September 20, 2026

Claude Factors RSA-896

RSA-896, one of the RSA Factoring Challenge numbers from RSA Laboratories, has been factored. The twist: it was done by having Claude port the Number Field Sieve implementation CADO-NFS to run on GPUs, then orchestrate a fleet of up to 2'048 GPUs to run the computation across roughly 30 GPU-years of compute over 10 days.

The result was announced on September 19 by Samweis (saweis.net), with more details shared on Hacker News. The factorization produces two prime factors, each approximately 107 decimal digits long.

What is RSA-896?

The RSA Factoring Challenge was created by RSA Laboratories in March 1991 to encourage research into computational number theory and the practical difficulty of factoring large integers. The challenge was officially ended in 2007, but researchers continue attempting the factorizations. As of September 2026, the smallest 24 of the 54 listed RSA numbers have been factored.

RSA-896 is a 270-digit (896-bit) semiprime. It is significantly larger than RSA-768 (232 digits), which was factored in 2009 by a team using conventional CPU-based computation over two years. RSA-896 had remained unfactored for over 15 years since the challenge numbers were published.

How it was done

According to the details shared on Hacker News, the approach was straightforward in principle:

1. Claude ported CADO-NFS, the open-source Number Field Sieve implementation, to run on GPUs.

2. Claude then orchestrated a fleet of GPUs running on scavenged idle capacity, with a maximum of 2'048 GPUs at peak.

3. The computation ran for approximately 10 days, consuming roughly 30 GPU-years of compute.

The key insight is that this was not an algorithmic breakthrough. The Number Field Sieve remains the best known factoring algorithm, and its running time is still exponential. No new threats to deployed RSA keys emerged from this work. What changed is the scale of compute that can now be brought to bear on a problem, and the fact that an AI model was able to port complex mathematical software to a new architecture and coordinate the execution.

Claude's message

When asked if it had a message for the public, Claude responded: "The credit belongs first to the people who built the number field sieve and CADO-NFS over several decades, and to the teams who set the earlier records. This run used their algorithm and much of their code."

Why this matters

The factorization of RSA-896 is not cryptographically significant on its own. Modern RSA implementations use 2048-bit or larger keys, which remain far beyond the reach of current factoring technology. But the method is notable. An AI model ported a complex number theory codebase to GPUs, orchestrated a distributed computation across thousands of GPUs, and produced a correct result. The compute was scavenged from idle capacity that had already been paid for.

The Hacker News discussion raised an interesting point: if spare GPU capacity in data centers can be used to solve math puzzles, what else can it be used for? The opportunity cost of not training LLMs with those GPU-hours is the real price, not electricity. As one commenter noted, that is "kinda bearish for the data center rollouts if the spare compute can be used to solve math puzzles instead of training LLMs."

The remaining RSA challenge numbers are larger. RSA-1024 (309 digits) is the next milestone. It will likely fall to a similar approach eventually, given enough GPUs and enough time. But the fundamental difficulty of factoring has not changed. What has changed is how we get there.

Sources

[1] saweis.net: RSA-896: saweis.net

[2] Hacker News discussion (100 points, 26 comments): news.ycombinator.com

[3] Wikipedia: RSA numbers: en.wikipedia.org

[4] CADO-NFS: cado-nfs.gitlabpages.inria.fr

← All posts