{
 "_about": "The history, one row per event. 'lane' is classical, quantum or riemann. 'src' names ids in tools/sources.py. CC BY 4.0, Nan · hongdam.net.",
 "events": [
  {"year": -240, "when": "about 240 BC", "lane": "classical", "who": "Eratosthenes of Cyrene", "what": "The sieve: write the numbers out, strike every second one after 2, every third after 3, and what is left standing is prime. Still the fastest way to list the small primes, and still the first move in every big factoring run.", "src": ["nicomachus"]},
  {"year": 1643, "when": "1643", "lane": "classical", "who": "Pierre de Fermat", "what": "A number that is the difference of two squares splits at once: a² − b² = (a − b)(a + b). Fermat shows Mersenne how to walk a up from the square root until a² − N is a square. It is quick when the two factors are close together and hopeless when they are not — which is exactly why key generators keep them far apart.", "src": ["fermat1643"]},
  {"year": 1732, "when": "1732", "lane": "classical", "who": "Leonhard Euler", "what": "Fermat had guessed that 2^(2^n) + 1 is always prime. Euler splits the fifth one: 4,294,967,297 = 641 × 6,700,417. He did it by knowing, from Fermat's own little theorem, that any factor had to have the form 64k + 1, so he only had to try a handful.", "src": ["euler1732"]},
  {"year": 1801, "when": "1801", "lane": "classical", "who": "Carl Friedrich Gauss", "what": "In the Disquisitiones, article 329: telling primes from composites and splitting the composites is 'one of the most important and useful in arithmetic', and 'the dignity of the science itself seems to require that every possible means be explored'. He lists two methods of his own. Nobody had a fast one.", "src": ["gauss1801"]},
  {"year": 1859, "when": "1859", "lane": "riemann", "who": "Bernhard Riemann", "what": "An eight-page paper on how many primes there are below a given size. The count is tied to the zeros of one function, ζ(s), and Riemann remarks that all the zeros he has looked at sit on one line and that it is 'very probable' they all do. He does not prove it. Nobody has.", "src": ["riemann1859"]},
  {"year": 1896, "when": "1896", "lane": "riemann", "who": "Jacques Hadamard and Charles de la Vallée Poussin", "what": "The Prime Number Theorem, proved twice in one year: the count of primes up to x runs like x divided by the natural log of x. The proof goes through Riemann's zeros — showing none of them sit on the edge of the strip. So there are plenty of primes of any size you want, and picking two big ones is cheap.", "src": ["hadamard1896"]},
  {"year": 1900, "when": "1900", "lane": "riemann", "who": "David Hilbert", "what": "The Riemann Hypothesis is the eighth of his twenty-three problems for the century. Asked what he would do if he woke after five hundred years, Hilbert is said to have answered: ask whether it had been proved.", "src": ["hilbert1900"]},
  {"year": 1926, "when": "1926", "lane": "classical", "who": "Maurice Kraitchik", "what": "The trick every modern method rests on: you do not need N itself to be a difference of two squares. It is enough to find x² ≡ y² (mod N), two numbers whose squares leave the same remainder. Then N divides (x − y)(x + y), and half the time gcd(x − y, N) is a factor. Kraitchik collects such congruences and multiplies them together until the product is a square.", "src": ["kraitchik1926"]},
  {"year": 1933, "when": "1926–1933", "lane": "classical", "who": "D. N. Lehmer and D. H. Lehmer", "what": "Sieving machines: first bicycle chains on a shaft, then a photo-electric sieve with gears and a beam of light, testing thousands of candidates a second for whether they leave the right remainders. The first factoring hardware.", "src": ["lehmer1933"]},
  {"year": 1950, "when": "1950", "lane": "riemann", "who": "Alan Turing", "what": "On the Manchester Mark 1, one of the first stored-program computers, Turing checks that the zeros of ζ up to a certain height all sit on Riemann's line. He was hoping to find one off it. He did not. Every computation since — now past the first ten trillion zeros — has found the same.", "src": ["turing1953", "platt2021"]},
  {"year": 1970, "when": "1970", "lane": "classical", "who": "Michael Morrison and John Brillhart", "what": "The continued-fraction method, run on an IBM 360/91, splits the seventh Fermat number: 39 digits, unfactored since 1732. The first factoring record set by a computer using a method built for computers.", "src": ["morrison1975"]},
  {"year": 1974, "when": "1974–1975", "lane": "classical", "who": "John Pollard", "what": "Two cheap methods in two years. The p − 1 method catches a factor p when p − 1 is made of small primes. The rho method walks a pseudo-random path through the numbers mod N and waits for it to loop; it finds a factor p in about √p steps, which for a 20-digit N is a few thousand steps on a laptop instead of a few billion.", "src": ["pollard1974", "pollard1975"]},
  {"year": 1976, "when": "1976", "lane": "riemann", "who": "Gary Miller", "what": "A fast, certain test for whether a number is prime — provided the Generalised Riemann Hypothesis is true. Without it the same test is fast and almost certain (Rabin's 1980 version), which is what every key generator uses. This is the closest the Riemann Hypothesis comes to cryptography: it would guarantee a primality test, not speed up any factoring.", "src": ["miller1976"]},
  {"year": 1977, "when": "1977", "lane": "classical", "who": "Ron Rivest, Adi Shamir and Leonard Adleman", "what": "RSA: pick two big primes, publish their product N and a number e, keep the primes secret. Anyone can lock a message with (N, e); only someone who knows the primes can unlock it. The whole scheme rests on one bet — that splitting N is far harder than making it. Martin Gardner's column prints a 129-digit N and offers $100 to whoever splits it; Rivest guesses forty quadrillion years.", "src": ["rsa1978", "gardner1977"]},
  {"year": 1981, "when": "1981", "lane": "classical", "who": "John Dixon", "what": "Kraitchik's idea with a proof attached: pick random x, keep the ones whose x² mod N breaks into small primes, and linear algebra over the parities finds a product that is a square. The first factoring method with a rigorous sub-exponential running time.", "src": ["dixon1981"]},
  {"year": 1981, "when": "1981", "lane": "classical", "who": "Carl Pomerance", "what": "The quadratic sieve: instead of testing each candidate x² − N for small factors one by one, sieve them all at once, the way Eratosthenes did — a factor p divides every p-th value in the row. Ten to a hundred times faster than the continued-fraction method for the same size, and the record holder for the next decade.", "src": ["pomerance1985", "pomerance1996"]},
  {"year": 1985, "when": "1985", "lane": "classical", "who": "Hendrik Lenstra", "what": "The elliptic curve method: Pollard's p − 1 idea, but on a curve you can change if the first one does not work. Its cost depends on the size of the factor it finds, not the size of N, so it is the tool for pulling a 30-digit factor out of a 300-digit number. Also the first serious use of the curves that a Bitcoin wallet key lives on.", "src": ["lenstra1987"]},
  {"year": 1988, "when": "1988–1990", "lane": "classical", "who": "John Pollard, then the Lenstra brothers and Mark Manasse", "what": "The number field sieve. Pollard's letter proposes sieving in a bigger number system than the integers; two years later the ninth Fermat number (155 digits) falls to it. The general version for numbers of no special form arrives in 1993 and is still, in 2026, the fastest method known for RSA-size numbers.", "src": ["lenstra1993", "nfs1993"]},
  {"year": 1991, "when": "1991", "lane": "classical", "who": "RSA Laboratories", "what": "The RSA Factoring Challenge: a list of numbers from 100 to 617 digits, each the product of two primes, with cash for each one split. The list becomes the yardstick everyone measures against.", "src": ["rsanumbers"]},
  {"year": 1994, "when": "April 1994", "lane": "classical", "who": "Derek Atkins, Michael Graff, Arjen Lenstra, Paul Leyland and about six hundred volunteers", "what": "Gardner's 129-digit number falls after eight months of spare time on computers around the world, by the quadratic sieve. The message inside: THE MAGIC WORDS ARE SQUEAMISH OSSIFRAGE. Rivest's forty quadrillion years lasted seventeen.", "src": ["atkins1995"]},
  {"year": 1994, "when": "1994", "lane": "quantum", "who": "Peter Shor", "what": "A quantum computer, if one could be built, could split any N in a number of steps that grows like a small power of its length instead of exponentially. The quantum part finds the period of a^x mod N; the rest is Euclid. Every serious estimate of when RSA and wallet keys fall is an estimate of when a machine can run this.", "src": ["shor1997"]},
  {"year": 1999, "when": "August 1999", "lane": "classical", "who": "Stefania Cavallar and a team of seventeen", "what": "RSA-155, the first 512-bit number, by the number field sieve: about seven months, on the order of eight thousand MIPS-years. 512-bit keys were still in wide use.", "src": ["cavallar2000"]},
  {"year": 2001, "when": "December 2001", "lane": "quantum", "who": "Lieven Vandersypen and the IBM Almaden group", "what": "Shor's algorithm runs on hardware for the first time: seven nuclear spins in a molecule, and 15 comes out as 3 × 5. The circuit was 'compiled' using knowledge of the answer, which every hardware demonstration since has also done.", "src": ["vandersypen2001"]},
  {"year": 2004, "when": "2002–2004", "lane": "riemann", "who": "Manindra Agrawal, Neeraj Kayal and Nitin Saxena", "what": "PRIMES is in P: a fast, certain primality test with no hypothesis attached. Telling prime from composite is now settled and easy. Splitting a composite is not, and this result says nothing about it.", "src": ["aks2004"]},
  {"year": 2009, "when": "December 2009", "lane": "classical", "who": "Thorsten Kleinjung and twelve others", "what": "RSA-768, 232 digits: about two thousand years of a single 2.2 GHz core, spread over two and a half years of wall time. The team's own estimate: a 1024-bit key is about a thousand times harder and 'may be feasible' within a decade with the same effort.", "src": ["kleinjung2010"]},
  {"year": 2012, "when": "2012", "lane": "quantum", "who": "Enrique Martín-López and the Bristol group", "what": "21 = 3 × 7 with photons and a recycled qubit. Still, in 2026, the largest number split by Shor's algorithm on a physical machine without the answer built into the circuit — and this one was compiled too.", "src": ["martinlopez2012"]},
  {"year": 2012, "when": "2012", "lane": "quantum", "who": "Austin Fowler, Matteo Mariantoni, John Martinis and Andrew Cleland", "what": "The first careful bill for breaking a 2000-bit key on a surface-code machine: on the order of a billion physical qubits, about a day. The number every later estimate is measured against.", "src": ["fowler2012"]},
  {"year": 2013, "when": "2013", "lane": "quantum", "who": "John Smolin, Graeme Smith and Alexander Vargo", "what": "'Oversimplifying quantum factoring': if you compile the circuit with the answer in hand, you can 'factor' any number at all with two qubits. The small demonstrations prove the hardware can hold a few qubits, and nothing about scaling.", "src": ["smolin2013"]},
  {"year": 2015, "when": "2015", "lane": "classical", "who": "Nadia Heninger's group at Penn; the Logjam team", "what": "'Factoring as a service': a 512-bit RSA key split in four hours on rented cloud machines for $75 — and hundreds of such keys still in use in mail and DNS. The same year, Logjam shows 512-bit Diffie-Hellman falling to a week's precomputation. Old key sizes do not retire themselves.", "src": ["valenta2015", "adrian2015"]},
  {"year": 2019, "when": "May 2019", "lane": "quantum", "who": "Craig Gidney and Martin Ekerå", "what": "The bill drops fifty-fold: 2048-bit RSA in eight hours on twenty million noisy qubits, given a physical error rate of one in a thousand. A model, not a machine — nothing had a thousandth of that.", "src": ["gidney2019"]},
  {"year": 2019, "when": "December 2019", "lane": "classical", "who": "Fabrice Boudot, Pierrick Gaudry, Aurore Guillevic, Nadia Heninger, Emmanuel Thomé and Paul Zimmermann", "what": "RSA-240 (795 bits) with the open-source CADO-NFS, about nine hundred core-years, in the same run as a 240-digit discrete logarithm. The two problems, factoring and discrete log, turn out to cost about the same.", "src": ["boudot2020"]},
  {"year": 2020, "when": "February 2020", "lane": "classical", "who": "The same six", "what": "RSA-250, 829 bits, 2,700 core-years of a 2.1 GHz Xeon. It stood as the record for six and a half years.", "src": ["rsa250", "boudot2020"]},
  {"year": 2021, "when": "March 2021", "lane": "classical", "who": "Claus Peter Schnorr", "what": "A preprint whose abstract says 'This destroys the RSA cryptosystem.' It did not split any challenge number, the claim was withdrawn in a revision, and later work found the method stops working past about 80 bits. The template for the next few years of headlines.", "src": ["schnorr2021", "schneier2021"]},
  {"year": 2022, "when": "December 2022", "lane": "quantum", "who": "Bao Yan and twenty-three others", "what": "A preprint says 372 qubits could 'challenge RSA-2048', by bolting Schnorr's method to a small quantum optimiser. The hardware run split a 48-bit number. Scott Aaronson: 'cargo cult quantum factoring'. The classical step does not scale, and the number 372 still circulates.", "src": ["yan2022", "aaronson2023"]},
  {"year": 2023, "when": "August 2023", "lane": "quantum", "who": "Oded Regev", "what": "The first real improvement to Shor's algorithm in thirty years: a multi-dimensional version with about √n fewer gates for an n-bit number, at the price of more qubits. Ragavan and Vaikuntanathan bring the qubit count back down within months.", "src": ["regev2023", "ragavan2024"]},
  {"year": 2024, "when": "May 2024", "lane": "riemann", "who": "Larry Guth and James Maynard", "what": "The first improvement since 1940 on how many zeros can sit off Riemann's line in a given range. Progress toward the Hypothesis, not a proof of it, and no change to any factoring method.", "src": ["guth2024"]},
  {"year": 2024, "when": "August 2024", "lane": "quantum", "who": "NIST", "what": "The first three post-quantum standards are final: ML-KEM for key exchange, ML-DSA and SLH-DSA for signatures. Three months later a draft transition plan: RSA-2048 and 256-bit curves deprecated after 2030, disallowed after 2035.", "src": ["nist2024", "nist8547"]},
  {"year": 2024, "when": "December 2024", "lane": "quantum", "who": "Google Quantum AI", "what": "Willow: 105 superconducting qubits, and for the first time a logical qubit that gets better as the code gets bigger — the 'below threshold' result the field had waited for since 1996. One logical memory, no logical gates.", "src": ["willow2024"]},
  {"year": 2025, "when": "May 2025", "lane": "quantum", "who": "Craig Gidney", "what": "The bill drops twenty-fold again: 2048-bit RSA with fewer than a million noisy qubits, in under a week. Same error-rate assumption as 2019; the savings are in the arithmetic and the error correction.", "src": ["gidney2025"]},
  {"year": 2026, "when": "February 2026", "lane": "quantum", "who": "Iceberg Quantum", "what": "The 'Pinnacle' architecture: RSA-2048 with fewer than 100,000 physical qubits, on a newer family of error-correcting codes that needs long-range wiring nobody has built. Aaronson: 'I have no idea by how much this shortens the timeline.'", "src": ["pinnacle2026", "aaronson2026"]},
  {"year": 2026, "when": "March 2026", "lane": "quantum", "who": "Ryan Babbush, Craig Gidney, Dan Boneh and colleagues at Google, Stanford and the Ethereum Foundation", "what": "The wallet bill: a 256-bit curve key with fewer than 500,000 physical qubits, in minutes, on a fast superconducting machine. Google withholds the circuits and publishes a proof they work. The same week, Caltech puts a slower neutral-atom version at ten thousand atoms and about ten days per key.", "src": ["babbush2026", "googleblog2026", "caltech2026"]},
  {"year": 2026, "when": "April 2026", "lane": "quantum", "who": "Giancarlo Lelli; Project Eleven", "what": "A 15-bit curve key recovered on IBM cloud hardware wins the one-bitcoin Q-Day Prize. Within a day, Bitcoin developers reproduce the 'recovery' with random bits, since 32,767 candidates can be checked by hand. Project Eleven's own CEO: this 'is not Q-Day'.", "src": ["qday2026", "qday2026b"]},
  {"year": 2026, "when": "September 2026", "lane": "classical", "who": "Eric Lu (Cognition); Stephen Weis (Anthropic)", "what": "Two classical records in one month, both by porting CADO-NFS to data-centre GPUs with AI coding agents: RSA-260 (862 bits) on the 3rd, about 4,900 GPU-days; RSA-896 (896 bits) on the 19th, about 30 GPU-years of idle time in ten days. Both authors say the same thing: no new mathematics, and no effect on 2048-bit keys.", "src": ["lu2026", "weis2026"]}
 ]
}
