Skip to the page
Big Numbers, Split

1991 to this monthRecords

Every general-purpose factoring record since the RSA challenge list was published, the curve they sit on, and a ruler for how far a 2048-bit key is from the biggest number anyone has split.

A line chart of factoring records in bits against year, rising from 330 bits in 1991 to 896 in 2026, with dashed lines at 512, 1024 and 2048.
Bits in the record number against the year. The 2026 pair are the first records set on GPUs and the first set with the help of AI coding agents; both authors said the mathematics did not change [99][101].
numberdigitsbitsdatewhomethodeffort
RSA-1001003301991-04-01Arjen LenstraMPQSa few days on a MasPar [29]
RSA-1101103641992-04-14Arjen Lenstra and Mark ManasseMPQSabout a month [29]
RSA-1201203971993-06-09Denny, Dodson, Lenstra, ManasseMPQSabout 830 MIPS-years [29]
RSA-1291294261994-04-26Atkins, Graff, Lenstra, Leyland and about 600 volunteersMPQSabout 5,000 MIPS-years over eight months [23]
RSA-1301304301996-04-10Lenstra and othersGNFSabout 1,000 MIPS-years — the first RSA number by the number field sieve [29]
RSA-1401404631999-02-02te Riele and others (CWI)GNFSabout 2,000 MIPS-years [29]
RSA-1551555121999-08-22Cavallar and seventeen othersGNFSabout 8,000 MIPS-years, seven months [24]
RSA-1601605302003-04-01Franke, Kleinjung and others (Bonn)GNFSa few months on a cluster [29]
RSA-5761745762003-12-03Franke, Kleinjung and othersGNFSmonths on a cluster [29]
RSA-6401936402005-11-02Bahr, Boehm, Franke, KleinjungGNFSabout 30 years of a 2.2 GHz Opteron [29]
RSA-2002006632005-05-09Bahr, Boehm, Franke, KleinjungGNFSabout 55 years of a 2.2 GHz Opteron [29]
RSA-7682327682009-12-12Kleinjung and twelve othersGNFSabout 2,000 years of a 2.2 GHz Opteron core [25]
RSA-2402407952019-12-02Boudot, Gaudry, Guillevic, Heninger, Thomé, ZimmermannGNFS (CADO-NFS)about 900 core-years of a 2.1 GHz Xeon Gold 6130 [26]
RSA-2502508292020-02-28Boudot, Gaudry, Guillevic, Heninger, Thomé, ZimmermannGNFS (CADO-NFS)about 2,700 core-years of a 2.1 GHz Xeon Gold 6130 [27][26]
RSA-2602608622026-09-03Eric Lu (Cognition)GNFS (CADO-NFS on GPUs)4,923 GPU-days on B200-class GPUs, about 16 days elapsed, about $400k at list prices [99]
RSA-8962708962026-09-19Stephen Weis (Anthropic)GNFS (CADO-NFS on GPUs)about 30 GPU-years on up to 2,048 idle GPUs over ten days [101]
still open
RSA-270270895270 digits, still open in the challenge list — RSA-896 (also 270 digits) was the one that fell [29]
RSA-10243091024the key size most of the web used until about 2013; still open [29]
RSA-20486172048the key size most of the web uses now; still open [29]
special form — a different, easier sieve; not comparable
2^1061 − 132010612012-08-04NFS@HomeSNFSthe special number field sieve works on numbers of a special form; the record for those is bigger, and says nothing about RSA keys [102]
Seventeen Mersenne numbers 2^n − 1, 1007 ≤ n ≤ 119936111992014-08Kleinjung, Bos, LenstraSNFS, shared sievingthe 'Mersenne factorization factory' — one sieving pass amortised across many numbers [102]

The two 2026 rows are not on the RSA challenge list's own cadence: RSA-260 was the next unsolved challenge number; RSA-896 was a 270-digit challenge number picked because it was a round number of bits. Effort units change with the era — MIPS-years, Opteron-years, Xeon core-years, GPU-years — and are not convertible without a footnote; the sources give each team's own figure.

The curve

The number field sieve's running time has a known shape [22]:

L(N) = exp( c · (ln N)1/3 · (ln ln N)2/3 ),   c = (64/9)1/3 ≈ 1.923
Reading it: not exponential in the number of bits (that would be 2 to the bits), and not a fixed power of the bits either; in between, with the 1/3 doing the work. Constants and lower-order terms are missing, which is why this is a ruler and not a forecast.

Anchor it on RSA-250 — 2,700 core-years for 829 bits [27] — and read off the rest:

bitsdigitstimes RSA-250core-years, scaledin words
5121552.67e-050.0721about 26 days of one core
7682320.164442about 442 core-years — a big cluster for a year
82925012.7e+03about 2,700 core-years — a big cluster for a year
10243092005.4e+05about 540,014 core-years — every core in a large data centre for years
15364631.99e+075.38e+105.4e+10 core-years — more computing than has been done on Earth
20486172.33e+116.29e+146.3e+14 core-years — more computing than has been done on Earth
30729258.82e+172.38e+212.4e+21 core-years — more computing than has been done on Earth
409612341.96e+235.29e+265.3e+26 core-years — more computing than has been done on Earth
A curve rising steeply from left to right: the estimated core-years to factor a key against its size in bits, marked at 512, 768, 1024, 2048 and 4096.
The same curve drawn. The RSA-768 team said 1024 bits was about a thousand times harder than 768; the ruler here says 1221×, which is the same order. The 2026 GPU runs do not move the curve; they move the price of a core-year.

The ruler

2048 bits

What the 2026 records changed

Two things, and neither is the mathematics. Eric Lu's RSA-260 run in early September and Stephen Weis's RSA-896 run two weeks later both ported CADO-NFS to data-centre GPUs, with AI coding agents doing much of the port [99][101]. Weis's ran as a low-priority job on idle machines: about thirty GPU-years in ten days, at no marginal cost to anyone. His own conclusion: the running time of the sieve did not improve, deployed 2048-bit keys are not affected — and a 1024-bit key is now within reach of anyone with a large GPU fleet and a slow month. Old keys do not retire themselves; in 2015 a 512-bit key cost $75 of cloud time to break and hundreds were still in use [32].