Genie Generate a free company AI assistant Try it
← Back to Blog

Cognition Factors RSA-260: Why the GPU Result Does Not Mean RSA-2048 Is Broken

Cognition Factors RSA-260: Why the GPU Result Does Not Mean RSA-2048 Is Broken

Key Takeaways

  • Cognition reported factoring the 260-digit RSA-260 challenge number.
  • The work applies GPU engineering to a known classical factoring method.
  • The report does not demonstrate a practical RSA-2048 break.
  • Compute-cost projections and spare-capacity accounting are not interchangeable.
BLOOMIE
POWERED BY NEROVA

Produced by Bloomie for Nerova AI using automated editorial checks. Sources used for factual claims are listed below.

Cognition reported a factorization of RSA-260 on September 9, 2026, using a GPU implementation developed with Devin. The result advances a public factoring challenge. It does not demonstrate a practical break of RSA-2048 encryption.

The research account attributes the gain to engineering a known general number field sieve workflow for GPUs. Its headline tenfold cost improvement and estimates for larger numbers are the author’s reported results and projections, not measurements Nerova reproduced.

The CADO-NFS project documentation describes an existing implementation of the Number Field Sieve, with stages that can run across networked computers. That background supports reading the result as engineering progress on a known factoring method, rather than evidence of a newly discovered shortcut.

What was factored

RSA-260 is a 260-digit challenge number. RSA security depends in part on the difficulty of recovering factors for much larger numbers. A record at one size cannot be carried over to another size with a simple percentage improvement.

Cognition explicitly distinguishes the challenge result from RSA-2048 and says the latter is not meaningfully affected by this work. The relevant story is a reduction in the cost of a particular classical computation, not a quantum breakthrough or evidence that all secure communication has become readable.

The AI contribution is software and performance engineering

The author describes Devin modifying a CADO-NFS-based pipeline, optimizing GPU lattice sieving, and managing compute work under human priorities and measurements. The underlying technique is not presented as a new factoring algorithm.

This makes the result interesting beyond cryptography. An engineering agent can explore kernel designs and bottlenecks when it has an objective that can be measured. That does not remove the need to confirm correctness, compare against an appropriate baseline, and account for the resources used to obtain the result.

Read cost projections as projections

The account estimates about 4,900 GPU-days for the factorization and a roughly $400,000 market-value compute cost, while describing use of otherwise spare cluster capacity. Those are different accounting views: spare capacity can have low marginal cost to one lab without being inexpensive for a customer renting the same resources.

A procurement or security team should ask whether an estimate includes failed runs, setup, optimization, and the cost of maintaining the infrastructure. Similarly, a projection for a larger key size is not a completed factorization at that size. Preserve that distinction in risk assessments.

What security teams should do with the news

A reasonable response is to understand the organization’s cryptographic inventory and existing upgrade responsibilities. A dramatic research headline is not a reason to improvise new cryptography or perform an unplanned replacement of working security systems.

The CADO-NFS project supplies context for the established software family mentioned in Cognition’s account. The result demonstrates why security-sensitive computational work needs inspectable artifacts and precise claims. It does not establish a new vulnerability in every product that uses RSA.

Nerova’s assessment is that this is a significant agent-assisted scientific computing case study. Its strongest operational lesson is the combination of measurable objectives, bounded compute, and human judgment about when optimization is going off track. The cryptographic implications should remain tied to the sizes and assumptions actually discussed.

Nerova context

Custom AI agents for business operations

Nerova builds custom AI agents for business operations. Companies use Nerova when they need AI support for customer intake, support, sales follow-up, research, website audits, internal handoffs, and workflow automation.

Nerova can help turn websites, business context, and operational workflows into practical AI systems: website chatbots, single-purpose agents, AI teams, audits, and automation workflows built around a clear business outcome.

Ask Bloomie about this article