# Claude factored RSA-896. Here is how RSA actually breaks

Published: 2026-09-21

On September 19 an Anthropic engineer factored RSA-896 — a 270-digit challenge number — with Claude, a GPU port of the open-source CADO-NFS sieve and ~30 GPU-years on 2,048 idle GPUs over ten days, sixteen days after Cognition's Devin did the same to RSA-260. Under the hood: how a factoring record is actually set (polynomial → sieving → a 656-million-row matrix → square root), why 896 bits fall and 2048 do not, and which of your keys should worry. Verdict: NEEDS REVIEW.

Canonical: https://thedailydiff.dev/video/2026-09-21-rsa-896-under-the-hood/

## What this video covers

- RSA-896 falls: 270 digits, 2,048 GPUs, ten days
- 1977 → 1994: forty quadrillion years, six hundred volunteers
- 2009 → 2020: one record per decade, all of it on CPUs
- Sep 2026: Devin, then Claude, two records in sixteen days
- The sieve: polynomial → sieving → a 656-million-row matrix → square root

## Chapters

- 0:00 RSA-896 falls: 270 digits, 2,048 GPUs, ten days
- 0:38 1977 → 1994: forty quadrillion years, six hundred volunteers
- 0:55 2009 → 2020: one record per decade, all of it on CPUs
- 1:10 Sep 2026: Devin, then Claude, two records in sixteen days
- 1:35 The sieve: polynomial → sieving → a 656-million-row matrix → square root
- 1:59 Why 2048 still holds: $30M for RSA-1024, $38 quadrillion for RSA-2048
- 2:24 Claim vs read: 'Claude broke RSA' vs 'no new algorithm'
- 3:04 Monday: ssh-keygen -l, your mail-signing keys, NIST's 2030 line
- 3:21 Verdict, under the hood

## Transcript

### RSA-896 falls: 270 digits, 2,048 GPUs, ten days

0:00 On Saturday an engineer at Anthropic factored RSA eight ninety-six, a two hundred seventy digit number meant to hold for a lifetime, with Claude and two thousand idle GPUs, which is the most expensive way ever found to confirm that your SSH key is probably fine. Three numbers. Thirty GPU-years in ten days. Seventy-five thousand dollars of prize money for this exact number, withdrawn in two thousand seven. And the price of doing it to the key on your laptop,

0:24 thirty-seven quadrillion dollars. In three minutes, how a factoring record is set, why the algorithm is a thirty-year-old sieve and not a chatbot, and which of your keys should worry. This is The Daily Diff, under the hood.

### 1977 → 1994: forty quadrillion years, six hundred volunteers

0:38 Nineteen seventy-seven. Martin Gardner prints a hundred twenty-nine digit number in Scientific American, and Ron Rivest estimates factoring it takes forty quadrillion years. It takes seventeen, six hundred volunteers and two fax machines, and the secret message is the magic words are squeamish ossifrage. Two thousand nine, RSA seven sixty-eight, two thousand core-years.

### 2009 → 2020: one record per decade, all of it on CPUs

0:58 Two thousand twenty, RSA two fifty, twenty-seven hundred core-years on an open-source sieve called Cado NFS, from a French lab. One record a decade, the pace of people with tenure.

### Sep 2026: Devin, then Claude, two records in sixteen days

1:10 Then September. Eric Lu at Cognition tells Devin, their coding agent, to port the sieve to GPUs and goes to bed. Three weeks and four hundred thousand dollars of spare cluster time later, RSA two sixty is done. Sixteen days later, Steve Weis at Anthropic repeats the trick with Claude. Six years between records, then two in a fortnight, one from a hobbyist with a coding agent, one from a cryptographer with spare GPUs. The mechanism. Four stages.

### The sieve: polynomial → sieving → a 656-million-row matrix → square root

1:36 Pick a polynomial. Sieve, which means hunting for billions of numbers with only small factors, each candidate independent, so that is the part that moved to GPUs. Then linear algebra, where eight billion relations become a matrix six hundred fifty million rows on a side, and every node talks to every other node until someone gets preempted. Then a square root, which Cognition's run overflowed and rewrote three times.

### Why 2048 still holds: $30M for RSA-1024, $38 quadrillion for RSA-2048

1:59 Why your two thousand forty-eight bit key is a different animal. The sieve is subexponential, so every extra bit costs less than a doubling, but it compounds. RSA ten twenty-four is seventy-eight times the work of RSA two sixty, call it thirty million dollars, couch money for a hyperscaler. RSA two thousand forty-eight is a billion times harder again, thirty-seven quadrillion dollars, which is Rivest's estimate with the unit changed from years to dollars.

### Claim vs read: 'Claude broke RSA' vs 'no new algorithm'

2:24 The claim versus the read. The headline says Claude broke RSA. Claude itself credits the people who built the sieve over decades, and Weis adds three lines. No new algorithm, still exponential, which he later corrected to subexponential, and no new threat to deployed keys. Both are true. The math did not move.

2:41 The price did, because idle GPUs plus an agent that ports old C to Cuda overnight turns a decade-per-record hobby into a long weekend. Hacker News says you do not need AI for this, just compute. True, until someone notes that Instagram still signs its email with a seven hundred sixty-eight bit key, which is now a weekend project. Best reply, from Allan Peng. Two is a factor of RSA eight ninety-six plus one.

### Monday: ssh-keygen -l, your mail-signing keys, NIST's 2030 line

3:04 Monday. Run ssh keygen dash L on your public keys, and anything that prints ten twenty-four is a twenty thirteen problem you kept. Dig your mail-signing records the same way. And read the Nist draft, because RSA two thousand forty-eight is deprecated after twenty thirty anyway, not for sieves, for qubits that do not exist yet

### Verdict, under the hood

3:21 either. Verdict, under the hood. Needs review. Two thousand forty-eight bits is fine. Seven hundred sixty-eight bits in your DNS is not, and the attacker no longer needs a lab, only spare GPUs and a chat window. Tell me what to open up next in the comments. And that's the diff for today. I'm Niko from Axrisi. Merge responsibly.

## Sources

- [Stephen A. Weis, "RSA-896" (N, p, q)](https://saweis.net/posts/rsa-896.html) — saweis.net
- [Weis on X — the run (2,048 GPUs, 30 GPU-years, 10 days)](https://x.com/sweis/status/2101488974418317736) — x.com
- [Weis on X — Claude's statement: https://x.com/sweis/status/2101492820028895607 · the three clarifications: https://x.com/sweis/status/2101494688528400792 · "GNFS is subexponential"](https://x.com/sweis/status/2101544544793972860) — x.com
- [Allan Peng: "2 is a factor of (RSA-896 + 1)"](https://x.com/apengwin/status/2101492866757361841) — x.com
- [Hacker News thread](https://news.ycombinator.com/item?id=49771966) — news.ycombinator.com
- [Eric Lu / Cognition, "Factoring RSA-260" (GPU siever, cost ladder, 656M-row matrix, sqrt rewritten 3×)](https://cognition.com/blog/factoring-rsa-260) — cognition.com
- [CADO-NFS (INRIA)](https://cado-nfs.gitlabpages.inria.fr/) — cado-nfs.gitlabpages.inria.fr
- [RSA numbers (RSA-129 … RSA-2048, prizes): https://en.wikipedia.org/wiki/RSA\_numbers · "The Magic Words are Squeamish Ossifrage"](https://en.wikipedia.org/wiki/The_Magic_Words_are_Squeamish_Ossifrage) — en.wikipedia.org
- [NIST IR 8547 (initial public draft), transition timeline](https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf) — nvlpubs.nist.gov
- [Instagram DKIM record](https://dns.google/resolve?name=pm._domainkey.instagram.com&type=TXT) — dns.google
