RSA Factoring
challenge.
Each RSA challenge number is the product of two similarly-sized primes whose factors were discarded after generation. RSA-260 was recently factored, so this page offers the remaining open targets — RSA-270 and upward.
Factoring workbench
Idle. No factoring computation is active.
These semiprimes are deliberately constructed to have no small factors. Trial division and Pollard's rho are shown here to make the difficulty tangible — they are astronomically far from breaking a 270+ digit modulus. Real factorization requires ECM or the general number field sieve on massive compute.
Factoring is asymmetric
Multiplying two primes is instant; recovering them from the product is believed to be exponentially hard. RSA-260's 2025 factorization was a milestone, which is why this page starts at RSA-270.
An honest browser grinder
The worker runs trial division over small odd numbers and a bounded Pollard's rho loop. It reports "no factor found" — exactly as expected. This is a teaching tool, not a factoring service.
Checked by the coordinator
A factor is only shown here after the server re-checks that it divides the modulus exactly and that both factors pass a strong probable-prime test.
No factorization has been verified yet.