Computing & AIPreprintExperiment3 min read

A 155-DIGIT NUMBER SPLIT ON GRAPHICS CARDS

Splitting a large number into its prime factors is hard, and that difficulty matters to cryptography — which is why the paper takes care to say what its result does not threaten. Public “RSA challenge” numbers serve as benchmarks for factoring methods. RSA-155 is one of them: 155 digits, or 512 bits.

Two sieves, one record each

Two families of algorithms dominate. The number field sieve is the champion for very large numbers: it split RSA-155 back in 1999, and, according to the paper, the general record now stands at a 270-digit number, RSA-896, in 2026. The older quadratic sieve is asymptotically slower and, in the authors’ own words, “the wrong tool” for general records. It has its own record list, though: the largest number split with it was RSA-150, in June 2025, using 11,664 CPU core-hours.

The quadratic sieve hunts for many small numbers that factor completely over a set of small primes, then uses linear algebra to combine them into two squares x² and y² that are equal modulo N. A greatest common divisor then reveals a factor. On a computer, this is a nightmare for graphics processors (GPUs): memory accesses scatter far beyond any cache, the tests are full of branches, and the final algebra works in a binary arithmetic that no vendor library supports. Earlier GPU efforts accelerated individual steps only.

Everything on the graphics card

Fabian Januszewski and Christoph Heinrichs, of Paderborn University’s mathematics institute in Germany, built CUDA-MPQS, an open-source quadratic sieve in which every stage — preparing the polynomials, sieving, checking candidates, matching partial results, building the matrix, solving it and taking the final square root — runs on the GPU. The ordinary processor only orchestrates, sets up and handles input and output; the authors list the few remaining host-side steps explicitly. On a 100-digit test, the GPU was busy 99.9% of the sieving time, with no pause to wait for the processor.

Scaling up exposed a subtle bug. At RSA-155’s size, an 8-bit counter used during sieving overflowed on exactly the most valuable candidates, silently discarding 98 to 99.5% of them. The team replaced it with a saturating counter that they prove gives identical results.

RSA-155 in about a day

On 14 July 2026, the pipeline split RSA-155 into two prime numbers of 78 digits each, checked both on the GPU and on the host:

  • Sieving: 64 NVIDIA H100 GPUs across 16 nodes, 10.8 hours, collecting about 17.3 million relations.
  • Linear algebra: a single H100 for 10.9 hours, on a matrix of 16.7 million rows with 684 million non-zero entries.
  • Total: 700.6 GPU-hours and 242 kilowatt-hours, roughly 24 hours from start to factors. Sieving was 98.4% of the cost.

To the authors’ knowledge, this is the largest integer ever factored by the quadratic sieve, five digits beyond the previous record — and achieved with the simplest variant of the method, which keeps only one “large prime” per relation where recent records used three.

Faster than the best processors

On a 100-digit number, a single H100 finishes in 29.2 seconds, and a consumer RTX 5070 Ti in 51 seconds. In a controlled comparison on the same number, with energy measured on both sides, one H100 was 3.6 to 4.2 times faster than the fastest CPU quadratic sieve running on 96 cores of an AMD EPYC processor, and about nine to ten times faster than another standard package. They also refactored RSA-150 in 302.9 GPU-hours, against the previous record’s 11,664 core-hours — a ratio the authors stress is not a like-for-like speedup.

No threat to encryption

The authors are explicit: RSA-155 had already been factored, this is not a general factoring record, and “nothing here narrows a security margin”. The code is also capped by design at about 155 digits. Their interest lies elsewhere: showing that an irregular, branch-heavy algorithm can live entirely on a GPU. They point to the GPU lattice siever at the heart of the number field sieve as the natural next target — work that, they note, others have since begun, factoring RSA-260 and RSA-896 with GPU ports of an existing package, the latter made with Claude.

Conflict of interest. The authors state that generative AI and agentic coding tools were used: Anthropic’s Claude models (via Claude Code) along with OpenAI’s GPT and Google’s Gemini models for software development, and Claude models for data and manuscript preparation. They state that all AI output was manually reviewed and verified. Claude also wrote the present article.

Legal notice