Quantum Security & PQC

RSA-896 Factored With Claude on Spare GPUs, 16 Days After RSA-260

September 19, 2026 – Stephen A. Weis, a member of technical staff at Anthropic, published the two prime factors of RSA-896, a 270-digit, 896-bit number from the RSA Factoring Challenge. The factorization, done with Anthropic’s Claude model on a fleet of up to 2,048 GPUs running between other jobs, makes RSA-896 the largest challenge number factored in public.

Weis wrote that Claude ported the open-source CADO-NFS factoring software to run on GPUs and orchestrated the computation. The job took about 10 days and roughly 30 GPU-years of compute, according to Weis, who wrote that he had not meaningfully improved the running time of the general number field sieve (GNFS). He added that deployed RSA-2048 keys are unaffected but that RSA-1024 keys are now vulnerable to many organizations with data-center GPU fleets.

RSA-896 is the second RSA challenge record in 16 days. On September 3, Eric Lu of Cognition published a factor of the 862-bit RSA-260 and later described a GPU version of CADO-NFS that Cognition’s Devin agent built and ran on idle cluster capacity. Lu estimated that a hyperscaler could factor RSA-1024 for about $30 million.

The result can be checked in seconds. Each of Weis’s two published primes has 135 digits and 448 bits, both pass primality tests, and their product equals the RSA-896 value on the public challenge list.

Before September, the record was the 829-bit RSA-250, factored in February 2020 by Fabrice Boudot, Pierrick Gaudry, Aurore Guillevic, Nadia Heninger, Emmanuel Thomé and Paul Zimmermann using CADO-NFS on CPUs, at a cost of about 2,700 core-years. RSA Laboratories ended the challenge in 2007. The prize for RSA-896 was $75,000.

Weis earned his PhD at MIT under Ron Rivest, co-inventor of RSA, according to his website. He worked on security and privacy at Google, Facebook and Databricks before joining Anthropic’s Secure Frameworks team.

In July, Weis and Anthropic colleague Zygimantas Straznickas published a key-recovery attack on HAWK, a lattice-based candidate in NIST’s additional post-quantum signature process, which Anthropic said was developed with its Claude Mythos Preview model. The HAWK team withdrew the scheme the following day. Weis also wrote a preprint, dated August 2026, on extracting the secret key from the Classic McEliece computation behind a recent distinguisher; a note on its first page says it was prepared with Claude.

Weis’s announcement consists of two paragraphs and the numbers, and he wrote that more details would follow. He did not name the GPU model or the version of Claude. He also did not say how the work divided between him and the model, which GNFS stages moved to GPUs, or whether the code will be released.

In a series of posts on X, Weis wrote that the fleet ran on idle capacity and that he had made no new algorithmic improvements to factoring. He asked Claude whether it had a message for the public. Claude gave the credit to the people who built the number field sieve and CADO-NFS and to the teams behind the earlier records.

My Analysis

Two AI-assisted RSA challenge records in 16 days, after none in six and a half years, is a real change in what it costs to run the number field sieve at scale. The sieve is the same algorithm the RSA-250 team used in 2020, and RSA-2048 is no closer to being broken. Both records were set on GPUs, so neither is evidence that a cryptographically relevant quantum computer exists.

Why the Jump From RSA-260 to RSA-896 Is Smaller Than It Looks

The classical factoring record went from 829 bits to 862 bits to 896 bits in 16 days. That looks like an acceleration, and some of the reaction on X has treated it as one. The records did come faster. Each one still cost about what the standard GNFS scaling curve predicts, and nothing about that curve has changed.

RSA-260 is 862 bits. RSA-896 is 896 bits. The difference between them is 34 bits, almost exactly the same as the 33-bit gap between RSA-250 and RSA-260. Under the standard GNFS scaling heuristic, 34 extra bits of key length cost about 2.6 times the computation. Weis’s 30 GPU-years is 2.2 times Lu’s 13.5 GPU-years, close to that ratio.

Two teams set the two records in the same month by porting CADO-NFS from CPUs to GPUs. Lu and Devin built the first GPU lattice siever used for a public factoring record. Once a GPU pipeline works, moving it to a slightly larger number is incremental. Weis and Claude built a second GPU port, apparently independently, and ran it on Anthropic’s idle capacity. Both records came from GPU code written by AI agents. The hard step was the first GPU siever that beat the CPU, and Devin had one working in about nine hours.

The coverage so far has been mixed. Crypto Briefing wrote that Claude helped Weis explore the parameter space of the computation, a claim that does not appear in his announcement or his posts on X. LavX News described the primes as roughly 320 digits each. They are 135 digits. LavX also wrote that Weis disclosed no computational setup. He disclosed 30 GPU-years, 10 days, up to 2,048 GPUs and idle capacity.

How Far RSA-2048 Still Is

RSA-896 is 896 bits. RSA-2048 is 2,048 bits. The gap between them is 1,152 bits, compared with 34 bits between RSA-260 and RSA-896. Under the same scaling heuristic, RSA-2048 requires about 35 billion times the work of RSA-896.

Weis’s run took 10 days on up to 2,048 GPUs. At the same efficiency, 2,048 GPUs running without a break would need about 190 billion days to factor RSA-2048, or roughly 510 million years.

In GPU-years, RSA-2048 comes to about a trillion at Weis’s rate of 30 GPU-years per RSA-896. At $3.50 per GPU-hour, the bill would be about $32 quadrillion. No fleet of GPUs will produce that, and no improvement to GPU sieving will close a gap of 35 billion.

RSA-2048 is about 34 more steps of 34 bits beyond RSA-896. At one record every 16 days, those steps would take about a year and a half. They cannot come at that pace, because each step costs a multiple of the one before: 2.6 times for the step from RSA-260 to RSA-896, and still about 1.8 times for the last step before 2,048 bits. At Weis’s efficiency, the next record after RSA-896 would cost about 75 GPU-years, the tenth about 150,000, the twentieth about 200 million and the thirty-fourth about a trillion.

The record moved from 829 to 896 bits in a month. Moving the next 1,152 bits to 2,048 is a different kind of problem. Whoever eventually breaks RSA-2048 will use Shor’s algorithm running on a CRQC. The resource estimate I use is Craig Gidney’s from May 2025: fewer than a million noisy physical qubits, under a week, at a 0.1% gate error rate and a one-microsecond error-correction cycle (arXiv:2505.15917). No machine with those specifications exists.

Checking Weis’s Account Against Lu’s

Lu’s write-up gave a full accounting: timelines for each stage, the polynomial, the matrix dimensions, the session counts between him and Devin. Weis’s announcement is two paragraphs. I multiplied his two primes and got RSA-896, and both pass a primality test. Everything beyond the factors themselves is his account: 30 GPU-years, 10 days, 2,048 GPUs, Claude’s role in the port. Until he publishes the promised details, the only support for those figures is his name and his track record, which is substantial.

The figures are consistent with what I would expect. RSA-896 costs about 2.6 times RSA-260 under GNFS scaling. Lu spent 13.5 GPU-years on RSA-260; 2.6 times that is about 35 GPU-years, and Weis reported 30. The gap between 35 and 30 GPU-years could reflect different GPU models, a more efficient port, or both, and Weis has not disclosed the hardware.

If Weis’s account holds, a second team at a second company, using a different AI agent, stood up a GPU GNFS pipeline and factored a larger number 16 days after the first record. That would be a second data point that an AI coding agent and a pool of idle GPUs can run the number field sieve at a scale that was, until August, the domain of specialist academic teams working for months.

Five things remain missing from Weis’s account:

  • Which GPUs he used and how many hours each stage consumed.
  • Which version of Claude wrote the port, and how the work divided between Weis and the model. Lu published his message and session counts; Weis has not published a comparable account.
  • Which GNFS stages moved to GPUs. At Cognition, the linear algebra and the square root moved as well as the sieving.
  • Whether the code will be released.
  • Whether the port was written independently of Cognition’s. If it was, that is stronger evidence about what these tools can do than either record alone.

One of the clarifications Weis posted on X, “no new threats to deployed keys,” is accurate for RSA-2048 and too reassuring for the 1,024-bit keys I described in my RSA-260 analysis.

What Changes for RSA-1024

RSA-1024 costs about 30 times RSA-896 under the same heuristic. At Weis’s efficiency, that is about 900 GPU-years, or roughly $28 million at $3.50 per GPU-hour. Lu’s estimate, scaled with the same heuristic from his RSA-260 run, was about $30 million. The two figures agree because Weis’s 30 GPU-years came close to the 35 I get by scaling Lu’s run with the same heuristic.

A run of 900 GPU-years on 2,048 dedicated GPUs would take about five months of wall-clock time. On 20,000 GPUs it would take about two weeks.

I covered the practical exposure of RSA-1024 keys in my RSA-260 analysis: DKIM selectors, recorded TLS sessions that used RSA key transport, and firmware-verification keys burned into devices. The two September records do not create that exposure. NIST disallowed 1,024-bit RSA for new protection in 2014. What the records change is the list of organizations that could pay for a factorization and the price they would pay. That list now includes any company with a data-center GPU fleet and a line item in the tens of millions.

Cryptographic Results Credited to AI Since July

Between late July and mid-September, researchers using AI tools from three companies received credit for at least five cryptographic results. Anthropic credited Claude Mythos Preview with the HAWK key-recovery attack and with an improved attack on seven-round AES-128. In the same NIST forum discussion, Hengyi Luo attributed a separate HAWK attack to OpenAI’s GPT-5.6. Cognition’s Devin then received credit for the RSA-260 factorization, and Claude for RSA-896.

I covered the July results as a change in what it costs to find a flaw in an algorithm, and in August I described the competing disclosures from OpenAI and Anthropic about AI agents breaking into real systems as theater around real capabilities. An 896-bit record from Anthropic’s fleet, 16 days after Cognition’s record, is hard to read outside that competitive pattern, although Weis’s own post is restrained. Motive aside, the factors are correct, and anyone can confirm that in seconds by multiplying them.

What to Do

I stand by the action list I published with the RSA-260 analysis:

  • Find every RSA key below 2,048 bits.
  • Rotate DKIM keys.
  • Assume recorded RSA-1024 sessions are readable.
  • Isolate devices with unrotatable firmware keys.
  • Leave the post-quantum roadmap alone.
  • Fund crypto-agility as its own workstream.

RSA-896 confirms that list without adding to it. Two teams, at Cognition with Devin and at Anthropic with Claude, have now built GPU factoring pipelines, and the second set a record 34 bits above the first 16 days later. The next record will come from whoever has idle GPUs and a researcher who knows what to point them at. Whether the next number is RSA-1024 or something in between depends mostly on ambition and budget. The main engineering exception is the linear algebra, which needs all of its workers running at once and so cannot run on idle capacity. For RSA-1024, by my rough scaling, that stage alone means a dedicated block of tightly networked GPUs for weeks.

The vendor who cites these records to sell quantum-safe urgency is selling on the wrong evidence. The case for post-quantum migration is the one that existed on September 2: the timeline to a CRQC is uncertain, and migration takes years. Regulators have already set their deadlines. What September’s records change is the classical cost of attacking RSA-1024, and anyone still running 1,024-bit keys should treat that as the cheapest item on their migration punch list.

Marin Ivezic

I am the Founder of Applied Quantum (AppliedQuantum.com), a research-driven consulting firm empowering organizations to seize quantum opportunities and proactively defend against quantum threats. A former quantum entrepreneur, I’ve previously served as a Fortune Global 500 CISO, CTO, Big 4 partner, and leader at Accenture and IBM. Throughout my career, I’ve specialized in managing emerging tech risks, building and leading innovation labs focused on quantum security, AI security, and cyber-kinetic risks for global corporations, governments, and defense agencies. I regularly share insights on quantum technologies and emerging-tech cybersecurity at PostQuantum.com.