Password crack time calculator
How long would brute force take? Set the length, the characters used and how the password was stored, and see the worst-case and average time to crack a randomly generated password.
- Average (half the space)
- 75 thousand years
- Possible passwords
- 9412 ≈ 4.8 × 10²³
- Entropy
- 78.7 bits
Assumes a truly random password. For one you chose yourself, use the strength checker: patterns cut these times drastically.
Same password, different attacker
Take a random 10-character password (all 94 symbols). Slide the attacker from a locked-down login to a GPU cluster and watch the time collapse. The password never changes; only how it's stored and attacked does.
17 years
A fast, unsalted hash. The attacker tests billions of guesses per second offline, with no lockout. Only length and randomness protect you now.
Brute-force crack time table
| Length | Digits (10) | Lowercase (26) | Mixed case (52) | + digits (62) | + symbols (94) |
|---|---|---|---|---|---|
| 6 | instantly | instantly | instantly | instantly | 6.9 seconds |
| 7 | instantly | instantly | 10 seconds | 35 seconds | 11 minutes |
| 8 | instantly | 2.1 seconds | 8.9 minutes | 36 minutes | 17 hours |
| 9 | instantly | 54 seconds | 7.7 hours | 1.6 days | 2.2 months |
| 10 | instantly | 24 minutes | 17 days | 3.2 months | 17 years |
| 11 | 1 second | 10 hours | 2.4 years | 16 years | 1.6 thousand years |
| 12 | 10 seconds | 11 days | 1.2 centuries | 1 thousand year | 151 thousand years |
| 14 | 17 minutes | 20 years | 335 thousand years | 3.9 million years | 1.3 billion years |
| 16 | 1.2 days | 14 thousand years | 906 million years | 15 billion years | about 10¹³ years |
| 18 | 3.8 months | 9.3 million years | about 10¹² years | about 10¹³ years | about 10¹⁷ years |
| 20 | 32 years | 6.3 billion years | about 10¹⁵ years | about 10¹⁷ years | about 10²⁰ years |
Worst-case time to exhaust every combination of random characters. Rates are orders of magnitude, not benchmarks of a specific rig.
Crack time FAQ
How long does it take to crack a password?
It depends on three things: how many possible passwords the attacker must search, how fast they can test guesses, and whether your password follows a pattern they try first. A random 8-character password using all 94 printable characters has about 6 × 10^15 possibilities: under a day against a fast MD5 hash on one high-end GPU, but thousands of years against bcrypt.
Where do the guess rates come from?
They are round orders of magnitude. The fast-hash figure reflects public Hashcat benchmarks for a single current high-end GPU against MD5 (around 10^11 per second); bcrypt at a typical cost factor runs at thousands to tens of thousands per GPU. Online rates assume the login form itself limits attempts.
Does this table apply to my password?
Only if your password was generated randomly. Human-chosen passwords are cracked far faster because attackers try dictionaries, leaked passwords and common patterns first. To estimate a specific password, use the strength checker, which models those patterns.
What does "worst case" mean here?
The time to try every possible combination. On average an attacker finds a random password after searching half the space, so expected time is half the figure shown.
Why is bcrypt so much slower to crack than SHA-256?
bcrypt, scrypt and Argon2 are deliberately slow and, in Argon2 and scrypt’s case, memory-hard. SHA-256 and MD5 are designed to be fast, which is great for file checksums and terrible for password storage. Try both on the password hash generator to feel the difference.