says so himself. The real foundation is years of open-source CADO-NFS accumulation; Lu even speculates the codebase appears extensively in pretraining corpora, helping the agents (the further a codebase is from upstream CADO-NFS, the more confused the agents get).
- The sieve and other implementations were not open-sourced as of September 10, so the 4,900 GPU-day efficiency claims cannot yet be independently verified.
- Cognition is Devin's developer, so the blog has inherent product-demo motives. That said, it candidly reports failures—643 GPU-days on polynomial selection (self-mockingly attributed to "operator incompetence") and 7% of linear-algebra compute lost to crashes and preemption. A blog willing to print ugly numbers earns credibility.
- Cognition methodology blog (Eric Lu, 2026-09-09): https://cognition.com/blog/factoring-rsa-260
- Scientific American (2026-09-04, editor's note added 9-9): https://www.scientificamerican.com/article/whats-the-tech-behind-the-record-breaking-rsa-260-crack/
- Senthorus security analysis (2026-09-06): https://blog.senthorus.ch/posts/rsa_260_factorization/
- lilting.ch technical walkthrough (2026-09-04): https://lilting.ch/en/articles/rsa-260-factored-how-computed
- FactorDB entry (status FF): https://factordb.com/index.php?id=1100000000104374167
- RSA-250 record announcement: https://caramba.loria.fr/rsa250.txt
A fitting HN comment: this may be the first "I had an agent swarm do a thing" blog post that was actually written by a human.
Wrap-up
A cold case from 1991 was closed 35 years later by one human directing a team of agents: $410,000, three weeks. The foundations of cryptography are unmoved—RSA-2048's math checks out. What is shaking is something else: how far pure engineering optimization can go when a trained agent cluster is paired with a person who knows what to watch. Three weeks ago, this problem had no answer.
Sources: