# Cash for breaking RSA assumptions

The Ethereum Foundation is offering 28,000 USD and 29 ETH in a bounty program to test the validity of two recent RSA assumptions: the **adaptive root assumption** and the **low order assumption**.

- The adaptive root assumption states that it is difficult to find a random root of a chosen element in an RSA group.
- The low order assumption states that it is difficult to find an element of low order in an RSA group.

Both assumptions were formalized in June 2018 for two RSA Verifiable Delay Functions (VDFs) schemes:

- The Wesolowski VDF construction is based on the adaptive root assumption.
- The Pietrzak VDF construction is based on the low order assumption.

## Where now?

- Straight to the bounties
- More on the RSA assumptions
- More on Verifiable Delay Functions