Breaking · Threat Intelligence
RSA-260 Was Just Factored: Why It Doesn't Change Your Quantum Timeline
September 6, 2026 · PQCClear · 4 minute read
A viral social media post this week claimed a researcher had cracked part of RSA encryption using little more than persistence. The headline is real. The alarm it's generating mostly isn't. Here's what actually happened, and why it doesn't move your institution's quantum-readiness timeline at all.
Earlier this week, an engineer named Eric Lu announced he had factored RSA-260, the largest number in the long-running RSA Factoring Challenge ever successfully broken. The claim went viral fast, in part because of Lu’s own tongue-in-cheek description of the method as “good old paper and pencil.” The real story is more mundane, and more reassuring, than the headline suggests.
What Actually Happened
RSA-260 is a specific 260-digit challenge number published decades ago by RSA Security as part of an academic factoring contest. Factoring it, finding the two secret prime numbers multiplied together to create it, is exactly the kind of problem that makes RSA encryption work: multiplying two large primes is easy, but working backward from the result is deliberately, extremely hard.
Lu’s factoring effort took roughly seven months of computer-assisted prime testing, not the sieving technique used in the last record (RSA-250, set in 2020), and despite some early confusion, it wasn’t AI-assisted either. It’s a genuine, non-trivial achievement in computational number theory. It is not, however, a crack of the RSA encryption your institution or its vendors actually rely on.
The Number That Actually Matters
~863 bits
RSA-260, the challenge number just factored
2,048 bits
Minimum key length in production systems today
7 months
Compute time behind the new record
That gap matters more than it might look on paper. Because factoring difficulty grows exponentially as key length increases, a key twice as long isn’t twice as hard to factor. It is astronomically harder, well beyond what any realistic increase in classical computing power could close in the foreseeable future. Even Emmanuel Thomé, a researcher involved in the 2020 RSA-250 record, described RSA-260 as roughly three times as computationally expensive as RSA-250, still nowhere close to the scale separating it from real-world key sizes.
What Actually Threatens RSA
The reason this story is worth covering at all, rather than dismissing outright, is that it sits right next to the topic that genuinely does matter: quantum computing. Classical computers, no matter how many of them you throw at the problem, remain fundamentally bad at factoring large numbers. A sufficiently powerful quantum computer would not be.
What just happened
A classical factoring record
- Difficulty climbs exponentially with key length, so every bit added costs more than the one before it.
- Roughly seven months of compute to break an 863-bit number.
- No credible path from here to a 2,048-bit production key, however much hardware is added.
What the deadlines are about
A cryptographically relevant quantum computer
- Shor's algorithm factors in polynomial rather than exponential time, which removes the difficulty curve entirely.
- Breaks RSA and elliptic curve cryptography at the key sizes in production use today.
- Does not exist yet, which is precisely why the migration windows carry dates.
That distinction is the entire basis for the post-quantum migration timeline this blog has covered extensively, and this week’s RSA-260 record doesn’t accelerate it by a single day, because it didn’t use anything resembling quantum computing.
A bigger classical crack is still nowhere near the real threat. Only a different kind of computer changes that equation.
Put simply: this week’s news is a genuine mathematical achievement, a useful reminder of how RSA actually works, and not a reason to move any deadline on your institution’s own PQC migration plan.
What to Do With This, Practically
- 01
If this comes up in a board or risk conversation, address it directly. A short, accurate explanation, that this was a small academic number rather than production-scale RSA and that classical computers still are not the real threat, closes the question far better than silence would.
- 02
Don't let this news distract from the actual timeline. The regulatory and quantum-readiness deadlines already in motion, EO 14412, OMB M-26-15, and the Treasury Quantum-Readiness Task Force, remain exactly where they were before this story broke.
- 03
Use it as a teaching moment, not a talking point to avoid. Stories like this are a good, low-stakes way to build organizational literacy on the actual difference between classical and quantum cryptographic risk.
Track the real risk, not the headline
PQCClear helps banks, credit unions, and payment processors assess quantum readiness across their fintech vendor portfolio, producing a Quantum Readiness Score, a full CBOM, and an examination-ready report for each one, grounded in the actual threat timeline rather than the news cycle.
Request accessThis post represents the editorial analysis of PQCClear as of September 6, 2026. It should not be construed as technical or legal advice.
Key sources: Peter Hall, “Was this record-setting encryption crack a fluke, or the new normal?” Scientific American (September 4, 2026); Executive Order 14412 (whitehouse.gov, June 22, 2026); OMB M-26-15 (whitehouse.gov, June 24, 2026).