Cognition published a factorization of RSA-260 this week, a 260-digit number from the old RSA Factoring Challenge. That makes it the largest publicly solved RSA challenge number, beating RSA-250, which had held the record since February 2020. The interesting part is not the number itself. It is who did the work and what it cost.
Not a quantum computer, not guesswork
Social media produced some creative theories after the announcement, so the Cognition team addressed them directly: nobody guessed 130-digit primes by hand, and there is no multi-thousand-qubit quantum machine hiding in the lab. RSA-260 was factored the classical way, with a general number field sieve, the most efficient known method for numbers above roughly 100 digits. What changed is the hardware target. The team modified CADO-NFS, the standard open source GNFS implementation, to run its lattice sieving and sparse linear algebra on GPUs. By their account this involved no new algorithms, just serious performance engineering aimed at GPU memory systems.
The human role was also unusual. A researcher set priorities, defined benchmarks, and steered when things drifted. Autonomous Devin agents handled the rest end to end: measurements, cluster operations, and optimization. The result is a GPU lattice siever the team claims beats the previous public state of the art by roughly 10x on cost.
The bill
The full run consumed about 4,900 GPU-days, or 13.5 GPU-years, which prices out around $400k at current market rates. It ran as a side project on a single-digit percentage of Cognition’s cluster while the team was really working on job scheduler improvements for disaggregated compute. The stage breakdown shows where the time went: 643 GPU-days on polynomial selection (flagged as anomalously high due to operator error), 3,813 GPU-days sieving, and 467 GPU-days solving the linear system.
Should RSA-2048 deployments worry?
Short answer: no, but watch the trend line. Standard GNFS scaling puts RSA-1024, a 309-digit problem, at only 78 times the computation of RSA-260. At market GPU prices that works out to roughly $30 million per number, and the author notes the current implementation is still meaningfully suboptimal, so another 2x cost reduction seems plausible. That is squarely within reach of hyperscalers and frontier AI labs, and well below what most threat models assumed for nation-state-only budgets.
RSA-2048, the size used in most real certificates today, remains about a billion times harder than RSA-1024. It is not meaningfully affected by this work. But 1024-bit RSA was deprecated back in 2013 precisely because of projections like this one, and the cost curve is bending faster than the projections assumed. If you still have 1024-bit keys anywhere, this post is your reminder that the deadline already passed.
Why this matters beyond crypto
The deeper story is about who can run this kind of research. A decade ago, factoring a 260-digit number required a specialized team and months of calendar time. Here, one researcher with a pool of coding agents produced a record result as a side project. Cognition’s own conclusion is that the barrier to entry for cryptanalysis, computational number theory, and large-scale scientific computing in general has dropped dramatically.
For security teams, two things follow. First, cost estimates in your threat model that assume expensive, slow cryptanalysis deserve a second look. Second, agents are now credible instruments for real performance engineering, not just boilerplate generation. The sieve parameters published in the post, down to the lattice bounds and GPU kernel vectors, read like the output of an experienced HPC team. They were largely machine-produced.
The sieve, briefly
It is worth understanding what the GPU switch actually bought. In GNFS, the sieving stage dominates cost: it hunts for smooth relations, numbers whose prime factors all sit below a chosen bound, across billions of candidate values. The classic CADO-NFS runs this on CPUs and parallelizes across machines. Reworking it around GPU memory bandwidth changes the economics of that stage entirely, and the linear algebra stage, solving a huge sparse system with Krylov methods, moved onto GB200 and GB300 nodes with NCCL for communication. The published timeline shows the whole pipeline, from polynomial selection through the final square root step, completing in under six days of wall clock time once sieving data was in hand. The final GCD extraction pulled out a 106-digit, a 117-digit, and a 163-digit prime whose product is the 260-digit semiprime.
Nobody should read this as a break in RSA itself. The general number field sieve was invented in the late 1980s, its complexity curve is unchanged, and the writeup introduces no new algorithm. What moved is the constant factor, by an order of magnitude, on hardware any large organization can rent. Cryptographic margins are designed against best-known implementation cost curves, and when that curve shifts 10x, margin calculations built on the old curve quietly go stale.
The agent angle deserves scrutiny
It is fair to be skeptical of agent-built infrastructure claims. HPC performance work is famously unforgiving: wrong vectorization choices, cache-unfriendly layouts, and silent numerical bugs all produce plausible-looking garbage. The mitigating evidence here is that the result is checkable. The factorization either multiplies out or it does not, and it does. Devin agents produced a verifiable mathematical result by building and tuning a complex system, which is a stronger demonstration than most agent benchmarks offer. That said, the author’s own framing is careful: his role was benchmarks and steering, which is to say the evaluation harness was the human contribution. That is likely the durable pattern. Agents do the optimization grind, humans own the ground truth.