A team using the CADO-NFS software factored RSA-250, an 829-bit number, in February 2020 using roughly 2,700 CPU-core-years of computation on the general number field sieve, the most efficient known classical factoring algorithm for numbers of this size. It remains the largest classically factored RSA challenge semiprime as of 2026, underscoring why standards bodies now recommend RSA key sizes of at least 2,048 or 3,072 bits for long-term security.
The question, scope, and sources behind this Registry record.
A team using the CADO-NFS software factored RSA-250, an 829-bit number, in February 2020 using roughly 2,700 CPU-core-years of computation on the general number field sieve, the most efficient known classical factoring algorithm for numbers of this size. It remains the largest classically factored RSA challenge semiprime as of 2026, underscoring why standards bodies now recommend RSA key sizes of at least 2,048 or 3,072 bits for long-term security.
The bit length of RSA-250, an 829-bit (250-decimal-digit) semiprime from the RSA Factoring Challenge, factored in February 2020 using the general number field sieve — the largest RSA modulus publicly factored by classical computation as of 2026.
Change a parameter to stress-test whether a proposed result is still inside the published specification. This is an audit aid, not a proof checker.
This record has no editable parameters. Read the formal question and assumptions before challenging it.
Current frontiers derived from accepted Claims.
An observed or demonstrated result; no opposing bound is implied.
The frontier is not sacred
Most progress starts with a disagreement that survives contact with evidence. If you can push the known lower bound up or pull the upper bound down, show us the work.
≥ when you have shown that at least this value is achievable.≤ when you have shown that anything above this value is impossible.No vibes. State the value, define the scope, and link the paper, proof, code, or reproduction that lets another person check it. Editors review every challenge before the public record changes.
Challenge this recordAssertions tied to evidence, attribution, and review.
The frontier as it changed over time.
Only accepted Claims matching the current specification contribute to the displayed bounds. Strict inequalities remain open; contradictory Claims require editorial review.
1 accepted Claim, with 1 linked evidence records.
Permanent ID limitsregistry.com/limits/LR-RSA250-FACTORING-RECORD
No active verified bounties are linked to this Limit.
View verified bounty tracker ↗No accepted machine-checked reproductions are recorded for this Limit.
Limits Registry. LR-RSA250-FACTORING-RECORD. Largest RSA-type number factored by classical computation. 2026.