Science1 distinct publisher2 min readPublished
Eric Lu published a 130-digit factor of RSA-260. Anyone can confirm it divides evenly. The method behind it is still undescribed, and that method is the part that would say anything about deployed key sizes.
The Scientist · Science desk
Compiled by The ScientistSomething wrong?How this is made
Follow any of these and your For You feed starts watching them — no settings page required.
build
Cognition's $47bn ask prices Devin at about 94 times its own run rate1 distinct publisher
leadership
Slack Code makes the chat window a coding surface, and a platform call for engineering leaders1 distinct publisher
build
SpaceX went shopping for a second AI coding company five days after closing Cursor2 distinct publishers
build
Devin now rents its execution: Cognition keeps the brain, Modal supplies the machines1 distinct publisher
Start with the shape of the number. RSA numbers take their names from their length in base ten, so RSA-260 runs to 260 digits [1], and the string posted on X accounts for exactly half of them [1]. Subtract, and the other prime factor has to run to roughly 130 digits as well [2]. Two secret primes of comparable size is the configuration RSA's security argument rests on [2], so this was an instance of the hard case: two roughly equal, unknown primes multiplied together, which is what makes factoring difficult in the first place.
About the how, there is very little. Lu has offered a claim, apparently in jest, that nothing more than "good old paper and pencil" went into it [5], which Scientific American calls inconceivable at this size [14]. The magazine's own reconstruction is that he sampled primes and divided them out of RSA-260 one at a time until one went evenly [6]. That description assumes a method; it does not document one. The difference matters more here than the record does.
It matters because the only quantity in the story with a named researcher behind it is a cost estimate, and cost estimates are what migration schedules are built from. Thomé's ratio was offered for one step, 250 digits to 260 [13]. Extrapolate it, which is more than he did: at three times per ten digits, thirty more digits would cost about 27 times as much [4]. Ten digits is what the record actually moved since 2020 [3]. Converting that into a date for your own key sizes is arithmetic the evidence does not carry.
The list is worth remembering for what it was. The RSA cryptosystem dates to 1977, and the company of the same name published these numbers in 1991 as a paid challenge whose contest closed well over a decade ago [9]. What remains is a scoreboard. A factoring result becomes a budget input in one of two ways: a published technique whose cost curve improves for everyone, or a factorization at a size someone is actually running. Neither is on offer yet, though the effort behind the result is substantial. Seven months of grinding is seven months of grinding, and Lu has form with long division: in 2019 he found a factor of a Mersenne number and knocked it off the prime list [15].
Until someone publishes the method, the strongest statement the evidence supports is that a hard-case 260-digit number now has one known factor. That belongs on a leaderboard, not in a line item.
Ranked by verification strength, evidence, and original report placement.
The number Lu factored is the largest RSA number ever cracked, though it is tiny in comparison with the RSA numbers used for modern cryptography.
Eric Lu, an engineer at the AI startup Cognition, posted a sequence of 130 digits on X early Thursday morning followed by the words "divides RSA-260".
RSA numbers are numerical strings created by multiplying two huge secret prime numbers; encryption uses the product and decryption requires the specific primes, so factoring amounts to decryption. Conventional thinking holds that bigger factor primes make the multiplication harder to undo.
Confirming Lu's achievement is as simple as entering the known RSA-260 number in a calculator and dividing by the 130-digit string he provided; cracking such problems is computationally difficult but checking a proposed answer is easy.
Lu has offered very few details about how he found the prime, other than a dubious claim, perhaps made in jest, that nothing more than "good old paper and pencil" was involved.
Scientific American presumes Lu's unclear methodology boiled down to randomly sampling primes and dividing them one by one from RSA-260 until one divided evenly.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 4, 2026
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Self-checking result, hearsay backstory
The fact at the centre needs no trust: divide RSA-260 by Lu's 130 digits and the claim stands or collapses on the spot, which is a stronger footing than most single-outlet stories ever get. Everything wrapped around it is thin by comparison — the seven months and the "by hand" gloss come from an unnamed engineer at Lu's own employer, the sampling method is the outlet's presumption rather than Lu's description, and Lu and Cognition both declined to answer questions.
A record, not a deployment
Nothing has been taken up, and that is the finding rather than a gap. What exists is a post and a divisor. Real RSA keys run to at least about two thousand bits, more than twice the length of RSA-260, and this reporting records no product, protocol or key policy moving in response — the previous record, six years old, moved nothing either.
Alarm outruns ten digits
The overstatement is in the verb, not the reporting. "Cracked" plus the worldwide excitement the post generated invites the reading that something broke; the substance is a ten-digit step that a researcher from the team it surpassed calls certainly feasible, if not low-hanging fruit. Scientific American does most of the deflating itself, and loses only a little of it by leaving the pencil-and-paper line in play for a paragraph before declaring hand computation inconceivable.
The only witnesses work there
Look at who is describing the work. An engineer at Cognition did it, another engineer at Cognition supplies the timeline, and Cognition sells an AI engineer, Devin, which the outlet says gave conflicting accounts of the same event. The insistence that no AI was involved cuts against a simple promotional read, but the sole narrative detail still originates inside one company that will not take questions, and the only outside voice comes from the group whose record was just beaten.
One outlet, one division
A single publisher, working without the participation of the person at the centre, is normally a reason to hold back. Here the arithmetic props it up: the risk is not that the record is wrong, it is that how it was set could still turn out to be something other than months of patient sampling — and that difference is the only part with any bearing on deployed key sizes.