Password crack time calculator

How long would brute force take? Set the length, the characters used and how the password was stored, and see the worst-case and average time to crack a randomly generated password.

Worst case151 thousand years
Average (half the space)
75 thousand years
Possible passwords
9412 ≈ 4.8 × 10²³
Entropy
78.7 bits

Assumes a truly random password. For one you chose yourself, use the strength checker: patterns cut these times drastically.

Same password, different attacker

Take a random 10-character password (all 94 symbols). Slide the attacker from a locked-down login to a GPU cluster and watch the time collapse. The password never changes; only how it's stored and attacked does.

17 years

A fast, unsalted hash. The attacker tests billions of guesses per second offline, with no lockout. Only length and randomness protect you now.

Brute-force crack time table

LengthDigits (10)Lowercase (26)Mixed case (52)+ digits (62)+ symbols (94)
6instantlyinstantlyinstantlyinstantly6.9 seconds
7instantlyinstantly10 seconds35 seconds11 minutes
8instantly2.1 seconds8.9 minutes36 minutes17 hours
9instantly54 seconds7.7 hours1.6 days2.2 months
10instantly24 minutes17 days3.2 months17 years
111 second10 hours2.4 years16 years1.6 thousand years
1210 seconds11 days1.2 centuries1 thousand year151 thousand years
1417 minutes20 years335 thousand years3.9 million years1.3 billion years
161.2 days14 thousand years906 million years15 billion yearsabout 10¹³ years
183.8 months9.3 million yearsabout 10¹² yearsabout 10¹³ yearsabout 10¹⁷ years
2032 years6.3 billion yearsabout 10¹⁵ yearsabout 10¹⁷ yearsabout 10²⁰ years

Worst-case time to exhaust every combination of random characters. Rates are orders of magnitude, not benchmarks of a specific rig.

Crack time FAQ

How long does it take to crack a password?

It depends on three things: how many possible passwords the attacker must search, how fast they can test guesses, and whether your password follows a pattern they try first. A random 8-character password using all 94 printable characters has about 6 × 10^15 possibilities: under a day against a fast MD5 hash on one high-end GPU, but thousands of years against bcrypt.

Where do the guess rates come from?

They are round orders of magnitude. The fast-hash figure reflects public Hashcat benchmarks for a single current high-end GPU against MD5 (around 10^11 per second); bcrypt at a typical cost factor runs at thousands to tens of thousands per GPU. Online rates assume the login form itself limits attempts.

Does this table apply to my password?

Only if your password was generated randomly. Human-chosen passwords are cracked far faster because attackers try dictionaries, leaked passwords and common patterns first. To estimate a specific password, use the strength checker, which models those patterns.

What does "worst case" mean here?

The time to try every possible combination. On average an attacker finds a random password after searching half the space, so expected time is half the figure shown.

Why is bcrypt so much slower to crack than SHA-256?

bcrypt, scrypt and Argon2 are deliberately slow and, in Argon2 and scrypt’s case, memory-hard. SHA-256 and MD5 are designed to be fast, which is great for file checksums and terrible for password storage. Try both on the password hash generator to feel the difference.