technology 5 min read

RSA-260 'Cracked' in a Tweet—What It Means for Encryption

An engineer posted a single factor of RSA-260 on X without a paper or explanation. If verified, it breaks a 35-year record—but does not endanger everyday encryption. Here's why a Japanese outlet led the story and what happens next.

  • Elon Musk
  • Cybersecurity
  • Cryptography
  • RSA Factorization
  • AI and Security

A record broken without a press release

On September 3, an engineer named Eric Lu—listed on X as working for the US AI company Cognition—posted a 130-digit number alongside three words: “divides RSA-260.” No paper. No GitHub repository. No interview. Just a single tweet, and within hours, the post had drawn scrutiny from cryptographers worldwide.

If the claim checks out, Lu has just factored RSA-260, a 260-digit (862-bit) semiprime that has resisted decomposition since 1991. It would shatter the record set in 2020 by RSA-250—a 250-digit, 829-bit number—and become the largest integer ever factored under the RSA Factoring Challenge banner, even though the challenge itself was retired nearly two decades ago.

Why a Japanese outlet broke the story

ITmedia NEWS published the first prominent report in Japanese, not because the breakthrough originated there, but because the tweet contained a single numeric string that Chinese-search engines and Japanese tech communities immediately began verifying. When the numbers started adding up, Japanese outlets—long accustomed to covering the intersection of Silicon Valley culture and Asian markets—had a ready-made narrative: an American AI engineer, a Japanese-language tech ecosystem racing to validate it, and Elon Musk himself weighing in on the character limit that made the post possible.

Musk’s reply—that expanding X’s character limit had been a good call—was a light footnote to a milestone that actually dates back to the Clinton era. RSA Data Security launched the factorization challenge in 1991 as a public benchmark for computational progress. It closed in 2007, but the numbers kept calling to anyone with enough compute and patience.

The verification gap

Here is the uncomfortable truth: no one outside Lu’s own team knows how he did it.

Cryptographic practice demands that any factorization claim be accompanied by a methodology, a resource audit, and an independent path to replication. Lu offered none of that. What he did offer is mathematically testable—one of the two prime factors of RSA-260. Anyone with a calculator and the public value of RSA-260 can confirm whether multiplying his 130-digit number by the implied co-factor reproduces the challenge composite.

That test is likely already underway across multiple research groups. The absence of a methodology, however, means the community is working blind on the harder question: did Lu use a novel algorithm, or simply more brute-force compute? The distinction matters enormously for what this result implies about the state of encryption.

Quantum computing is not the story here

Several cryptographers have already noted that this factorization almost certainly has nothing to do with quantum computing. RSA-260, while a record-breaking feat for classical methods, sits far below the threshold where Shor’s algorithm on a fault-tolerant quantum computer would be required. Factoring RSA-260 classically is hard but routine for enough specialized hardware and time. The community’s immediate dismissal of a quantum angle suggests Lu’s approach was classical optimization, not quantum advantage.

That is not a downgraded story—it is an upgraded one. Classical factoring progress is slower, harder-won, and tells a different tale about where cryptographic boundaries actually sit.

What this does not mean for your bank account

RSA-260 operates at 862 bits. The RSA keys protecting most internet traffic today are 2,048 bits or larger. The difference is not incremental; it is generational. Moving from 862-bit security to 2,048-bit security is not like upgrading from a bicycle to a car. It is closer to the difference between a horse-drawn carriage and a jetliner. Each additional bit roughly doubles the computational effort required to break the key. At 2,048 bits, we are talking about effort measured not in years but in timescales that exceed the age of the universe for classical methods.

The practical takeaway is straightforward: no internet service, no banking protocol, no TLS connection you use daily is endangered by this result.

What this does mean

The real signal here is not about breaking encryption. It is about the sociology of how a cryptographic milestone gets announced and validated in 2025.

For decades, the RSA Factoring Challenge was a slow-moving academic contest. Records were published in journals, presented at conferences, peer-reviewed. Lu’s tweet bypassed all of that. He announced a world-record factorization the way someone might announce a personal best on social media—and the cryptography community had to scramble to catch up.

That shift is worth watching. If this claim verifies, it establishes a new precedent: that major cryptographic results can now debut as unreviewed social posts, with the community doing the verification work after the fact. The incentives are clear. A tweet is fast, shareable, and platform-native. A paper is slow, formal, and often paywalled. We are likely to see more of this.

The numbers that matter

  • RSA-260: 260 digits, 862 bits. The new classical factorization record.
  • RSA-250: 250 digits, 829 bits. The previous record, factored in 2020.
  • RSA-2048: 617 digits, 2,048 bits. The current standard for most secured communications.
  • The gap between RSA-260 and RSA-2048: roughly 1,186 bits, or about 2^1,186 times more computational work. No classical method closes that gap in any near-term timeframe.

What happens next

The immediate next step is independent verification of Lu’s factor. The public should expect a confirmation or retraction within days, not months—the arithmetic is trivially checkable if the posted number is correct.

The longer-term question is whether Cognition, a company whose public focus has centered on AI agents rather than number theory, will release a methodology paper. If they do, and if the approach is classical and scalable, it could signal that the rate of progress on integer factorization is accelerating faster than many cryptographers assumed. If they do not, the result will remain a remarkable but opaque benchmark, debated in forums and Slack channels rather than cited in standards documents.

Meanwhile, the NIST post-quantum cryptography transition—already underway to replace RSA and ECC with algorithms resistant to future quantum attacks—continues on its current timeline. This factorization does not change that roadmap. It does change how the world watches cryptographic milestones unfold.

The tweet that cracked a 35-year record did more than factor a number. It showed us a future where the announcement and the validation are no longer the same thing.