math ⇄ art lab — The RSA Room

The RSA Room

Two famous semiprimes, multiplied live in front of you — and then painted. Forward is trivial; backward took the world ~2700 core-years.

RSA-250 = p × q 250 digits · 829 bits

Factored by Fabrice Boudot, Pierrick Gaudry, Aurore Guillevic, Nadia Heninger, Emmanuel Thomé & Paul Zimmermann — announced 28 February 2020.

multiplying p × q with BigInt…

The same multiplication took humanity ~2700 core-years of Number Field Sieve to invert (CADO-NFS, announced 28 Feb 2020).

RSA-260 = p × q 260 digits · 862 bits · brand-new

Six years after RSA-250, Eric Lu returned the factors of the next challenge number. Smallest RSA challenge still standing: RSA-270 / RSA-896 (270 digits).

The Lattice — the heat map of p × q

One cell per digit pair: cell (i, j) is the product p[i] × q[j]. This is the complete anatomy of the multiplication your browser just performed — hover any cell.

copied ✓

Dozenal view — RSA-250 in base twelve

The same 250-digit semiprime, re-drawn in the lab's favourite base. Each pointy-top hexagon is one dozenal digit of N, filled with its own gradient — hue = value × 30°, swept across the hexagon at that same angle, lightness 62% → 34%.

← drag / scroll sideways for the full strip

Digit-frequency fingerprints of N, p and q in base 12 — the bars hover around the dashed uniform line (expected = length ÷ 12) with pure random wobble. No visible structure — that's the point of a good semiprime.

Field notes — the humans behind the factors

RSA-250 250 digits · 829 bits

  • Factored by Fabrice Boudot, Pierrick Gaudry, Aurore Guillevic, Nadia Heninger, Emmanuel Thomé and Paul Zimmermann.
  • Announced 28 February 2020.
  • Cost ≈ 2700 core-years at 2.1 GHz (Intel Xeon Gold 6130), using the open-source CADO-NFS Number Field Sieve.
  • The team dedicated the computation to Peter Montgomery — of Montgomery multiplication — who died on 18 February 2020, ten days before the announcement.
  • The challenge's prizes were retracted in 2007; the teams kept factoring anyway.

RSA-260 260 digits · 862 bits

  • Factored by Eric Lu, announced 3 September 2026 — six years after RSA-250.
  • Smallest RSA challenge number still unfactored: RSA-270 / RSA-896 (270 digits).
  • Full challenge table: RSA numbers — Wikipedia.
copied ✓