RSA Cryptosystem Faces New Classical Attack, But Security Experts Remain Cautious
The RSA cryptosystem has faced a new classical attack, but panic can wait. In September 2026, Eric Lu of Cognition factored the 862-bit RSA-260 challenge number using GPU-accelerated general number field sieve methods, at a cost of roughly $400,000.
This milestone has prompted a reassessment of how much runway RSA's older key sizes still have. The security of RSA relies on the difficulty of reversing-engineering large prime numbers from their product, but with increasing computing power and lower costs, even larger keys are now within reach.
Experts project that factoring an RSA-1024 key will cost around $30 million, a sum within reach of nation-states and well-resourced intelligence agencies. However, this threat was anticipated, and the deprecation of RSA-1024 was not just precautionary theater.
RSA-2048 remains secure against both current classical attacks and known quantum approaches. The computational cost of factoring climbs steeply with key size, meaning RSA-2048 sits in a different threat category for now.