Skip to content

Build1 publisher3 min readPublished

Steve Weis factors RSA-896 in ten days with Claude and idle GPUs

Anthropic engineer Steve Weis factored the 270-digit RSA-896 in ten days with Claude and up to 2,048 idle GPUs. Cognition estimates that factoring one 1024-bit number costs about $30 million, a sum a hyperscaler could spend.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Steve Weis factors RSA-896 in ten days with Claude and idle GPUs
Generated illustration

What happened

  • RSA-896 comes from the old RSA Factoring Challenge, and no one had split it before Weis did on September 19.
  • Cognition had factored RSA-260 with a coding agent and spare GPUs sixteen days earlier, after six years in which no factoring record fell.
  • The algorithm is the decades-old number field sieve, and the new work was an AI agent porting the open-source CADO-NFS siever to GPUs.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • contradiction Weis's "No new threats to deployed keys" fits the explainer's warning on 1024-bit keys only if those keys already counted as weak. A team that read Weis alone could keep them in service.
  • capability Record-scale factoring now runs on leftover GPU capacity with a coding agent doing the porting, so the plausible attackers on a 1024-bit key include large operators with idle clusters as well as those who fund dedicated ones.
  • cost Cognition's figure is per number. An attacker pays it again for every 1024-bit key they want, and the total grows with each key targeted.

Once the modulus is factored, the private key follows from the key-generation math. Everything secret in RSA comes from the primes p and q, and recovering the private exponent takes two lines of Python [8]:

```python phi = (p - 1) * (q - 1) d = pow(e, -1, phi) # the private key ```

So the whole cost is in the factoring. The general number field sieve is the fastest known classical algorithm at this size [9]. It is subexponential, meaning each extra bit costs less than doubling the work, but the cost compounds [9]. Weis corrected an earlier post on X a few hours after making it. "Oops, GNFS is subexponential. Just trying to emphasize factoring is still as hard and this didn't improve the runtime," he wrote [10].

The speedup sits in one stage. Sieving is most of the work, and each candidate is independent of every other, so it moves to GPUs [11]. Linear algebra is one giant sparse matrix in which every node talks to every other node. It is the fragile, communication-heavy stage [12]. Eric Lu of Cognition, in his write-up of the RSA-260 run, wrote that he reports "essentially no algorithmic advancements" and credited "good old performance engineering" [13]. His Devin agents built what he called "the world's highest-performance GPU lattice siever", at about "10x lower cost than the previous public state of the art" [14]. I'd credit the write-up for claiming that much and no more. The siever builds on CADO-NFS, from INRIA and the Loria lab in Nancy, the same software behind the 2020 record [16].

The "up to" in "up to 2,048 GPUs" matters. At full occupancy, 2,048 GPUs for ten days is about 56 GPU-years [1]. The run used about 30 GPU-years [5]. The average works out near 1,100 GPUs, a bit over half the peak [2]. Lu's RSA-260 run likewise drew on "spare or fragmented compute", a single-digit share of the cluster [17].

Cognition's $30 million is an estimate for one 1024-bit number [6]. Two things have to hold for it to transfer to a given attacker. They need idle GPUs at a similar marginal cost. The linear algebra stage, which sits outside the siever, also has to behave at 1024 bits. For scale, RSA-2048 comes out about 1.3 billion times the 1024-bit price on the explainer's figures [3].

In my view, the 768-bit and 1024-bit keys the explainer calls not fine [19] should come out of SSH, TLS and DKIM now. I would make that call even if the $30 million estimate is off by a wide margin, because the siever got 10x cheaper through engineering alone [14].

What to watch

  • A public factoring of a 1024-bit RSA number, or a revised Cognition cost estimate below $30 million.
  • Published per-stage costs for the linear algebra step at 1024 bits, the stage the GPU siever does not cover.
  • A detailed RSA-896 write-up from Weis with per-stage numbers, comparable to Lu's RSA-260 logbook.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories