RSA cryptosystem faces new classical attack, but widespread panic can wait

RSA cryptosystem faces new classical attack, but widespread panic can wait

A researcher factored an 862-bit RSA key using GPU computing, renewing questions about encryption timelines without triggering an immediate crisis.

On September 3, 2026, Eric Lu of Cognition factored the 862-bit RSA-260 challenge number using GPU-accelerated general number field sieve methods, at a cost of roughly $400,000. That is a meaningful milestone in computational number theory, and it has prompted a reassessment of exactly how much runway RSA’s older key sizes still have.

What just happened, and why it matters

RSA security rests on a deceptively simple problem: it is easy to multiply two large prime numbers together, but extremely hard to reverse-engineer the original primes from the result. The bigger the key, the harder the reversal.

Projections now place the computational expense of factoring an RSA-1024 key at around $30 million. That is not a trivial sum, but it is within reach of nation-states and well-resourced intelligence agencies. RSA-1024 is already deprecated precisely because this kind of threat was anticipated, but the research confirms that the deprecation was not just precautionary theater.

Advertisement

RSA-2048, the standard in active, widespread use today, remains secure against both current classical attacks and known quantum approaches. The computational cost of factoring climbs steeply with key size, meaning RSA-2048 sits in a different threat category entirely for now.

The quantum angle has not gone away

Shor’s algorithm, which runs on quantum hardware and can factor large numbers exponentially faster than any classical approach, remains the longer-term threat to RSA-2048. The migration toward post-quantum cryptographic standards, which the National Institute of Standards and Technology has been formalizing, starts to look less like long-term planning and more like medium-term necessity.

Allurity, a Stockholm-based cybersecurity group with roughly 800 specialists across 18 countries and a portfolio built through acquisitions including SRLabs, operates in the broader landscape where these cryptographic shifts play out. The firm covers identity management, threat intelligence, and related domains. No specific RSA research is directly attributed to Allurity itself.

What this means for crypto and digital security

For crypto infrastructure specifically, the immediate practical impact is close to zero. Bitcoin’s elliptic curve cryptography operates on different mathematical foundations than RSA factoring, and the attack vectors are distinct. Most blockchain networks do not rely on RSA in their core signing mechanisms.

Where RSA does appear in crypto-adjacent infrastructure is in transport layer security, certificate authorities, and legacy enterprise systems that interact with exchanges, custodians, and financial rails.

The $400,000 price tag on factoring RSA-260 is a useful reference point for security teams doing threat modeling. Attacks that cost hundreds of thousands of dollars are within reach of sophisticated criminal organizations, not just government actors. Security teams relying on anything below 2048-bit RSA should treat the current findings as a concrete prompt to migrate.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
RSA cryptosystem faces new classical attack, but widespread panic can wait
RSA cryptosystem faces new classical attack, but widespread panic can wait

A researcher factored an 862-bit RSA key using GPU computing, renewing questions about encryption timelines without triggering an immediate crisis.

On September 3, 2026, Eric Lu of Cognition factored the 862-bit RSA-260 challenge number using GPU-accelerated general number field sieve methods, at a cost of roughly $400,000. That is a meaningful milestone in computational number theory, and it has prompted a reassessment of exactly how much runway RSA’s older key sizes still have.

What just happened, and why it matters

RSA security rests on a deceptively simple problem: it is easy to multiply two large prime numbers together, but extremely hard to reverse-engineer the original primes from the result. The bigger the key, the harder the reversal.

Projections now place the computational expense of factoring an RSA-1024 key at around $30 million. That is not a trivial sum, but it is within reach of nation-states and well-resourced intelligence agencies. RSA-1024 is already deprecated precisely because this kind of threat was anticipated, but the research confirms that the deprecation was not just precautionary theater.

Advertisement

RSA-2048, the standard in active, widespread use today, remains secure against both current classical attacks and known quantum approaches. The computational cost of factoring climbs steeply with key size, meaning RSA-2048 sits in a different threat category entirely for now.

The quantum angle has not gone away

Shor’s algorithm, which runs on quantum hardware and can factor large numbers exponentially faster than any classical approach, remains the longer-term threat to RSA-2048. The migration toward post-quantum cryptographic standards, which the National Institute of Standards and Technology has been formalizing, starts to look less like long-term planning and more like medium-term necessity.

Allurity, a Stockholm-based cybersecurity group with roughly 800 specialists across 18 countries and a portfolio built through acquisitions including SRLabs, operates in the broader landscape where these cryptographic shifts play out. The firm covers identity management, threat intelligence, and related domains. No specific RSA research is directly attributed to Allurity itself.

What this means for crypto and digital security

For crypto infrastructure specifically, the immediate practical impact is close to zero. Bitcoin’s elliptic curve cryptography operates on different mathematical foundations than RSA factoring, and the attack vectors are distinct. Most blockchain networks do not rely on RSA in their core signing mechanisms.

Where RSA does appear in crypto-adjacent infrastructure is in transport layer security, certificate authorities, and legacy enterprise systems that interact with exchanges, custodians, and financial rails.

The $400,000 price tag on factoring RSA-260 is a useful reference point for security teams doing threat modeling. Attacks that cost hundreds of thousands of dollars are within reach of sophisticated criminal organizations, not just government actors. Security teams relying on anything below 2048-bit RSA should treat the current findings as a concrete prompt to migrate.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.