124 numberedSources
Every citation on the site, in the order the numbers were assigned. Primary where a primary exists; a press report where that is all there is, and the row that rests on it says so.
- [1] Nicomachus of Gerasa, Introduction to Arithmetic, book I ch. 13 — the earliest written description of the sieve, credited to Eratosthenes. c. 100 AD; English by M. L. D'Ooge, 1926.
- [2] Pierre de Fermat, Letter to Marin Mersenne on a method of factoring, with 2027651281 = 44021 × 46061 as the example. 1643; in Dickson, History of the Theory of Numbers vol. I ch. XIV.
- [3] Leonhard Euler, Observationes de theoremate quodam Fermatiano aliisque ad numeros primos spectantibus (E26) — 2^32 + 1 = 641 × 6700417. Commentarii academiae scientiarum Petropolitanae 6, 1738 (presented 1732).
- [4] Carl Friedrich Gauss, Disquisitiones Arithmeticae, art. 329 — on the problem of telling primes from composites and splitting the latter. Leipzig, 1801; English by A. A. Clarke, 1966.
- [5] Bernhard Riemann, Ueber die Anzahl der Primzahlen unter einer gegebenen Grösse. Monatsberichte der Berliner Akademie, November 1859.
- [6] Jacques Hadamard, Sur la distribution des zéros de la fonction ζ(s) et ses conséquences arithmétiques. Bulletin de la Société Mathématique de France 24 (1896) 199–220.
- [7] David Hilbert, Mathematische Probleme — the eighth problem. Göttinger Nachrichten, 1900; English in Bull. AMS 8 (1902) 437–479.
- [8] D. H. Lehmer, A photo-electric number sieve. American Mathematical Monthly 40 (1933) 401–406.
- [9] Maurice Kraitchik, Théorie des nombres, tome II — the idea of combining congruences into a square. Gauthier-Villars, Paris, 1926.
- [10] Alan Turing, Some calculations of the Riemann zeta-function — zeros checked on the Manchester machine in 1950. Proceedings of the London Mathematical Society s3-3 (1953) 99–117.
- [11] Michael A. Morrison and John Brillhart, A method of factoring and the factorization of F7. Mathematics of Computation 29 (1975) 183–205.
- [12] J. M. Pollard, Theorems on factorization and primality testing — the p − 1 method. Mathematical Proceedings of the Cambridge Philosophical Society 76 (1974) 521–528.
- [13] J. M. Pollard, A Monte Carlo method for factorization — the rho method. BIT Numerical Mathematics 15 (1975) 331–334.
- [14] Gary L. Miller, Riemann's hypothesis and tests for primality. Journal of Computer and System Sciences 13 (1976) 300–317.
- [15] R. L. Rivest, A. Shamir and L. Adleman, A method for obtaining digital signatures and public-key cryptosystems. Communications of the ACM 21 (1978) 120–126.
- [16] Martin Gardner, A new kind of cipher that would take millions of years to break — the RSA-129 challenge. Scientific American 237, August 1977, 120–124.
- [17] John D. Dixon, Asymptotically fast factorization of integers. Mathematics of Computation 36 (1981) 255–260.
- [18] Carl Pomerance, The quadratic sieve factoring algorithm. Advances in Cryptology, EUROCRYPT '84, LNCS 209 (1985) 169–182.
- [19] Carl Pomerance, A tale of two sieves. Notices of the American Mathematical Society 43 (1996) 1473–1485.
- [20] H. W. Lenstra Jr., Factoring integers with elliptic curves. Annals of Mathematics 126 (1987) 649–673.
- [21] A. K. Lenstra, H. W. Lenstra Jr., M. S. Manasse and J. M. Pollard, The factorization of the ninth Fermat number. Mathematics of Computation 61 (1993) 319–349.
- [22] A. K. Lenstra and H. W. Lenstra Jr. (eds.), The development of the number field sieve. Lecture Notes in Mathematics 1554, Springer, 1993.
- [23] Derek Atkins, Michael Graff, Arjen K. Lenstra and Paul C. Leyland, The magic words are squeamish ossifrage — RSA-129. Advances in Cryptology, ASIACRYPT '94, LNCS 917 (1995) 261–277.
- [24] Stefania Cavallar and 16 others, Factorization of a 512-bit RSA modulus. Advances in Cryptology, EUROCRYPT 2000, LNCS 1807, 1–18.
- [25] Thorsten Kleinjung and 12 others, Factorization of a 768-bit RSA modulus. Advances in Cryptology, CRYPTO 2010, LNCS 6223, 333–350; IACR ePrint 2010/006.
- [26] Fabrice Boudot, Pierrick Gaudry, Aurore Guillevic, Nadia Heninger, Emmanuel Thomé and Paul Zimmermann, Comparing the difficulty of factorization and discrete logarithm: a 240-digit experiment. Advances in Cryptology, CRYPTO 2020; IACR ePrint 2020/697.
- [27] Paul Zimmermann, Factorization of RSA-250 — announcement to the cado-nfs list. 28 February 2020.
- [28] The CADO-NFS development team, CADO-NFS, an implementation of the number field sieve. INRIA, release 2.3.0 and later.
- [29] Wikipedia contributors, RSA numbers — the challenge list with each factorization's date, team and effort. Wikipedia, read September 2026.
- [30] Samuel Wagstaff Jr. (ed.), The Cunningham Project — factorizations of b^n ± 1, kept since 1925. Purdue University. listed, not cited on a page
- [31] David Adrian and 13 others, Imperfect forward secrecy: how Diffie-Hellman fails in practice — the Logjam attack and 512-bit keys. ACM CCS 2015.
- [32] Luke Valenta, Shaanan Cohney, Alex Liao, Joshua Fried, Satya Bodduluri and Nadia Heninger, Factoring as a service — a 512-bit RSA key in four hours for $75 of cloud time. Financial Cryptography 2016; IACR ePrint 2015/1000.
- [33] Manindra Agrawal, Neeraj Kayal and Nitin Saxena, PRIMES is in P. Annals of Mathematics 160 (2004) 781–793.
- [34] Hugh L. Montgomery, The pair correlation of zeros of the zeta function. Analytic Number Theory, Proc. Sympos. Pure Math. 24 (1973) 181–193.
- [35] Andrew M. Odlyzko, On the distribution of spacings between zeros of the zeta function. Mathematics of Computation 48 (1987) 273–308.
- [36] Andrew M. Odlyzko, Tables of zeros of the Riemann zeta function. University of Minnesota.
- [37] Michael V. Berry and Jonathan P. Keating, The Riemann zeros and eigenvalue asymptotics. SIAM Review 41 (1999) 236–266.
- [38] Clay Mathematics Institute, The Riemann Hypothesis — Millennium Prize problem statement by Enrico Bombieri. 2000.
- [39] Larry Guth and James Maynard, New large value estimates for Dirichlet polynomials. arXiv:2405.20552, May 2024.
- [40] Yitang Zhang, Discrete mean estimates and the Landau-Siegel zero. arXiv:2211.02515, November 2022.
- [41] Dave Platt and Tim Trudgian, The Riemann hypothesis is true up to 3·10^12. Bulletin of the London Mathematical Society 53 (2021) 792–797.
- [42] Peter W. Shor, Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer. SIAM Journal on Computing 26 (1997) 1484–1509; first given at FOCS 1994.
- [43] Lieven M. K. Vandersypen, Matthias Steffen, Gregory Breyta, Costantino S. Yannoni, Mark H. Sherwood and Isaac L. Chuang, Experimental realization of Shor's quantum factoring algorithm using nuclear magnetic resonance — 15 = 3 × 5. Nature 414 (2001) 883–887.
- [44] Enrique Martín-López, Anthony Laing, Thomas Lawson, Roberto Alvarez, Xiao-Qi Zhou and Jeremy L. O'Brien, Experimental realization of Shor's quantum factoring algorithm using qubit recycling — 21 = 3 × 7. Nature Photonics 6 (2012) 773–776.
- [45] Nanyang Xu, Jing Zhu, Dawei Lu, Xianyi Zhou, Xinhua Peng and Jiangfeng Du, Quantum factorization of 143 on a dipolar-coupling nuclear magnetic resonance system. Physical Review Letters 108, 130501 (2012).
- [46] Nikesh S. Dattani and Nathaniel Bryans, Quantum factorization of 56153 with only 4 qubits. arXiv:1411.6758, 2014.
- [47] John A. Smolin, Graeme Smith and Alexander Vargo, Oversimplifying quantum factoring. Nature 499 (2013) 163–165.
- [48] Thomas Monz and 8 others, Realization of a scalable Shor algorithm — 15 on five trapped ions. Science 351 (2016) 1068–1070.
- [49] Mirko Amico, Zain H. Saleem and Muir Kumph, An experimental study of Shor's factoring algorithm on IBM Q — 35 attempted, noise wins. Physical Review A 100, 012305 (2019).
- [50] Austin G. Fowler, Matteo Mariantoni, John M. Martinis and Andrew N. Cleland, Surface codes: towards practical large-scale quantum computation. Physical Review A 86, 032324 (2012).
- [51] Craig Gidney and Martin Ekerå, How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits. Quantum 5, 433 (2021); arXiv May 2019.
- [52] Élie Gouzien and Nicolas Sangouard, Factoring 2048-bit RSA integers in 177 days with 13 436 qubits and a multimode memory. Physical Review Letters 127, 140503 (2021).
- [53] Claus Peter Schnorr, Fast factoring integers by SVP algorithms. IACR ePrint 2021/232.
- [54] Bao Yan and 23 others, Factoring integers with sublinear resources on a superconducting quantum processor — the 372-qubit claim. arXiv:2212.12372, December 2022.
- [55] Scott Aaronson, Cargo cult quantum factoring. Shtetl-Optimized, 4 January 2023.
- [56] Oded Regev, An efficient quantum factoring algorithm. arXiv:2308.06572, August 2023; Journal of the ACM 72 (2025).
- [57] Seyoon Ragavan and Vinod Vaikuntanathan, Space-efficient and noise-robust quantum factoring. Advances in Cryptology, CRYPTO 2024; arXiv:2310.00899.
- [58] Craig Gidney, How to factor 2048 bit RSA integers with less than a million noisy qubits. arXiv:2505.15917, May 2025.
- [59] Martin Roetteler, Michael Naehrig, Krysta M. Svore and Kristin Lauter, Quantum resource estimates for computing elliptic curve discrete logarithms. Advances in Cryptology, ASIACRYPT 2017; arXiv:1706.06752.
- [60] Mark Webber, Vincent Elfving, Sebastian Weidt and Winfried K. Hensinger, The impact of hardware specifications on reaching quantum advantage in the fault tolerant regime — breaking a Bitcoin key in 10 minutes, an hour, a day. AVS Quantum Science 4, 013801 (2022).
- [61] Daniel Litinski, How to compute a 256-bit elliptic curve private key with only 50 million Toffoli gates. arXiv:2306.08585, June 2023.
- [62] Google Quantum AI, Quantum error correction below the surface code threshold — the Willow chip. Nature 638 (2025) 920–926; announced 9 December 2024.
- [63] National Institute of Standards and Technology, NIST releases first three finalized post-quantum encryption standards — FIPS 203, 204, 205. 13 August 2024.
- [64] National Institute of Standards and Technology, Transition to post-quantum cryptography standards — NIST IR 8547 (initial public draft): RSA and ECC deprecated after 2030, disallowed after 2035. November 2024.
- [65] Michele Mosca and Marco Piani, Quantum threat timeline report 2024 — the expert survey. Global Risk Institute, December 2024. listed, not cited on a page
- [66] Satoshi Nakamoto, Bitcoin: a peer-to-peer electronic cash system. 31 October 2008.
- [67] Neal Koblitz, Elliptic curve cryptosystems. Mathematics of Computation 48 (1987) 203–209.
- [68] Certicom Research, SEC 2: recommended elliptic curve domain parameters — secp256k1. Standards for Efficient Cryptography, version 2.0, 2010.
- [69] Bitcoin Project, Developer guide — transactions, P2PKH, P2PK, P2WPKH and P2TR output types. developer.bitcoin.org.
- [70] Pieter Wuille, Jonas Nick and Tim Ruffing, BIP 340 — Schnorr signatures for secp256k1. 2020. listed, not cited on a page
- [71] Pieter Wuille, Jonas Nick and Anthony Towns, BIP 341 — Taproot: SegWit version 1 spending rules (the output carries a public key). 2020.
- [72] Hunter Beast and others, BIP 360 — a quantum-resistant output type for Bitcoin. bitcoin/bips, 2024 onward.
- [73] Itan Barmes and Bram Bosch, Quantum computers and the Bitcoin blockchain — the share of coins in exposed-key outputs. Deloitte Netherlands.
- [74] Jameson Lopp, Christian Papathanasiou, Ludovic Perret, Kevin Le Bao and Trevor Ross, Post quantum migration and legacy signature sunset — a BIP draft. bitcoin-dev, July 2025. listed, not cited on a page
- [75] Bitcoin Optech, Topic: quantum resistance. bitcoinops.org. listed, not cited on a page
- [76] Clémence Chevignard, Pierre-Alain Fouque and André Schrottenloher, Reducing the number of qubits in quantum factoring — RSA-2048 with about 1730 logical qubits. Advances in Cryptology, CRYPTO 2025; IACR ePrint 2024/222.
- [77] Wang Chao and others (Shanghai University), reported by The Register, A 22-bit RSA integer factored on a D-Wave annealer — the 'China breaks RSA' story. Chinese Journal of Computers, 2024; The Register, 14 October 2024.
- [78] Wang Chao and others (Shanghai University), A first successful factorization of RSA-2048 integer by D-Wave quantum computer — on integers whose two primes differ in two low bits. Tsinghua Science and Technology, online 30 December 2024.
- [79] Microsoft and Quantinuum, Twelve logical qubits on the 56-qubit H2 trapped-ion machine. Microsoft Azure Quantum blog, 10 September 2024.
- [80] Adrian Cho, Science, Debate erupts around Microsoft's blockbuster quantum computing claims — Majorana 1. Science, 21 February 2025.
- [81] HPCwire, NIST selects HQC as fifth algorithm for post-quantum encryption. 12 March 2025.
- [82] South China Morning Post, China cracks another quantum code barrier — a 90-bit RSA integer on a D-Wave machine, reported without a paper. April 2025.
- [83] CoinDesk, Quantum computing group offers 1 BTC to whoever breaks Bitcoin's cryptographic key — the Q-Day Prize opens. 17 April 2025.
- [84] IBM, IBM sets the course to build the world's first large-scale, fault-tolerant quantum computer — Starling, 200 logical qubits by 2029. IBM Quantum blog, 10 June 2025.
- [85] Steve Tippeconnic, Quantum attack on a 5-bit elliptic curve key on IBM's 133-qubit ibm_torino. arXiv:2507.10592, July 2025.
- [86] Quantinuum, Commercial launch of Helios — 98 trapped-ion qubits, 48 error-corrected logical qubits. 5 November 2025.
- [87] The Next Platform, IBM lets fly Nighthawk and Loon QPUs on the way to quantum advantage. 12 November 2025.
- [88] Mark Webster, Lucas Berent, Sunil Chandra, Ewan Hockings, Nouédyn Baspin, Frederik Thomsen, Alexander Smith and Oscar Cohen (Iceberg Quantum), The Pinnacle architecture — RSA-2048 with fewer than 100,000 physical qubits on qLDPC codes. arXiv:2602.11457, February 2026.
- [89] Scott Aaronson, On the Pinnacle claim — serious work, engineering caveats, timeline effect unknown. Shtetl-Optimized, 15 February 2026.
- [90] Heather Adkins and Sophie Schmieg, Google, Google's post-quantum migration timeline — done by 2029. Google blog, 25 March 2026.
- [91] Ryan Babbush, Lev Zalcman, Craig Gidney, Michael Broughton, Tanuj Khattar, Hartmut Neven, Thiago Bergamaschi, Justin Drake and Dan Boneh, Resource estimates for breaking 256-bit elliptic curve keys — under 1,450 logical qubits, fewer than 500,000 physical, minutes of runtime. arXiv:2603.28846, 30 March 2026.
- [92] Ryan Babbush and Hartmut Neven, Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly. Google Research blog, 31 March 2026.
- [93] Caltech and Oratomic, Shor's algorithm is possible with as few as 10,000 reconfigurable atomic qubits. Caltech news, 31 March 2026.
- [94] Pranav Mundada and others (Q-CTRL), A heterogeneous architecture for RSA-2048 in 9.2 days on 381,000 physical qubits. arXiv:2604.06319, April 2026.
- [95] Project Eleven, The Q-Day Prize awarded for a 15-bit elliptic curve key recovered on IBM Heron processors. 24 April 2026.
- [96] Bitcoin.com News, IBM quantum hardware cracks 15-bit ECC key, but Bitcoin devs say random bits match the result. 24 April 2026.
- [97] Tian Xue and Jacob P. Covey, Distributed Shor's algorithm on a modular neutral-atom processor of half a million qubits. arXiv:2605.03951, May 2026.
- [98] The White House, Executive Order 14412 — Securing the nation against advanced cryptographic attacks. 22 June 2026.
- [99] Eric Lu (Cognition), Factoring RSA-260 — a GPU port of CADO-NFS, 4,923 GPU-days. 3 September 2026, written up 9 September.
- [100] Thomas Häner and 13 others (IonQ), Computing 256-bit elliptic curve discrete logarithms in 26 days on a fault-tolerant trapped-ion quantum computer with 20,000 qubits. arXiv:2609.05625, September 2026.
- [101] Stephen A. Weis (Anthropic), Factoring RSA-896 — CADO-NFS on idle data-centre GPUs, about 30 GPU-years in ten days. 19 September 2026.
- [102] Wikipedia contributors, Integer factorization records. Wikipedia, read September 2026.
- [103] Bruce Schneier, No, RSA is not broken — on Schnorr's claim. Schneier on Security, 5 March 2021.
- [104] Anthony Milton and Clara Shikhelman (Chaincode Labs), Bitcoin and quantum computing: current status and future directions. May 2025.
- [105] CoinDesk, reporting CoinShares, The quantum threat to Bitcoin is smaller than people think — 1.6 million BTC in P2PK. 9 February 2026.
- [106] Glassnode Research, via Yahoo Finance, 6.04 million BTC with the public key already visible on-chain. May 2026.
- [107] The Block, reporting Coinbase's advisory board, Coinbase quantum report flags exchange cold wallets among millions of bitcoin exposed by address reuse. 13 June 2026.
- [108] CoinDesk, Coinbase advisory board says the quantum computing threat is on the horizon. 21 April 2026.
- [109] Jameson Lopp, Christian Papathanasiou, Ludovic Perret, Kevin Le Bao and Trevor Ross, BIP 361 — Post quantum migration and legacy signature sunset. bitcoin/bips, draft, 2026.
- [110] Jameson Lopp, A post quantum migration proposal. bitcoindev mailing list, 13 July 2025.
- [111] Hunter Beast, Hourglass — rate-limiting spends from pay-to-pubkey outputs. bitcoindev mailing list, 30 April 2025.
- [112] Tadge Dryja, A commit-reveal soft fork for spending exposed keys after ECDSA is broken. bitcoindev mailing list, 29 May 2025.
- [113] CoinDesk, reporting BitMEX Research, Bitcoin devs float a quantum tripwire that triggers a coin freeze only if an attack is proven. 16 April 2026.
- [114] CoinDesk, reporting Jonas Nick and Mikhail Kudinov (Blockstream), SHRINCS — a hash-based post-quantum signature sized for Bitcoin blocks. 27 August 2026.
- [115] Bitcoin Optech, Newsletter #403 — the post-quantum discussion that week. 1 May 2026. listed, not cited on a page
- [116] Bitcoin Optech, Newsletter #412 — hybrid signatures in BIP-360 leaves. 3 July 2026. listed, not cited on a page
- [117] ethereum.org, Roadmap — quantum resistance. read September 2026.
- [118] Algorand Foundation, Quantum-resistant transactions on Algorand with Falcon signatures. 3 November 2025.
- [119] Michele Mosca and Marco Piani, Quantum threat timeline report 2025 — the expert survey. Global Risk Institute and evolutionQ, March 2026; summarised at postquantum.com.
- [120] The Quantum Insider, BlackRock updates its Bitcoin ETF prospectus with a broadened quantum computing warning. 13 May 2025.
- [121] CoinDesk, Google says post-quantum migration needs to happen by 2029 — and Bitcoin has no roadmap. 28 March 2026.
- [122] Casey Rodarmor, P2Q — a draft BIP for a SegWit version 3 output whose key path can later be switched off. draft on GitHub.
- [123] CoinDesk, Quantum-safe Bitcoin now possible without a soft fork, but costs $200 a pop. 10 April 2026.
- [124] CoinDesk, Provable address-control timestamps — a way to prove control without moving coins. 2 May 2026.
Data files
The rows behind the tables, as JSON, each with its source ids: timeline · records · claims · estimates · machines · developments · wallet · glossary · the hundred zeros · every computed number. All CC BY 4.0, credit "Nan · hongdam.net · CC BY 4.0".