September 21, 2026ยท5 min read

RSA-896 Was Factored on Spare Cycles

EN | DE

The largest RSA key ever publicly broken was broken in the gaps between other jobs. Stephen Weis, an engineer at Anthropic, published two 448-bit primes on Saturday. Multiply them and you get RSA-896, a 270-digit challenge number that RSA Security announced on May 23, 2001 with a $75,000 prize attached. Weis had Claude port CADO-NFS to GPUs and schedule it as a low-priority task on idle capacity. Ten days, a peak of 2,048 GPUs, about 30 GPU-years. I multiplied the factors. They check.

Today, two days later, NIST moves every FIPS 140-2 certificate to the Historical list.

FIPS 140-2 was signed on May 25, 2001. The number and the standard were born two days apart and went historical two days apart, twenty-five years later. Only one of those dates was on a calendar.

Spare Cycles

In 1977 Martin Gardner printed a 129-digit RSA modulus in Scientific American and Ron Rivest estimated 40 quadrillion years to factor it. It fell in 1994. Six hundred volunteers donated idle time on 1,600 machines, two of them fax machines, and mailed their results to a coordinator. The plaintext was “The Magic Words are Squeamish Ossifrage.” FIPS 140-1 was issued the same year.

Factoring records have always been set on leftovers. What changes is the size of the leftovers. In 1994 it was workstations overnight. In 2026 it is two thousand accelerators that a scheduler would otherwise leave dark between training runs. Nobody bought hardware to break RSA-896. Nobody rented any either.

The Math Did Not Move

Weis is explicit that the General Number Field Sieve got no faster. Same algorithm as the 1990s, same open-source implementation that set the last several records.

What moved is labor. RSA-250, at 829 bits, held the record from February 2020 until this month. Six and a half years. Then Eric Lu at Cognition factored RSA-260 at 862 bits on September 3 using a swarm of Devin agents to build a GPU lattice siever. Sixteen days later Weis took 896 with a different agent at a different company. Rewriting a tuned CPU research codebase for GPUs and babysitting it across a fleet used to require a handful of specialists who mostly knew each other. That scarcity was a security control nobody wrote down. It is gone.

1024

Run the GNFS complexity estimate from 896 bits to 1024 and the work grows by a factor of about 30. Call it 900 GPU-years. Lu’s writeup puts RSA-1024 at roughly $30 million per key for a hyperscaler or frontier lab, and he expects that to drop. A lab with a hundred thousand GPUs produces 900 idle GPU-years as a rounding error. The linear algebra stage does not spread across a fleet the way sieving does, so that arithmetic is a floor on wall-clock time and not a forecast. It is still a number that fits inside a budget line.

In 2015 the Logjam authors priced a break of 1024-bit Diffie-Hellman at a few hundred million dollars of special-purpose hardware to crack one prime a year. They called it plausible for a nation-state and pointed at the NSA budget. The argument required a state. Weis now writes that RSA-1024 is “vulnerable to many actors with data center-level fleets of GPUs.” Many actors.

RSA-2048 is about a billion times harder than 1024. No amount of idle time closes that gap and nobody credible says otherwise.

Thirteen Years of Warning

NIST disallowed 1024-bit RSA for signing at the end of 2013. That is thirteen years of margin ahead of a public break at 896. The committee got the date right, with room to spare.

The keys are still there. SP 800-131A carries 1024-bit signature verification as “legacy use” because old firmware and old documents still need to verify. RFC 8301 still sets the DKIM floor at 1024 bits and the large mailbox providers still verify it. The DNSSEC root zone-signing key sat at 1024 bits until 2016. Boot ROMs hold 1024-bit public keys that will never be reflashed. Every session recorded in the years when 1024 was the default is sitting wherever it was stored.

Most of that list is signature verification, which means nothing had to be recorded in advance. Marin Ivezic, writing about post-quantum DNSSEC, calls the pattern Trust Now, Forge Later: recover one signing key and everything it vouches for is forgeable from that day on. The classical version needs no quantum computer, only idle GPUs.

This is what “Historical” means in the CMVP database too. Agencies should not buy the module for new systems. The module keeps running in the old ones. The status changes in a table in Gaithersburg and nothing changes in the rack. Vendors who want off the list face a validation queue where CMVP’s share of the process alone averages 542 days.

Two Calendars

Defenders work from a published calendar. FIPS 140-2 had its retirement date fixed years ahead. CNSA 2.0 says 2027, 2030, 2035. NIST’s draft transition plan deprecates RSA-2048 after 2030 and disallows it after 2035. These are negotiated dates, set by people balancing procurement cycles against risk, and they are reasonable.

Attackers work from capacity. Their date is whenever the leftovers get big enough. Lu and Weis announced theirs after the fact, as numbers on a web page. Nothing obliges the next one to publish. For 1024 the defenders’ calendar beat the attackers’ calendar by more than a decade, and it did not matter for any key that nobody went and found.

The post-quantum dates will work the same way. A deadline moves a certificate to a list. It does not move a key.

A key does not know it has been deprecated.