Claude ports CADO-NFS to GPUs and factors RSA-896 in 10 days on up to 2,048 scavenged GPUs
- Stephen A. Weis factored RSA-896 on September 19, 2026, after having Claude port CADO-NFS to run on GPUs and orchestrate a fleet on scavenged idle capacity, peaking at 2,048 GPUs for roughly 30 GPU-years over 10 days.
- Weis reports no new algorithmic factoring improvements from the run and no new threats to deployed keys, and a commenter corrects his claim that factoring is still exponential by pointing out the general number field sieve is subexponential.
- The statement Claude wrote about the result credits the people who built the number field sieve and CADO-NFS over several decades and the teams behind earlier records, since the run used their algorithm and much of their code.
- The factorization pays nothing: RSA Labs ended the $75,000 reward for RSA-896 in 2007, so the comment thread's bounty jokes have no payout behind them.
- Commenters argue the compute was effectively free only under flat rate electricity and cooling, that GPU mining is power-inefficient next to ASICs, and that a million-GPU fleet could plausibly attack 1,024-bit keys from recordings of not too old data.
Hacker News opinions
I had Claude port CADO-NFS to run on GPUs, then it orchestrated a fleet to run on scavenged idle capacity. Max of 2048 GPUs, about 30 GPU-years over 10 days.
So is it still exponential? The post says no new algorithmic improvements and no new threats to deployed keys.
It's actually subexponential, not exponential. That's the entire point of the general number field sieve.
10 days on 2048 GPUs. Back of the envelope, 1024-bit keys from recordings of not too old data can probably be found, and Microsoft only deprecated them in 2024 even though they planned it in 2013. What does it look like for the NSA with the equivalent of a million GPUs or crypto tuned ASICs?
If you've already paid for and reserved a whole cluster of GPUs, any idle capacity is capacity you've already paid for, so using it is effectively free. Might as well solve fun math puzzles with it. Though mining crypto would make more financial sense.
Only if you pay a flat rate for electricity and cooling.
How much crypto do you think 30 GPU-years would have produced at current exchange rates? They're not as efficient as ASICs but GPUs can still mine a lot.
GPUs are power-inefficient for mining most crypto, so not necessarily. You can end up paying more in electricity than you mine. Most crypto mining is on ASICs now.
Enjoy the bounty.
There is no bounty. RSA Labs ended the $75,000 reward back in 2007.
Kinda bearish for the data center rollouts if spare compute can be used to solve math puzzles instead of training LLMs.