Claims · broke RSA
77
0 substantiated · 0 actually broke RSA.
Corroboration · RSA records, claims graded since 2026
The Factoring Claims RegisterSuccessor to the RSA Factoring Challenge (1991-2007)
Only locked counts
The 77-claim census, the 54-number catalogue, and the classical and quantum resource frontiers. Every chart is derived locally and paired with its exact data table and provenance labels.
77
0 substantiated · 0 actually broke RSA.
22×
20,000,000 → 897,864; runtime grew and neither is a factorisation.
21
Compiled small-instance hardware result; not RSA scale.
54
23 factored · 31 open.
49 of 77 are C4 / quantum
Exact count: 0 substantiated
What this means: class and status answer different questions. A narrow hardware result can be real while its general RSA implication remains special-structure-only or open. The six literal status words are not collapsed.
| Claim stream | Count |
|---|---|
| C1 | 1 |
| C2 | 14 |
| C3 | 13 |
| C4 | 49 |
| Literal status | Count |
|---|---|
| substantiated | 0 |
| refuted | 12 |
| unsubstantiated | 18 |
| estimate-not-demonstration | 11 |
| special-structure-only | 24 |
| open | 11 |
| withdrawn | 1 |
What this means: the stream clusters with the quantum-publicity cycle. That is a pattern in this curated set, not a causal claim and not a census of every public statement.
| Year | All claims | C4 / quantum | C1–C3 |
|---|---|---|---|
| 1993 | 1 | 0 | 1 |
| 1994 | 1 | 0 | 1 |
| 1995 | 0 | 0 | 0 |
| 1996 | 0 | 0 | 0 |
| 1997 | 0 | 0 | 0 |
| 1998 | 0 | 0 | 0 |
| 1999 | 1 | 0 | 1 |
| 2000 | 0 | 0 | 0 |
| 2001 | 3 | 1 | 2 |
| 2002 | 1 | 0 | 1 |
| 2003 | 1 | 0 | 1 |
| 2004 | 0 | 0 | 0 |
| 2005 | 0 | 0 | 0 |
| 2006 | 1 | 0 | 1 |
| 2007 | 4 | 2 | 2 |
| 2008 | 1 | 1 | 0 |
| 2009 | 3 | 1 | 2 |
| 2010 | 0 | 0 | 0 |
| 2011 | 1 | 1 | 0 |
| 2012 | 4 | 2 | 2 |
| 2013 | 3 | 2 | 1 |
| 2014 | 1 | 1 | 0 |
| 2015 | 1 | 0 | 1 |
| 2016 | 1 | 1 | 0 |
| 2017 | 2 | 2 | 0 |
| 2018 | 2 | 2 | 0 |
| 2019 | 5 | 4 | 1 |
| 2020 | 4 | 4 | 0 |
| 2021 | 6 | 4 | 2 |
| 2022 | 5 | 4 | 1 |
| 2023 | 5 | 5 | 0 |
| 2024 | 7 | 4 | 3 |
| 2025 | 9 | 5 | 4 |
| 2026 | 4 | 3 | 1 |
Two evidence streams answer different questions. The classical staircase records completed general-purpose factorisations. The quantum trajectory records engineering estimates for a future RSA-2048 run and keeps those estimates separate from real-hardware demonstrations.
Do not compare the 2026 quantum marks as a single improving time series. They exchange physical qubits for runtime under architecture-specific assumptions.
What this means: the locked exact-bit record rose from 426 bits in 1994 to 829 bits in 2020: 403 bits, or 94.6%. Progress is real but stepwise. Four milestones with null bit counts remain not locked in local evidence and are not estimated from their decimal digits.
| Date | Record | Digits | Bits | Method | Evidence | Plain provenance refs |
|---|---|---|---|---|---|---|
| 1994-04-26 | RSA-129 | 129 | 426 | PPMPQS/MPQS quadratic sieve | verified | tracker-1:SRC-R129-ANN; tracker-1:SRC-R129-SURVEY |
| 1996-04-10 | RSA-130 | 130 | not locked in local evidence | Number field sieve | verified | tracker-1:SRC-R130-PAPER; tracker-1:SRC-RECORDS |
| 1999-02-02 | RSA-140 | 140 | not locked in local evidence | Number field sieve | verified | tracker-1:SRC-R140-PAPER; tracker-1:SRC-RECORDS |
| 1999-08-22 | RSA-155 | 155 | 512 | GNFS | verified | tracker-1:SRC-R155-PAPER |
| 2002-01-18 | C158 | 158 | not locked in local evidence | Number field sieve | verified | tracker-1:SRC-C158-ANN; tracker-1:SRC-RECORDS |
| 2003-04-01 | RSA-160 | 160 | 530 | GNFS | secondary | tracker-1:SRC-R160-SECONDARY |
| 2003-12-03 | RSA-576 | not locked in local evidence | 576 | not locked in local evidence | verified | tracker-1:SRC-R576-ANN; tracker-1:SRC-RECORDS |
| 2005-05-02 | C176 | 176 | not locked in local evidence | not locked in local evidence | verified | tracker-1:SRC-C176-ANN; tracker-1:SRC-RECORDS |
| 2005-05-09 | RSA-200 | 200 | 663 | GNFS | verified | tracker-1:SRC-R200-ANN |
| 2009-12-12 | RSA-768 | 232 | 768 | GNFS | verified | tracker-1:SRC-R768-PAPER |
| 2019-12-02 | RSA-240 | 240 | 795 | GNFS with CADO-NFS | verified | tracker-1:SRC-RECORDS; tracker-1:SRC-R240-ANN; tracker-1:SRC-R240250-PAPER |
| 2020-02-28 | RSA-250 | 250 | 829 | GNFS with CADO-NFS | verified | tracker-1:SRC-R250-ANN; tracker-1:SRC-R240250-PAPER |
Effort is not charted: the rows mix MIPS-years, heterogeneous CPU-years, reference-core-years, and stage-only versus total costs.
What this means: the closest surface-code pair falls from 20,000,000 modelled physical qubits in 2019 to 897,864 in 2025, a 22.3× reduction, while expected runtime moves from about 7.4 hours to 4.96 days. The 2026 points trade qubits for runtime under different codes, connectivity, cycle times and memory assumptions, so they are not a continuation of that line.
| Date | Target | Logical qubits | Physical qubits | Runtime | Chart treatment | Evidence | Plain provenance refs |
|---|---|---|---|---|---|---|---|
| 2019-05-23 | RSA-2048 | 6189 | 20,000,000 | 0.31 days, about 7.4 hours; title rounds to 8 hours | like-for-like trend line | verified | tracker-2:E01 |
| 2021-03-10 | RSA-2048 | 8284 | 13,436 | 177 days | separate 2026 architecture mark 3 | verified | tracker-2:E02 |
| 2022-01-20 | RSA-2048, Beauregard circuit | 4099 | 13,500,000 | 1.89 × 10^7 hours | not plotted: different design / runtime trade-off | verified | tracker-2:E03 |
| 2022-01-20 | RSA-2048, Pavlidis circuit | 18434 | 648,000,000 | 1.16 × 10^5 hours | not plotted: different design / runtime trade-off | verified | tracker-2:E03 |
| 2024-02-13 | RSA-2048 | 1730 | not locked in local evidence | not locked in local evidence | separate 2026 architecture mark 3 | verified | tracker-2:E04 |
| 2025-05-21 | RSA-2048 | 1537 | 897,864 | 12.07 hours per shot; 4.96 days expected per factorisation; headline says less than one week | like-for-like trend line | verified | tracker-2:E05 |
| 2026-02-12 | RSA-2048 | not locked in local evidence | 94,000 | At most one month expected | separate 2026 architecture mark 3 | verified | tracker-2:E06 |
| 2026-03-30 | RSA-2048, neutral-atom space-efficient | 1399 | 11,033 | Approximately 4.3 × 10^4 days | separate 2026 architecture mark 1 | verified | tracker-2:E07 |
| 2026-03-30 | RSA-2048, neutral-atom balanced | 1399 | 13,255 | Approximately 1.0 × 10^4 days | separate 2026 architecture mark 2 | verified | tracker-2:E07 |
| 2026-03-30 | RSA-2048, neutral-atom time-efficient | 6144 | 102,000 | 97 days | separate 2026 architecture mark 4 | verified | tracker-2:E07 |
| 2026-04-07 | RSA-2048, heterogeneous grid-coupled architecture | 1399 | 381,000 | 9.2 days | separate 2026 architecture mark 6 | verified | tracker-2:E08 |
| 2026-04-07 | RSA-2048, heterogeneous architecture with adder accelerator | 1436 | 439,000 | 4.9 days | separate 2026 architecture mark 7 | verified | tracker-2:E08 |
| 2026-04-07 | RSA-2048, hypothetical qLDPC long-range memory | 1399 | 190,000 | 9.2 days | separate 2026 architecture mark 5 | verified | tracker-2:E08 |
| 2026-05-05 | RSA-1024, six-module atomic DShor | not locked in local evidence | 296,240 | 27.4 days per shot | not plotted: RSA-1024 target | verified | tracker-2:E09 |
| 2026-05-05 | RSA-2048, six-module atomic DShor | not locked in local evidence | 512,500 | 190.4 days per shot; 9.2 shots expected | separate 2026 architecture mark 8 | verified | tracker-2:E09 |
| Date | Target | Logical qubits | Physical qubits | Method / assumptions | Caveat | Evidence | Plain provenance refs |
|---|---|---|---|---|---|---|---|
| 2001-12-30 | 15 = 3 × 5 | not locked in local evidence | 7 | Liquid-state NMR using seven spin-1/2 nuclei; simplest compiled Shor instance. | Compiled for 15; the authors explicitly state that scalability is not implied. | verified | tracker-2:D01 |
| 2007-05-11 | 15 = 3 × 5 | not locked in local evidence | 4 | Linear-optical photonic circuit with modular exponentiation and semiclassical QFT. | The known period r=2 and selected N=15 were used to simplify the network; this is answer-dependent compilation, not a general-size Shor circuit. | verified | tracker-2:D02 |
| 2009-11-06 | 15 = 3 × 5 | not locked in local evidence | 4 | Integrated silica-on-silicon photonic chip using four single-photon qubits. | The target and modular exponentiation were compiled specifically for 15. | verified | tracker-2:D03 |
| 2011-11-16 | 143 = 11 × 13 | not locked in local evidence | 4 | Adiabatic factorisation on a liquid-crystal NMR processor, not Shor; classical algebra reduced the target before the quantum run. | A later analysis reports that the same four-qubit Hamiltonian represents several larger selected targets, showing that printed integer size does not track experimental difficulty. | secondary | tracker-2:D11; tracker-2:D12 |
| 2012-10-21 | 21 = 3 × 7, order-finding only | not locked in local evidence | 2 | Two-photon iterative compiled order finding with higher-dimensional work states and a recycled control qubit. | A later full-factorisation paper reports that only two output bits were obtained, insufficient for continued fractions; do not register this as uncontested complete factorisation of 21. | secondary | tracker-2:D04; tracker-2:D08 |
| 2015-07-31 | 15 = 3 × 5 | 7 | 11 | Trapped-ion Kitaev/Shor structure using seven effective algorithm qubits plus four cache qubits via recycling; reported success above 90%. | Still an N=15 implementation with instance optimisations, although later modular multipliers avoided reliance on prior knowledge of the solution. | verified | tracker-2:D05 |
| 2018-04-08 | Largest row: 376,289 = 571 × 659 | 94 | not locked in local evidence | D-Wave 2000Q annealing, not Shor; multiplication mapped to an Ising optimisation problem; table also reports 15, 143 and 59,989. | The 94 value is the logical Hamiltonian size; active embedded physical-qubit count is not reported, and this is not a fault-tolerant Shor resource point. | verified | tracker-2:D13 |
| 2018-05-26 | 4,088,459 = 2,017 × 2,027 | 2 | 2 | Generalised Grover/exact-search circuit on IBM ibmqx4, not Shor; two active qubits on a five-qubit processor after algebraic simplification. | All other factor bits were resolved classically. The separately mentioned 966,887 case was a classical simulation and is excluded. | verified | tracker-2:D14 |
| 2019-03-02 | 15, 21, and attempted 35; largest successful target 21 = 3 × 7 | not locked in local evidence | 7 | Compiled Shor on IBM ibmqx5; five qubits for 15, six for 21 and seven for attempted 35; iterations split into separate circuits with classically selected reinitialisation. | Continued fractions did not work at available precision, periods were assigned by statistical overlap, and the algorithm failed to factor 35; seven is the attempted-case maximum, not the qubit count of the successful 21 row. | verified | tracker-2:D06 |
| 2020-12-14 | 1,099,551,473,989 = 1,048,589 × 1,048,601 | 3 | 3 | QAOA variational factoring on a superconducting processor, not Shor; a heavily reduced QUBO was executed for the 41-bit target. | Aggressive classical preprocessing made the largest decimal target the smallest quantum search; decimal size must not be plotted as a Shor or RSA-like capability record. | secondary | tracker-2:D07; tracker-2:D10 |
| 2021-08-16 | 21 = 3 × 7 | not locked in local evidence | 5 | Compiled Shor/QPE on IBM processors with three control and two work qubits; enough phase bits for continued fractions; cross-register entanglement checked. | Compiled specifically for 21 and used approximate relative-phase Toffoli gates; this is the cleanest complete gate-model Shor-style factor-21 row, not a scalable RSA result. | verified | tracker-2:D08 |
| 2022-12-23 | 261,980,999,226,229 = 15,538,213 × 16,860,433 (48 bits) | not locked in local evidence | 10 | Schnorr-lattice plus QAOA hybrid on superconducting hardware, not Shor; hardware generated one smooth-relation pair. | Other relations were numerical and the remaining lattice and linear-algebra pipeline was classical; the separate 372-qubit RSA-2048 statement is only an estimate. | verified | tracker-2:D09 |
| 2024-02-12 | 8,219,999 = 32,749 × 251 | not locked in local evidence | not locked in local evidence | D-Wave Advantage 4.1 annealing, not Shor; largest product solved without external search or preprocessing; device topology has 5,760 qubits. | The active qubit count for the solved instance is not reported, 5,760 is device capacity, and the factors are strongly unbalanced at 15 bits by 8 bits. | verified | tracker-2:D10 |
| 2024-10-02 | Largest hardware result: 253 = 11 × 23 | not locked in local evidence | 9 | CVaR-VQE on IBM hardware, not Shor; direct multiplication-cost encoding also factored 15, 21, 57 and 123 without prior arithmetic simplification. | The VQE loop is hybrid and iterative. The 1,048,561 result used a 27-qubit ideal classical simulation and is excluded as a hardware record. | verified | tracker-2:D15 |
| 2024-12-30 | Ten specially constructed 2,048-bit products | not locked in local evidence | not locked in local evidence | D-Wave annealing, not Shor; exact QPU allocation is not reported. | A later analysis reports that every factor pair differs by only 2 or 6 and is immediately recoverable by near-square arithmetic; these are not generated RSA-2048 keys. | secondary | tracker-2:D18; tracker-2:D19 |
| 2025-01-17 | 1,034,879,359,475,633,166,138,643 = 1,001,721,172,891 × 1,033,101,213,673 (80 bits) | 26 | 94 | Closest-vector and classical preprocessing plus D-Wave Advantage 4.1, not Shor; 26 logical variables embedded in 94 physical qubits. | A selected finite run does not establish the broader claim of breaking arbitrary 80-bit RSA inputs, and independent reproduction is unknown. | verified | tracker-2:D17 |
| 2025-11-22 | 35 = 5 × 7 | not locked in local evidence | not locked in local evidence | Simplified Regev-algorithm circuit on superconducting hardware, not Shor; factors recovered with lattice postprocessing; exact qubit count is not reported in the primary abstract. | The full circuits were assessed in noisy simulation and the executed circuit was further simplified; this does not turn the failed 2019 Shor-35 run into a Shor record. | verified | tracker-2:D16 |
What this means: the locked catalogue has a clean decimal frontier: every target at 250 digits or below is factored; every target at 260 digits or above is open. RSA-250 is the largest general-purpose factorization in the local evidence.
| Decimal digits | Factored | Open | Total |
|---|---|---|---|
| 100–149 | 6 | 0 | 6 |
| 150–199 | 8 | 0 | 8 |
| 200–249 | 8 | 0 | 8 |
| 250–259 | 1 | 0 | 1 |
| 260–299 | 0 | 5 | 5 |
| 300–399 | 0 | 12 | 12 |
| 400–499 | 0 | 11 | 11 |
| 500+ | 0 | 3 | 3 |
The chart uses decimal digits, which are locked for all 54 records. The separate bit field is locked for 17 records; 37 remain not locked in local evidence and are never zero-filled.
What this means: these amounts describe the withdrawn programme. A longer bar is not a current offer.
| RSA number | Historical label | Catalogue status |
|---|---|---|
| RSA-576 | $10,000 | factored |
| RSA-640 | $20,000 | factored |
| RSA-704 | $30,000 | factored |
| RSA-768 | $50,000 | factored |
| RSA-896 | $75,000 | open |
| RSA-1024 | $100,000 | open |
| RSA-1536 | $150,000 | open |
| RSA-2048 | $200,000 | open |
Every chart on this page is drawn only from the four named JSONL datasets. Exact labels and tables accompany colour. Nulls render as not locked in local evidence, are excluded where an axis requires a number, and are never guessed or zero-filled.