Back
SiTech
RSA-896 factored: Claude ported CADO-NFS to up to 2,048 GPUs
SiTech AI Team2 წთ. საკითხავი

RSA-896 factored: Claude ported CADO-NFS to up to 2,048 GPUs

Security researcher Stephen A. Weis says he factored RSA-896, a 270-digit challenge number from RSA Laboratories, on September 19, 2026, with Claude orchestrating the run across up to 2,048 GPUs.

Security researcher Stephen A. Weis has factored RSA-896, a 270-digit semiprime published by RSA Laboratories as part of the RSA Factoring Challenge, using Anthropic's Claude model to organise the computation on GPUs. The blog post is dated September 2026 and states that the factorisation was completed on September 19, 2026.

A 270-digit challenge number falls

RSA-896 belongs to the set known as RSA numbers: large semiprimes — numbers with exactly two prime factors — issued by RSA Laboratories in March 1991 to measure how hard integer factorisation is in practice. The challenge was ended in 2007 and the remaining prizes were withdrawn, but the numbers stayed public. Wikipedia's table of RSA numbers lists 54 entries and records that only the smallest 24 had been factored as of September 2026; RSA-896, at 896 bits and 270 decimal digits, was not among them. Weis published the number together with its two prime factors, p and q, and noted that more details will follow.

CADO-NFS moved to GPUs

The result does not rest on a new algorithm. Weis says Claude was used to port CADO-NFS — the open-source implementation of the General Number Field Sieve (GNFS) maintained by the French research institute INRIA — so that it could run on graphics processors. The model then orchestrated the job across a fleet of up to 2,048 GPUs, scheduled as a low-priority task that used idle time between regular jobs at Anthropic. The computation ran for ten days and consumed roughly 30 GPU-years of compute time.

What it means for deployed keys

Weis is explicit about the limits of the work: it did not meaningfully improve the runtime of GNFS, and it does not affect the security of deployed RSA-2048 keys. His conclusion is narrower and more practical — that RSA-1024 keys are vulnerable to many actors with data-centre-level fleets of GPUs. That is a statement about cost and access rather than a mathematical break: the barrier to a 1,024-bit factorisation has dropped to the level of a well-funded organisation that can spare idle accelerator time.

For engineers, the practical reading is the one Weis offers: key sizes below current recommendations deserve to be treated as migration work, while the 2,048-bit baseline remains safe.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.