RSA-260, a problem that sat unsolved in a public challenge for 6 years, was cracked in 4 days by Cognition engineer Eric Lu and a team of Devin agents — at a total cost of roughly 4,900 GPU-days and $400,000, about one-tenth of the previous public best. But 2048-bit RSA remains roughly a billion times harder than 1024-bit, so this poses no practical threat in the near term.
A public challenge untouched for 6 years, dismantled in 4 days by an AI agent
RSA-260 sat in a public challenge database for 6 years — now it's been solved by an AI agent called Devin.
The RSA Factoring Challenge is a public database, with difficulty scaled by digit length. In February 2020, RSA-250 was solved, pushing the public record to 250 digits; the next tier, RSA-260, is a 260-digit (862-bit) composite number that has been sitting there untouched since 1991.
Cognition engineer Eric Lu first posted a 130-digit integer on X on September 3 with the note "divides RSA-260," and followed up with a full writeup 6 days later.
The core algorithm for factoring large numbers is GNFS(General Number Field Sieve — currently the most efficient classical algorithm for factoring large integers; no quantum component). What Devin wrote isn't a new algorithm — it's a high-performance GPU implementation that took INRIA's open-source CADO-NFS and modified it, moving the lattice sieving step(lattice sieving — the most compute-intensive step in GNFS) from CPU to GPU. This is engineering optimization, not a number-theory breakthrough. It finished in 4 days, and by that measure, this is the first time in 6 years anyone has solved this public challenge.
Lu also estimated in his writeup: if a supercomputing vendor or frontier AI lab used this pipeline to factor RSA-1024 (309 digits), it would cost roughly $30 million per number at current market rates. RSA-2048 (617 digits — the key length actually used in the real world) remains roughly a billion times harder than RSA-1024, and the GNFS route essentially doesn't touch it.
Code written by Devin, benchmarks run by Devin, cluster tuned by Devin
The three main steps of GNFS haven't changed. What changed is who writes the code: from a researcher to one operator plus a team of Devins.
GNFS (General Number Field Sieve) works in three steps: first select polynomials, then do lattice sieving (using a large pool of candidate relations to build a big matrix), and finally solve a sparse linear system. Lu didn't change the algorithm itself — he took the open-source CADO-NFS and rewrote it, moving the most compute-intensive step (lattice sieving) from CPU to GPU, with a drop-in replacement implementation.
Lu didn't do the work himself. He says he only did three things: set priorities, establish benchmarks, and recognize when things went off-track. Measurement, cluster scheduling, and performance optimization(making code run faster while using fewer resources) — all of that was handled by Devin. A detail that appears in multiple reports: Lu was driving up to 18 concurrent Devin sessions by himself, over a period of roughly three weeks.
The cluster was ready-made: fragmented compute left over from LLM training/inference on NVL72 racks. Cognition's cluster scheduler was already optimizing to "pick up these idle gaps," and RSA-260 was slipped in alongside. The entire pipeline occupied only a "single-digit percentage" of the cluster's compute — all single-node scraps that were idle outside of LLM training and inference.
The essential difference from previous records isn't in the algorithm — it's who's at the keyboard.
The "1024-bit RSA is unsafe" story is actually two decades old
The thing people fear most — "AI killed 1024-bit encryption" — isn't new to this round. What actually changed is who can act on it.
When people outside the field see numbers like "$30M to break RSA-1024," their first reaction is "the sky is falling." Eric Lu himself states it plainly in his blog:
$30 million isn't an abstract number — it's in the same ballpark as "what one major LLM training run burns through." So the real shift isn't in whether it can be broken, but in the two displacements Lu keeps emphasizing: the participants have shifted from "a handful of people who build specialized hardware" to "anyone with GPUs"; and even people with no cryptography background can now speed up factorization with Devin. That last point is the most consequential: where it used to take an institution like INRIA six months to touch GNFS code, one engineer can now spin up 18 Devin sessions and turn CADO-NFS (INRIA's open-source implementation) into a GPU version in three weeks.
As for your HTTPS certificate — that's typically 2048-bit. RSA-2048 (~617 digits) is a billion times harder than RSA-1024, and this efficiency gain on the GNFS path basically doesn't reach it. Lu puts it bluntly: "RSA-2048 has not been meaningfully affected."
So what this round of AI has torn open isn't "all the encryption everyone uses is done for" — it's that "medium-strength encryption" has been downgraded from a nation-state capability to an enterprise-level one. And that middle tier is exactly what a lot of legacy systems, embedded devices, and decade-old keys are actually using.
The barrier drops to waist height — is cryptography still safe?
Lu is quite direct about what this really means: the entry barrier to cryptanalysis, computational mathematics, and indeed most large-scale scientific computing has dropped dramatically. This isn't AI inventing new algorithms — it's AI turning something that used to eat expert person-months into a side project a GPU engineer can hack on for a few weeks.
Devin didn't propose a new number-theory algorithm. The General Number Field Sieve (GNFS, a classical algorithm for splitting a large integer into two factors)(the fastest known general-purpose algorithm for factoring large integers) it ran is the same pipeline used by the 2020 team; the so-called "glas" is just a GPU rewrite of INRIA's open-source tool CADO-NFS. What it actually did was move the lattice sieving step(the most compute-intensive step in GNFS, repeatedly sifting through candidate data in large tables) — a workload that's "awkward on the surface but extremely bandwidth-hungry" — onto GPUs. Lu's exact words: just put that "anomalous memory subsystem" on the GPU to work.
Conveniently, this workload is a perfect match for training-cluster scraps. An NVL72 rack(NVIDIA's 72-GPU interconnected rack, designed for large-model training) used for LLM training has 18 interconnected machines, and large-model tasks often don't fully saturate an entire machine — leaving single-node, independent, preemptable fragments of idle capacity. Lattice sieving happens to be exactly the kind of job that is "single-node, preemptable in seconds, and independent of other tasks" — so the work runs on those fragments at near-zero marginal cost. Total: 4,900 GPU-days, 13.5 GPU-years, roughly $400,000.
Anyone who sees this match can easily arrive at Lu's bolder claim: as long as a problem can be programmatically broken down, it's worth letting autonomous software-engineering agents take a crack at it. The barrier isn't in the math — it's in the code. And that part, AI can now walk for you.
Subsequent signals worth watching:
· The "$30M per RSA-1024" figure is Lu's own back-of-envelope estimate, with no third-party verification. If a supercomputing center or frontier lab publicly breaks through to 1024-bit and actually gets the cost down to the $30M range, it proves the "hyperscale compute as a substitute for cryptanalysis" path works.
· Whether agents are entering harder domains — say pure number theory, computational chemistry, or astrophysics, where expert judgment is needed to decide "which direction to go" in research code. If a non-cryptography case appears in the same "a few experts over weeks vs. agents over weeks" mold, it means the Devin pattern isn't domain-specific.
· Whether a fragmented-compute market emerges. Idle NVL72 topology is being identified as tradable "compute inventory" — if a platform shows up that fills "single-node, preemptable, decoupled" tasks (more GNFS, distributed scientific computing, batch simulations), the TCO(Total Cost of Ownership — including procurement, operations, electricity, etc.) of training clusters will get recalculated.
· RSA-2048 isn't going down anytime soon. Lu is explicit: 2048-bit is roughly a billion times harder than 1024-bit, and "this work has almost no impact on its feasibility." If a preprint or institutional announcement (not a blog guess) claiming "2048-bit breached" appears, that's the real earthquake.
· Existing 2048-bit RSA certificates won't be replaced because of this. CA(Certificate Authority — a trusted third party that issues HTTPS certificates to websites) and browser-side rotation cycles run on the order of years; the signal to watch is whether a major CA voluntarily and preemptively switches 2048-bit root certificates(the highest-trust-level certificate embedded in browsers and operating systems) to 3072 or 4096 bits — not scattered discussion in the press.
What you can understand: those three numbers
RSA-260 itself is a problem only professionals can tackle — ordinary people can't reproduce it. But the key numbers and concepts in this section are on the table for anyone to verify.
The first thing you can do is check three dates. RSA-250 was the previous public record, set in February 2020 by 6 researchers. RSA-260 sat open for 6 years. This time the main pipeline finished in 4 days, with roughly 3 weeks from Devin picking it up to results. Put the three numbers together: 6 years vs. 3 weeks, unsolved vs. solved in one run — the meaning speaks for itself.
The second is to read the cost curve. The original writeup is clear: GNFS (General Number Field Sieve)(currently the fastest classical algorithm for factoring large integers) on RSA-260 cost roughly 4,900 GPU-days, or 13.5 GPU-years, or about $400,000 at market rates. Of that, polynomial selection took 643 GPU-days, sieving took 3,813 GPU-days, and linear-system solving took 467 GPU-days. Cognition claims this cost is roughly one-tenth of the previous public best, but there's no third-party verification — that's a vendor self-report, so take it with a grain of salt.
The third is to look at the author's own assessment. The original gives two hard limits: RSA-1024 (~309 digits), extrapolated by GNFS standards(inferring an unknown point from known data points in an algorithm), comes to roughly $30 million — achievable by top institutions; RSA-2048 remains roughly a billion times harder than RSA-1024, and the author explicitly says the GNFS route has limited impact. In other words, the 2048-bit certificates in your browser are not affected today. What actually moved is the cost curve — and who gets to move it.
One more detail worth noting: the hardware for this pipeline isn't exotic — it ran on the fragmented compute left over from LLM training on NVL72 racks(NVIDIA's 72-GPU interconnected high-density rack), essentially "training ran the problem on the side." The barrier isn't the hardware — it's someone writing it out. And that, Devin did automatically; the author's role was to set priorities, read the benchmarks, and course-correct.
Check the RSA Factoring Challenge public list: whether RSA-260 has moved from "unsolved" to "factored," and confirm the previous record is still RSA-250 from February 2020.
Write down the three cost numbers: 4,900 GPU-days, roughly $400,000, roughly $30 million (RSA-1024) — and wait for third-party verification to compare against the vendor's figures.
Open your usual bank or email site in the browser and check the certificate's key length — it's most likely still 2048-bit, which the author explicitly says is unaffected.
Watch whether Cognition subsequently releases the glas siever and GPU-modification code or paper, and whether third parties reproduce that "10× cost reduction."
Treat this as "a signal": when a researcher with a single GPU cluster on a single task shatters a long-standing record in some field, watch which discipline gets hit next.
Source: Cognition Blog "Factoring RSA-260," by Eric Lu. Caveat: All key figures in this article (4,900 GPU-days, $400K, 10× cost reduction, $30M estimate for RSA-1024) come from Cognition's own writeup and the author's own estimates, with no independent third-party verification; "Devin autonomously wrote the code" is the vendor's positioning of its own product.