Corroboration · RSA records, claims graded since 2026

The Factoring Claims Register

Successor to the RSA Factoring Challenge (1991-2007)

Only locked counts

Stats

The 77-claim census, the 54-number catalogue, and the classical and quantum resource frontiers. Every chart is derived locally and paired with its exact data table and provenance labels.

At a glance

Claims · broke RSA

77

0 substantiated · 0 actually broke RSA.

2019–2025 physical-qubit estimate change

22×

20,000,000 → 897,864; runtime grew and neither is a factorisation.

Largest real gate-model Shor factorisation

21

Compiled small-instance hardware result; not RSA scale.

Historical RSA records

54

23 factored · 31 open.

The 77-claim census

Provenance: sweep/live-claims.jsonl

Claim class

49 of 77 are C4 / quantum

Live claim classesThe 77 claims divide into one C1, fourteen C2, thirteen C3 and forty-nine C4 records.C1: 11C1C2: 1414C2C3: 1313C3C4: 4949C4

Literal status

Exact count: 0 substantiated

Six distinct claim statusesThe six status counts are twelve refuted, eighteen unsubstantiated, eleven estimate not demonstration, twenty-four special structure only, eleven open and one withdrawn.refutedrefuted: 1212unsubstantiatedunsubstantiated: 1818estimate-not-demonstrationestimate-not-demonstration: 1111special-structure-onlyspecial-structure-only: 2424openopen: 1111withdrawnwithdrawn: 11

What this means: class and status answer different questions. A narrow hardware result can be real while its general RSA implication remains special-structure-only or open. The six literal status words are not collapsed.

Exact labels and tables carry the meaning; colour is supplementary.
Exact live-claim data
Live claims by stream
Claim streamCount
C11
C214
C313
C449
Live claims by literal status
Literal statusCount
substantiated0
refuted12
unsubstantiated18
estimate-not-demonstration11
special-structure-only24
open11
withdrawn1

The claim stream, 1993–2026

Provenance: sweep/live-claims.jsonl
  • C4 / quantum: 49 of 77
  • C1–C3
  • 2019–2025: 41 of 77
Claims per year from 1993 through 2026The bars total seventy-seven claims. Forty-one are dated 2019 through 2025, and forty-nine of the full census are C4 quantum claims.2019–2025: 41 of 77 claims1993: 0 C4 / quantum claims1993: 1 other claims19931994: 0 C4 / quantum claims1994: 1 other claims1995: 0 C4 / quantum claims1995: 0 other claims19951996: 0 C4 / quantum claims1996: 0 other claims1997: 0 C4 / quantum claims1997: 0 other claims1998: 0 C4 / quantum claims1998: 0 other claims19981999: 0 C4 / quantum claims1999: 1 other claims2000: 0 C4 / quantum claims2000: 0 other claims2001: 1 C4 / quantum claims2001: 2 other claims20012002: 0 C4 / quantum claims2002: 1 other claims2003: 0 C4 / quantum claims2003: 1 other claims2004: 0 C4 / quantum claims2004: 0 other claims20042005: 0 C4 / quantum claims2005: 0 other claims2006: 0 C4 / quantum claims2006: 1 other claims2007: 2 C4 / quantum claims2007: 2 other claims20072008: 1 C4 / quantum claims2008: 0 other claims2009: 1 C4 / quantum claims2009: 2 other claims2010: 0 C4 / quantum claims2010: 0 other claims20102011: 1 C4 / quantum claims2011: 0 other claims2012: 2 C4 / quantum claims2012: 2 other claims2013: 2 C4 / quantum claims2013: 1 other claims20132014: 1 C4 / quantum claims2014: 0 other claims2015: 0 C4 / quantum claims2015: 1 other claims2016: 1 C4 / quantum claims2016: 0 other claims20162017: 2 C4 / quantum claims2017: 0 other claims2018: 2 C4 / quantum claims2018: 0 other claims2019: 4 C4 / quantum claims2019: 1 other claims20192020: 4 C4 / quantum claims2020: 0 other claims2021: 4 C4 / quantum claims2021: 2 other claims2022: 4 C4 / quantum claims2022: 1 other claims20222023: 5 C4 / quantum claims2023: 0 other claims2024: 4 C4 / quantum claims2024: 3 other claims2025: 5 C4 / quantum claims2025: 4 other claims20252026: 3 C4 / quantum claims2026: 1 other claims2026

What this means: the stream clusters with the quantum-publicity cycle. That is a pattern in this curated set, not a causal claim and not a census of every public statement.

Bars show the record year. The shaded range foregrounds 2019–2025; stacked colour distinguishes C4 from C1–C3 without changing the annual total.
Exact annual claim data
Claims per year, including zero-count years
YearAll claimsC4 / quantumC1–C3
1993101
1994101
1995000
1996000
1997000
1998000
1999101
2000000
2001312
2002101
2003101
2004000
2005000
2006101
2007422
2008110
2009312
2010000
2011110
2012422
2013321
2014110
2015101
2016110
2017220
2018220
2019541
2020440
2021642
2022541
2023550
2024743
2025954
2026431

The resource frontier

Two evidence streams answer different questions. The classical staircase records completed general-purpose factorisations. The quantum trajectory records engineering estimates for a future RSA-2048 run and keeps those estimates separate from real-hardware demonstrations.

Do not compare the 2026 quantum marks as a single improving time series. They exchange physical qubits for runtime under architecture-specific assumptions.

Classical general-purpose record staircase

Provenance: sweep/classical-records.jsonl; plain tracker-1 refs in table
Classical factorisation record staircase by bit length and yearThe exact locked bit series rises from RSA-129 at 426 bits in 1994 to RSA-250 at 829 bits in 2020. Four digit-labelled milestones with null bit counts remain in the table and are not guessed onto the chart.4005006007008001994199920042009201420192020RSA-129: 426 bits in 1994RSA-129 426RSA-155: 512 bits in 1999RSA-155 512RSA-160: 530 bits in 2003RSA-160 530RSA-576: 576 bits in 2003RSA-576 576RSA-200: 663 bits in 2005RSA-200 663RSA-768: 768 bits in 2009RSA-768 768RSA-240: 795 bits in 2019RSA-240 795RSA-250: 829 bits in 2020RSA-250 829YearBits

What this means: the locked exact-bit record rose from 426 bits in 1994 to 829 bits in 2020: 403 bits, or 94.6%. Progress is real but stepwise. Four milestones with null bit counts remain not locked in local evidence and are not estimated from their decimal digits.

The line steps only through the eight milestones with locked bit counts. All 12 milestones remain in the exact table.
Exact 12-milestone data
Classical general-purpose record milestones
DateRecordDigitsBitsMethodEvidencePlain provenance refs
1994-04-26RSA-129129426PPMPQS/MPQS quadratic sieveverifiedtracker-1:SRC-R129-ANN; tracker-1:SRC-R129-SURVEY
1996-04-10RSA-130130not locked in local evidenceNumber field sieveverifiedtracker-1:SRC-R130-PAPER; tracker-1:SRC-RECORDS
1999-02-02RSA-140140not locked in local evidenceNumber field sieveverifiedtracker-1:SRC-R140-PAPER; tracker-1:SRC-RECORDS
1999-08-22RSA-155155512GNFSverifiedtracker-1:SRC-R155-PAPER
2002-01-18C158158not locked in local evidenceNumber field sieveverifiedtracker-1:SRC-C158-ANN; tracker-1:SRC-RECORDS
2003-04-01RSA-160160530GNFSsecondarytracker-1:SRC-R160-SECONDARY
2003-12-03RSA-576not locked in local evidence576not locked in local evidenceverifiedtracker-1:SRC-R576-ANN; tracker-1:SRC-RECORDS
2005-05-02C176176not locked in local evidencenot locked in local evidenceverifiedtracker-1:SRC-C176-ANN; tracker-1:SRC-RECORDS
2005-05-09RSA-200200663GNFSverifiedtracker-1:SRC-R200-ANN
2009-12-12RSA-768232768GNFSverifiedtracker-1:SRC-R768-PAPER
2019-12-02RSA-240240795GNFS with CADO-NFSverifiedtracker-1:SRC-RECORDS; tracker-1:SRC-R240-ANN; tracker-1:SRC-R240250-PAPER
2020-02-28RSA-250250829GNFS with CADO-NFSverifiedtracker-1:SRC-R250-ANN; tracker-1:SRC-R240250-PAPER

Effort is not charted: the rows mix MIPS-years, heterogeneous CPU-years, reference-core-years, and stage-only versus total costs.

Quantum RSA-2048 resource-estimate trajectory

Provenance: sweep/quantum-estimates.jsonl; plain tracker-2 refs in tables
  • Closest like-for-like surface-code estimates
  • 2026 architecture-dependent estimates: separate, not like-for-like
RSA-2048 physical-qubit estimates by yearA line connects the closest like-for-like surface-code estimates: twenty million physical qubits in 2019 and 897,864 in 2025. Eight numbered 2026 architecture-dependent qubit-runtime trade-offs are separate marks with no continuation of the line.10k100k1m10m20m2019: 20,000,000 physical qubits; 0.31 days, about 7.4 hours; title rounds to 8 hours20,000,00020192025: 897,864 physical qubits; 12.07 hours per shot; 4.96 days expected per factorisation; headline says less than one week897,86420252026 mark 1: 11,033 physical qubits; Approximately 4.3 × 10^4 days; RSA-2048, neutral-atom space-efficient12026 mark 2: 13,255 physical qubits; Approximately 1.0 × 10^4 days; RSA-2048, neutral-atom balanced22026 mark 3: 94,000 physical qubits; At most one month expected; RSA-204832026 mark 4: 102,000 physical qubits; 97 days; RSA-2048, neutral-atom time-efficient42026 mark 5: 190,000 physical qubits; 9.2 days; RSA-2048, hypothetical qLDPC long-range memory52026 mark 6: 381,000 physical qubits; 9.2 days; RSA-2048, heterogeneous grid-coupled architecture62026 mark 7: 439,000 physical qubits; 4.9 days; RSA-2048, heterogeneous architecture with adder accelerator72026 mark 8: 512,500 physical qubits; 190.4 days per shot; 9.2 shots expected; RSA-2048, six-module atomic DShor82026 architecture-dependent setSeparate marks: qubits traded against runtime; not like-for-likePhysical qubits · log scale

What this means: the closest surface-code pair falls from 20,000,000 modelled physical qubits in 2019 to 897,864 in 2025, a 22.3× reduction, while expected runtime moves from about 7.4 hours to 4.96 days. The 2026 points trade qubits for runtime under different codes, connectivity, cycle times and memory assumptions, so they are not a continuation of that line.

Log scale. Numbered 2026 marks map to the table. The 2021 value of 13,436 is not plotted because it excludes the enormous multimode memory.
Exact 15 estimate rows
Quantum resource estimates, including unplotted context
DateTargetLogical qubitsPhysical qubitsRuntimeChart treatmentEvidencePlain provenance refs
2019-05-23RSA-2048618920,000,0000.31 days, about 7.4 hours; title rounds to 8 hourslike-for-like trend lineverifiedtracker-2:E01
2021-03-10RSA-2048828413,436177 daysseparate 2026 architecture mark 3verifiedtracker-2:E02
2022-01-20RSA-2048, Beauregard circuit409913,500,0001.89 × 10^7 hoursnot plotted: different design / runtime trade-offverifiedtracker-2:E03
2022-01-20RSA-2048, Pavlidis circuit18434648,000,0001.16 × 10^5 hoursnot plotted: different design / runtime trade-offverifiedtracker-2:E03
2024-02-13RSA-20481730not locked in local evidencenot locked in local evidenceseparate 2026 architecture mark 3verifiedtracker-2:E04
2025-05-21RSA-20481537897,86412.07 hours per shot; 4.96 days expected per factorisation; headline says less than one weeklike-for-like trend lineverifiedtracker-2:E05
2026-02-12RSA-2048not locked in local evidence94,000At most one month expectedseparate 2026 architecture mark 3verifiedtracker-2:E06
2026-03-30RSA-2048, neutral-atom space-efficient139911,033Approximately 4.3 × 10^4 daysseparate 2026 architecture mark 1verifiedtracker-2:E07
2026-03-30RSA-2048, neutral-atom balanced139913,255Approximately 1.0 × 10^4 daysseparate 2026 architecture mark 2verifiedtracker-2:E07
2026-03-30RSA-2048, neutral-atom time-efficient6144102,00097 daysseparate 2026 architecture mark 4verifiedtracker-2:E07
2026-04-07RSA-2048, heterogeneous grid-coupled architecture1399381,0009.2 daysseparate 2026 architecture mark 6verifiedtracker-2:E08
2026-04-07RSA-2048, heterogeneous architecture with adder accelerator1436439,0004.9 daysseparate 2026 architecture mark 7verifiedtracker-2:E08
2026-04-07RSA-2048, hypothetical qLDPC long-range memory1399190,0009.2 daysseparate 2026 architecture mark 5verifiedtracker-2:E08
2026-05-05RSA-1024, six-module atomic DShornot locked in local evidence296,24027.4 days per shotnot plotted: RSA-1024 targetverifiedtracker-2:E09
2026-05-05RSA-2048, six-module atomic DShornot locked in local evidence512,500190.4 days per shot; 9.2 shots expectedseparate 2026 architecture mark 8verifiedtracker-2:E09
Exact 17 real-hardware demonstration rows
Real-hardware demonstrations: actuality check
DateTargetLogical qubitsPhysical qubitsMethod / assumptionsCaveatEvidencePlain provenance refs
2001-12-3015 = 3 × 5not locked in local evidence7Liquid-state NMR using seven spin-1/2 nuclei; simplest compiled Shor instance.Compiled for 15; the authors explicitly state that scalability is not implied.verifiedtracker-2:D01
2007-05-1115 = 3 × 5not locked in local evidence4Linear-optical photonic circuit with modular exponentiation and semiclassical QFT.The known period r=2 and selected N=15 were used to simplify the network; this is answer-dependent compilation, not a general-size Shor circuit.verifiedtracker-2:D02
2009-11-0615 = 3 × 5not locked in local evidence4Integrated silica-on-silicon photonic chip using four single-photon qubits.The target and modular exponentiation were compiled specifically for 15.verifiedtracker-2:D03
2011-11-16143 = 11 × 13not locked in local evidence4Adiabatic factorisation on a liquid-crystal NMR processor, not Shor; classical algebra reduced the target before the quantum run.A later analysis reports that the same four-qubit Hamiltonian represents several larger selected targets, showing that printed integer size does not track experimental difficulty.secondarytracker-2:D11; tracker-2:D12
2012-10-2121 = 3 × 7, order-finding onlynot locked in local evidence2Two-photon iterative compiled order finding with higher-dimensional work states and a recycled control qubit.A later full-factorisation paper reports that only two output bits were obtained, insufficient for continued fractions; do not register this as uncontested complete factorisation of 21.secondarytracker-2:D04; tracker-2:D08
2015-07-3115 = 3 × 5711Trapped-ion Kitaev/Shor structure using seven effective algorithm qubits plus four cache qubits via recycling; reported success above 90%.Still an N=15 implementation with instance optimisations, although later modular multipliers avoided reliance on prior knowledge of the solution.verifiedtracker-2:D05
2018-04-08Largest row: 376,289 = 571 × 65994not locked in local evidenceD-Wave 2000Q annealing, not Shor; multiplication mapped to an Ising optimisation problem; table also reports 15, 143 and 59,989.The 94 value is the logical Hamiltonian size; active embedded physical-qubit count is not reported, and this is not a fault-tolerant Shor resource point.verifiedtracker-2:D13
2018-05-264,088,459 = 2,017 × 2,02722Generalised Grover/exact-search circuit on IBM ibmqx4, not Shor; two active qubits on a five-qubit processor after algebraic simplification.All other factor bits were resolved classically. The separately mentioned 966,887 case was a classical simulation and is excluded.verifiedtracker-2:D14
2019-03-0215, 21, and attempted 35; largest successful target 21 = 3 × 7not locked in local evidence7Compiled Shor on IBM ibmqx5; five qubits for 15, six for 21 and seven for attempted 35; iterations split into separate circuits with classically selected reinitialisation.Continued fractions did not work at available precision, periods were assigned by statistical overlap, and the algorithm failed to factor 35; seven is the attempted-case maximum, not the qubit count of the successful 21 row.verifiedtracker-2:D06
2020-12-141,099,551,473,989 = 1,048,589 × 1,048,60133QAOA variational factoring on a superconducting processor, not Shor; a heavily reduced QUBO was executed for the 41-bit target.Aggressive classical preprocessing made the largest decimal target the smallest quantum search; decimal size must not be plotted as a Shor or RSA-like capability record.secondarytracker-2:D07; tracker-2:D10
2021-08-1621 = 3 × 7not locked in local evidence5Compiled Shor/QPE on IBM processors with three control and two work qubits; enough phase bits for continued fractions; cross-register entanglement checked.Compiled specifically for 21 and used approximate relative-phase Toffoli gates; this is the cleanest complete gate-model Shor-style factor-21 row, not a scalable RSA result.verifiedtracker-2:D08
2022-12-23261,980,999,226,229 = 15,538,213 × 16,860,433 (48 bits)not locked in local evidence10Schnorr-lattice plus QAOA hybrid on superconducting hardware, not Shor; hardware generated one smooth-relation pair.Other relations were numerical and the remaining lattice and linear-algebra pipeline was classical; the separate 372-qubit RSA-2048 statement is only an estimate.verifiedtracker-2:D09
2024-02-128,219,999 = 32,749 × 251not locked in local evidencenot locked in local evidenceD-Wave Advantage 4.1 annealing, not Shor; largest product solved without external search or preprocessing; device topology has 5,760 qubits.The active qubit count for the solved instance is not reported, 5,760 is device capacity, and the factors are strongly unbalanced at 15 bits by 8 bits.verifiedtracker-2:D10
2024-10-02Largest hardware result: 253 = 11 × 23not locked in local evidence9CVaR-VQE on IBM hardware, not Shor; direct multiplication-cost encoding also factored 15, 21, 57 and 123 without prior arithmetic simplification.The VQE loop is hybrid and iterative. The 1,048,561 result used a 27-qubit ideal classical simulation and is excluded as a hardware record.verifiedtracker-2:D15
2024-12-30Ten specially constructed 2,048-bit productsnot locked in local evidencenot locked in local evidenceD-Wave annealing, not Shor; exact QPU allocation is not reported.A later analysis reports that every factor pair differs by only 2 or 6 and is immediately recoverable by near-square arithmetic; these are not generated RSA-2048 keys.secondarytracker-2:D18; tracker-2:D19
2025-01-171,034,879,359,475,633,166,138,643 = 1,001,721,172,891 × 1,033,101,213,673 (80 bits)2694Closest-vector and classical preprocessing plus D-Wave Advantage 4.1, not Shor; 26 logical variables embedded in 94 physical qubits.A selected finite run does not establish the broader claim of breaking arbitrary 80-bit RSA inputs, and independent reproduction is unknown.verifiedtracker-2:D17
2025-11-2235 = 5 × 7not locked in local evidencenot locked in local evidenceSimplified Regev-algorithm circuit on superconducting hardware, not Shor; factors recovered with lattice postprocessing; exact qubit count is not reported in the primary abstract.The full circuits were assessed in noisy simulation and the executed circuit was further simplified; this does not turn the failed 2019 Shor-35 run into a Shor record.verifiedtracker-2:D16

The factoring frontier

Provenance: sweep/historical-record.jsonl
  • Factored
  • Open
Factored and open RSA catalogue entries by decimal-digit bandBlue factored bars occupy every band through 250 to 259 digits. Rust open bars occupy every band from 260 to 299 digits onward.100–149: 6 factored100–149: 0 open100–149150–199: 8 factored150–199: 0 open150–199200–249: 8 factored200–249: 0 open200–249250–259: 1 factored250–259: 0 open250–259260–299: 0 factored260–299: 5 open260–299300–399: 0 factored300–399: 12 open300–399400–499: 0 factored400–499: 11 open400–499500+: 0 factored500+: 3 open500+
Blue means factored; orange means open. Labels and the exact table repeat the distinction without relying on colour.

What this means: the locked catalogue has a clean decimal frontier: every target at 250 digits or below is factored; every target at 260 digits or above is open. RSA-250 is the largest general-purpose factorization in the local evidence.

Exact frontier data
Historical catalogue by decimal-digit band
Decimal digitsFactoredOpenTotal
100–149606
150–199808
200–249808
250–259101
260–299055
300–39901212
400–49901111
500+033

The chart uses decimal digits, which are locked for all 54 records. The separate bit field is locked for 17 records; 37 remain not locked in local evidence and are never zero-filled.

The historical prize schedule

Provenance: sweep/historical-record.jsonl, fixed-prize bit-labelled targets
Historical fixed-prize labelsEight former labels rise from ten thousand dollars for RSA-576 to two hundred thousand dollars for RSA-2048. All are inactive.RSA-576RSA-576: $10,000, historical and inactive$10kRSA-640RSA-640: $20,000, historical and inactive$20kRSA-704RSA-704: $30,000, historical and inactive$30kRSA-768RSA-768: $50,000, historical and inactive$50kRSA-896RSA-896: $75,000, historical and inactive$75kRSA-1024RSA-1024: $100,000, historical and inactive$100kRSA-1536RSA-1536: $150,000, historical and inactive$150kRSA-2048RSA-2048: $200,000, historical and inactive$200k

What this means: these amounts describe the withdrawn programme. A longer bar is not a current offer.

Orange bars preserve the historical labels. Every label has been inactive since the challenge was withdrawn in 2007.
Exact prize-label data
Historical fixed-prize labels, all inactive since 2007
RSA numberHistorical labelCatalogue status
RSA-576$10,000factored
RSA-640$20,000factored
RSA-704$30,000factored
RSA-768$50,000factored
RSA-896$75,000open
RSA-1024$100,000open
RSA-1536$150,000open
RSA-2048$200,000open

Every chart on this page is drawn only from the four named JSONL datasets. Exact labels and tables accompany colour. Nulls render as not locked in local evidence, are excluded where an axis requires a number, and are never guessed or zero-filled.