Password Crack Time Calculator
Pick a length and character set — or type a password — and see how long brute force would take, from a rate-limited login form to a multi-GPU cracking rig. Everything runs in your browser.
16 characters · 88-character pool · 103 bits of entropy
| Attack scenario | Average time to crack |
|---|---|
| Online, rate-limited100 guesses per hour · A login form with lockouts and throttling. | 5.8 × 10²⁴ yearslonger than the age of the universe |
| Online, unthrottled10 guesses per second · A login endpoint with no rate limiting. | 1.6 × 10²² yearslonger than the age of the universe |
| Offline, slow hash10 thousand guesses per second · Stolen hashes stored with bcrypt, scrypt or Argon2. | 1.6 × 10¹⁹ yearslonger than the age of the universe |
| Offline, fast hashOur benchmark10 billion guesses per second · Stolen MD5, SHA-1 or NTLM hashes on a GPU. | 16 trillion yearslonger than the age of the universe |
| Offline, multi-GPU rig1 trillion guesses per second · A dedicated cracking rig against an unsalted fast hash. | 161 billion yearslonger than the age of the universe |
Calculated entirely in your browser. Nothing you type is ever sent anywhere.
How the calculator works
The calculator measures entropy: length × log₂(pool size), in bits. The pool is the set of characters a password can draw from — 26 lowercase letters, 26 uppercase letters, 10 digits and 26 symbols, the same 88 characters the generator on this site uses. A 16-character password from all four sets carries about 103 bits; every extra bit doubles the number of passwords an attacker must try.
The time shown is the average: half of the 2bits possible passwords divided by the attacker's guesses per second. When you type a password, its length and the character types it contains are read locally and nothing leaves the page.
The five attack scenarios
- Online, rate-limited (100 guesses per hour) — guessing through a login form that locks or slows down after failed attempts. This is the attack most accounts face day to day.
- Online, unthrottled (10 per second) — a login endpoint with no rate limiting.
- Offline, slow hash (10 thousand per second) — the password database was stolen, but the site stored passwords with bcrypt, scrypt or Argon2, which are designed to be expensive to test.
- Offline, fast hash (10 billion per second) — stolen hashes made with MD5, SHA-1 or NTLM, tested on a GPU. This is the benchmark used across this site, including the table in how long it takes to crack a password.
- Offline, multi-GPU rig (1 trillion per second) — a dedicated cracking machine against an unsalted fast hash: the worst case you should plan for.
The first four follow the scenarios of zxcvbn, the open-source strength estimator published by Dropbox. Real attackers vary, so read the table as orders of magnitude rather than stopwatch readings.
Why your real password may crack faster
The math assumes every character was chosen at random. Human-made passwords are not: cracking tools try dictionary words, names, dates, keyboard walks like qwerty123 and substitutions like P@ssw0rd1! long before brute force. That last example scores 65 bits on paper and falls in seconds in practice. The calculator flags the most common passwords outright, but it cannot spot every word or birthday — if a person chose it, assume it is weaker than shown. For a single strength score of a password you already use, try the password strength checker.
What to do with the result
Aim for at least 80 bits against the offline fast-hash row — the point where brute force stops being a realistic threat. A random 16-character password (about 103 bits, roughly 16 trillion years at 10 billion guesses per second) clears it with room to spare. A random 12-character password (about 78 bits, around 479 thousand years) is the practical floor. Keep 8 characters for systems that cap the length: about 2.6 days at the same rate. For the reasoning behind these numbers, see what a good password length is.
Frequently Asked Questions
How long would it take to crack my password?
It depends on how random the password is and on who is attacking. A random 8-character password with all four character types falls in about 2.6 days to an offline attacker testing 10 billion guesses per second, and in under an hour on a multi-GPU rig. Twelve random characters take about 479 thousand years at the same rate, and sixteen about 16 trillion years. A password built from words, names or dates falls much faster than these figures.
Is it safe to type my password into this calculator?
Yes. Every calculation runs locally in JavaScript in your browser tab; nothing you type is transmitted, logged or stored. You can confirm it by opening your browser’s network tab while typing: no request leaves the page. Even so, the settings mode gives the same answer without typing a real password at all.
How is password crack time calculated?
First the entropy: length × log2(pool size), where the pool is the number of possible characters (26 lowercase, 26 uppercase, 10 digits, 26 symbols). Then the average time: half of the 2^entropy possible passwords divided by the attacker’s guesses per second. A 16-character password from all 88 characters has about 103 bits of entropy.
Why do crack time calculators give different results?
They assume different attackers. The guessing rate can differ by a factor of a trillion between a throttled login form and a GPU rig against a fast hash; some tools report the worst case (the whole keyspace) instead of the average; and some count 95 printable characters instead of the 88 a typical generator uses. This calculator shows five scenarios side by side so the assumption is never hidden.
How many bits of entropy does a strong password need?
Below 40 bits is weak and 40–59 bits is fair. From 60 bits a password is strong for most accounts, and from 80 bits it is beyond the reach of offline brute force even against a fast hash. A random 16-character password (about 103 bits) clears that bar with a wide margin, which is why it is the default on this site.
Written & reviewed by Andrew Ivanov, Fractional CTO. Last reviewed .