RSA-896 Factored With Claude Using a GPU Number Field Sieve

Stephen Weis reports factoring the 270-digit RSA-896 after Claude ported CADO-NFS to GPUs, using about 30 GPU-years. He says deployed RSA-2048 keys are unaffected.

A 270-digit challenge number, factored

Stephen Weis, a member of technical staff at Anthropic, reported that he factored RSA-896, a 270-digit, 896-bit number from the RSA factoring challenge, with Claude on September 19, 2026. Claude ported the CADO-NFS implementation of the general number field sieve to run on GPUs and orchestrated the job across up to 2,048 GPUs at Anthropic as a low-priority task in idle time, running for ten days and about 30 GPU-years of compute. Weis did not say which Claude model he used. [1][3]

His post publishes the two 135-digit factors. OfficeChai multiplied them and confirmed they reproduce RSA-896; the multiplication is trivial for anyone to repeat, although the compute figures are Weis's own. [1][2]

A faster run, not a new method

Weis wrote that the work did not meaningfully improve the runtime of the number field sieve and does not affect the security of deployed RSA-2048 keys, but that it shows RSA-1024 keys are vulnerable to many actors with data-center fleets of GPUs. [1]

Atlas interpretation: The contribution is engineering: an AI model porting a mature research codebase to new hardware and running it at scale on spare capacity. It was the second such result in a month: on September 9, Cognition's Eric Lu had published his factoring of the 260-digit RSA-260 with a GPU-accelerated CADO-NFS built and run by Devin agents. The RSA-1024 warning is Weis's inference from the compute used, not a separate measurement. [1][2][3]

Sources

  1. RSA-896

    Stephen A. Weis · Sep 19, 2026

  2. Claude Helped Factor RSA-896, A 270-Digit Encryption Challenge, Says Anthropic Engineer

    OfficeChai · Sep 20, 2026

  3. RSA-896 Has Been Factored. Steve Weis Reports Factoring RSA-896 Using Claude

    Quantum Zeitgeist · Sep 21, 2026