New world record in factoring RSA numbers

On September 3, 2026, US researcher Eric Lu announced that he had successfully factored RSA-260, an RSA challenge number consisting of 260 decimal digits or 862 bits. This surpasses the previous factoring record, RSA-250 (829 bits), which dated back to 2020. The achievement marks the largest RSA challenge number ever factored.

Lu’s entire announcement on X consisted of a single number followed by four words:

4397328654844826923795068102505872571721883526553349659561256924505973939597593482272505698004801207988043088656411102133523080581 divides RSA-260

To anyone outside the cryptographic community, this looked rather cryptic. To number theorists, it was enough.

A challenge dating back to 1991

RSA-260 originates from the famous RSA Factoring Challenge, which was launched in 1991 by RSA Laboratories. The challenge was intended to track the progress of factoring technology and thereby provide insight into the security of RSA encryption. The naming convention was simple: RSA-260 has 260 decimal digits. The challenge eventually ended in 2007, leaving several numbers unfactored.

After the official competition was discontinued, the cryptographic puzzle portal MysteryTwister C3 adopted the remaining unsolved RSA challenges – including RSA-260 and listed them among its open mysteries (level 3). Following Lu’s breakthrough, RSA-260 naturally disappeared from the list of unsolved challenges.

The number itself

For completeness, here is RSA-260:

22112825529529666435281085255026230927612089502470015394413748319128822941402001986512729726569746599085900330031400051170742204560859276357953757185954298838958709229238491006703034124620545784566413664540684214361293017694020846391065875914794251435144458199

And here are its two prime factors:

4397328654844826923795068102505872571721883526553349659561256924505973939597593482272505698004801207988043088656411102133523080581
5028695206842569864686141618253083416610081090075366674776775706538324961364412200138116378509733307971876652984898985905923678379

Multiplying these two numbers reproduces RSA-260 exactly. The factorization can therefore be verified within seconds, while finding the factors is an enormously difficult computational task.

Why does this matter?

RSA encryption relies on one fundamental assumption: multiplying two large prime numbers is easy, but factoring the resulting product is hard. An RSA public key contains such a composite number. If an attacker manages to factor it, the corresponding private key can be derived, and the protection provided by RSA collapses. This is why factoring records attract so much attention. They provide a benchmark for how quickly factoring technology is advancing and whether current key sizes remain safe.

Fortunately, there is no reason for panic. Modern RSA deployments normally use keys of 2048 bits or larger. RSA-260, despite being a record, is only 862 bits long. The computational effort required for factoring a 2048-bit RSA modulus remains vastly greater. Experts continue to regard RSA-2048 as secure against classical factoring attacks.

Pencil, paper, and a sense of humor

At the time of the initial announcement, Lu disclosed no technical details, which fueled curiosity throughout the cryptographic community. When asked, he reportedly suggested that he had done the calculation using paper and pencil. Needless to say, this was a joke. Breaking RSA records traditionally requires years of computation time, sophisticated software, and enormous computational resources.

The story received additional attention because Eric Lu works in the AI field. As a result, some headlines quickly suggested that artificial intelligence had “cracked RSA.” Such claims are misleading. Traditionally, factoring records are achieved through advances in computing power. Artificial intelligence is generally not a core component of the mathematical factoring process.

What comes next?

The fall of RSA-260 naturally raises the next question: which challenge number will be next? Several larger RSA challenge numbers remain unsolved. As always, the cryptographic community will watch closely to see whether RSA-270 becomes the next victim.

Back to Cipherbrain Blog