On September 3, 2026, Cognition engineer Eric Lu announced that his company's coding agent, Devin, had done something no one had managed in 35 years: factor RSA-260, an 862-bit number that had sat unsolved on the RSA Factoring Challenge list since 1991. The number itself isn't secret — factoring challenge numbers were published specifically so people would try to break them — but the way this one fell is what's kept the story circulating for weeks. Lu didn't assemble an international research team or borrow a supercomputing grant. He spent roughly $400,000 on GPU time and let an AI agent build the software that did the math.
What RSA-260 Actually Is (and Why It Sat Unsolved for 35 Years)
RSA-260 is a 260-digit, 862-bit semiprime — a number that is the product of exactly two prime numbers — released by RSA Laboratories in 1991 as part of the original RSA Factoring Challenge. The challenge was designed to give cryptographers a public, standardized way to measure how hard it actually is to break RSA encryption at various key sizes, by offering numbers of increasing size for anyone to try to factor.
The Last Big Holdout
Most of the smaller challenge numbers fell years ago. The largest one solved before RSA-260 was RSA-250, an 829-bit number factored in February 2020. That made RSA-260 the largest publicly unfactored RSA challenge number for more than six years — a gap that reflected just how steeply the computational cost rises with each additional bit, not a lack of interest in trying.
Devin's team confirmed the result the way any factoring claim has to be confirmed: both resulting factors are 130-digit primes that pass standard primality tests, and their product matches the originally published RSA-260 value exactly.
What Devin Actually Did — And What Eric Lu Actually Did
The algorithm behind the break wasn't new. Factoring RSA-260 required the General Number Field Sieve (GNFS), the same method used on every RSA challenge number for decades, run through a GPU-optimized pipeline. What Cognition is actually claiming credit for is that Devin — not a team of number theorists — designed, built, and tuned that GPU implementation, including the polynomial selection stage, the lattice sieving stage, and the final linear algebra step needed to extract the factors.
The Numbers Behind the Headline
The total computational bill came to roughly 4,900 GPU-days, or about 13.5 GPU-years, run on a mix of Nvidia B200, GB200, and GB300 chips — hardware that didn't exist when RSA-250 was factored in 2020. Lu's own breakdown of the pipeline shows where that time went:
- Polynomial selection: 643 GPU-days
- Lattice sieving: 3,813 GPU-days (the bulk of the work)
- Linear system solving: 467 GPU-days
At current market GPU rates, Cognition estimates that adds up to about $400,000, and Lu frames the whole approach as roughly 10 times cheaper than the prior public state of the art for GNFS at this scale. The entire effort, from Lu's first prompt to Devin to a completed factorization, took about three weeks.
82,702 Words: The Human Half of the Story
The part of the announcement that's easy to skip past is how much human steering this took. Lu says he exchanged 82,702 words across 3,328 messages over 192 sessions with Devin — setting goals, benchmarking performance, redirecting the agent away from unproductive approaches, and organizing the experiments. That's not "an AI cracked encryption on its own" — it's an experienced engineer using an agent as a very fast, very tireless collaborator on a problem that still required real domain judgment to steer. Lu's own framing is more modest than the headlines: Devin, he says, proved to be "a sufficiently powerful software engineer" to execute on a hard problem at the intersection of computational number theory and GPU performance engineering — not a replacement for the person deciding what to build.
How RSA-260 Stacks Up Against the Last Record
The most useful comparison isn't RSA-260 versus nothing — it's RSA-260 versus RSA-250, the last time anyone pushed this frontier. The two efforts look almost nothing alike operationally, even though the underlying math problem is only modestly harder.
| RSA-250 (2020) | RSA-260 (2026) | |
|---|---|---|
| Key size | 829 bits / 250 digits | 862 bits / 260 digits |
| Who did it | Multi-person international research team | One engineer (Eric Lu) directing the Devin agent |
| Compute used | ~2,700 CPU core-years | ~4,900 GPU-days (~13.5 GPU-years) |
| Hardware | CPU clusters | Nvidia B200 / GB200 / GB300 GPUs |
| Time from start to prompt-driven build | Extended academic collaboration | ~3 weeks |
| Estimated dollar cost | Not publicly disclosed (academic/institutional compute) | ~$400,000 at market GPU rates |
The headline number Cognition wants you to take away is the cost efficiency: an order-of-magnitude drop in what it takes to push the factoring frontier, achieved mostly through modern GPU hardware and an agent doing the systems-engineering grind rather than a large human team doing it by hand.
What This Actually Means for RSA-1024
This is where the real debate is, and it's more nuanced than "RSA is broken." Lu himself provided the extrapolation: factoring a 1,024-bit RSA key would require roughly 78 times more computation than RSA-260 took, which he estimates would cost around $30 million at today's GPU prices. Hacker News commenters doing their own back-of-envelope math landed in a similar range, estimating RSA-1024 at somewhere between 50 and 100 times harder than RSA-260 — different methods, same ballpark.
Where RSA-1024 and RSA-2048 Actually Stand
| RSA-260 (now broken) | RSA-1024 | RSA-2048 | |
|---|---|---|---|
| Key size | 862 bits | 1,024 bits | 2,048 bits |
| Relative compute vs. RSA-260 | 1x (4,900 GPU-days) | ~78x by Lu's estimate | ~a billion times harder than RSA-1024, per Lu |
| Estimated cost to factor | ~$400,000 (done) | ~$30 million (Lu's estimate) | Not meaningfully affected by this work |
| Where you'd still find it | Historical challenge number only | Legacy certificates, older embedded/IoT systems, some aging infrastructure | Current baseline for TLS, SSH, and PGP keys |
$30 million is real money, but it's within reach of a well-funded corporation or a nation-state — which is exactly why RSA-1024 has already been phased out of new deployments for years by organizations that take this seriously. It's also why this result reads less like "the sky is falling" and more like "the long-known deprecation of RSA-1024 just got a fresher, more concrete price tag attached to it." RSA-2048, by contrast, isn't in the conversation: Lu's own estimate puts it roughly a billion times harder than RSA-1024, putting it well outside anything GPU-driven GNFS scaling threatens in the foreseeable future.
The Skeptic's Case, Straight From Hacker News
"This Isn't a New Algorithm"
The most repeated pushback in the Hacker News thread on the announcement was that nothing algorithmically new happened here. Commenters pointed out that GPU-accelerated sieving tools for GNFS already existed before this project, and that Devin's contribution was building and tuning an implementation of known techniques rather than inventing a faster way to factor numbers. One commenter noted that if an AI agent had actually found a mathematical shortcut to factoring, "that would be the headline, not RSA-260 was factorized" — the story is an engineering and cost story, not a cryptographic breakthrough.
Who Already Has This Capability
The other strand of debate was about who could already do this without an AI agent's help at all. Several commenters argued that well-resourced nation-states have likely had RSA-1024-breaking capability for years, using dedicated hardware and classified budgets that dwarf a public $30 million estimate — meaning the real value of Cognition's result isn't that it makes something newly possible, but that it makes the cost of doing it publicly visible and reproducible by a much smaller set of people than before.
What It Means for the Passwords and Keys You Actually Use
Here's the part that gets lost fastest in headlines like this one: RSA factoring has essentially nothing to do with the passwords you type into websites. Your account password isn't RSA-encrypted — it's typically run through a hashing algorithm like bcrypt or Argon2, which is a completely different mathematical problem that GNFS doesn't touch at all. What RSA-260's factoring actually threatens, in the far future and at real cost, is systems that still rely on short RSA keys for encryption or digital signatures: aging TLS certificates, legacy VPN configurations, old PGP keys, and embedded or IoT devices that were never updated past RSA-1024.
For almost anyone reading this, the practical keys protecting your traffic today are already RSA-2048 or larger, or have moved to elliptic-curve cryptography entirely — neither of which this result touches. The people who should actually be checking their configuration are system administrators maintaining older infrastructure: if you can confirm your certificates, SSH host keys, and signing keys are RSA-2048 or better (or on ECC), this announcement changes nothing for you operationally. If you're not sure what key size something is still running on, that's the concrete, actionable takeaway from a story that otherwise reads more dramatic than it is.
The more durable story here may not be about RSA at all — it's about how far the cost of highly technical, previously specialist-only computational work can drop when an agent can be pointed at weeks of GPU-engineering grind and left to iterate. Whether that trend shows up next in cryptanalysis, drug discovery, or chip design, the RSA-260 result is a data point worth remembering, not a verdict on RSA's remaining lifespan.
-EditorZ
Photo by Kevin Ache on Unsplash

Post a Comment