Generador Studio

How Long Does It Take to Crack a Password? A Table by Length and Character Set

Last updated: October 8, 2026

"How long would it take to crack my password?" has an honest answer that few sites give in full: it depends on how the password was stored and on the attacker's hardware. This guide works out the time for several scenarios using real numbers, states exactly what was assumed, and explains what the table does NOT tell you, which matters as much as what it does.

What "cracking" a password actually means

Almost nobody guesses your password one try at a time on the login page: sites throttle or lock repeated attempts. The real risk appears when a service is breached and attackers get the database of password hashes (a mathematical fingerprint, not the password itself). With those hashes in hand, the attacker tests combinations as fast as their own hardware allows, with no attempt limit. That is called an offline attack, and it is the scenario this table models.

That is why speed depends more on the hashing algorithm the site used than on you. Fast, older algorithms (MD5, SHA-1, NTLM) were designed to be quick, which is great for the attacker. Deliberately slow algorithms (bcrypt, scrypt, Argon2) were designed to make every guess expensive. You don't control which one a site uses, but you do control your password's length, the one thing that helps in both cases.

The assumptions behind the numbers

The fast-hash scenario assumes 1.6 × 10¹¹ guesses per second, in line with public hashcat benchmarks for MD5 on a single high-end graphics card (an RTX 4090 lands around 155 to 165 billion hashes per second). The slow-hash scenario assumes about 1.7 × 10³ guesses per second, an estimate for bcrypt at cost factor 12 derived by scaling the public low-cost benchmark (difficulty doubles with each cost increment). These are orders of magnitude, not exact measurements: real speed varies with software, drivers and configuration.

The table shows the time to run through ALL possible combinations in a given space, the worst case. On average an attacker finds the password after covering half the space, so the typical time is roughly half of what appears. Everything is computed for a single graphics card: an attacker with 8 cards divides the times by 8, and one with a dedicated cluster by hundreds.

Time to try every combination — fast hash (MD5/NTLM), one high-end GPU
Characters used810121416
Digits only (10)< 1 s< 1 s6 s10 min17 h
Lowercase (26)1 s15 min7 days13 years8.6 × 10³ years
Upper, lower and digits (62)23 min61 days639 years2.5 × 10⁶ years9.4 × 10⁹ years
All printable characters (94)11 h11 years9.4 × 10⁴ years8.3 × 10⁸ years7.4 × 10¹² years

If the site used a slow hash (bcrypt)

The same exercise with an algorithm built to be slow changes the picture completely: an 8-character password that falls in hours against MD5 can take thousands of years against bcrypt. This is why "use long passwords" and "sites should use slow hashes" are two defenses that complement each other: yours covers the case where the site did it wrong, theirs covers the case where your password is shorter than ideal.

Time to try every combination — bcrypt (cost 12, estimated), one high-end GPU
Characters used81012
Digits only (10)17 h70 days19 years
Lowercase (26)4 years2.7 × 10³ years1.8 × 10⁶ years
Upper, lower and digits (62)4.2 × 10³ years1.6 × 10⁷ years6.2 × 10¹⁰ years
All printable characters (94)1.2 × 10⁵ years1.0 × 10⁹ years9.1 × 10¹² years

What the table does NOT tell you

These times only hold for truly random passwords. If your password is a word with a typical substitution ("P@ssw0rd"), your pet's name plus a year, or any pattern a human considers "hard", the attacker doesn't walk the whole space: they try dictionaries, leaked-password lists and common transformation rules first. In that case a 12-character password can fall in seconds even though mathematically it "has" 94 symbols available.

Randomness is what makes the table true, and it is hard to achieve by hand because people choose predictably. A generator that uses a cryptographically secure source (like this site's password generator, built on crypto.getRandomValues()) produces combinations that actually fill the whole space, not just the part a human tends to pick.

What to do with this

For important accounts (main email, bank, password manager) use at least 16 random characters: per the table, even against a fast hash that is in the range of billions of years for one attacker with one GPU. For everything else, 12 random characters already put the attack in the hundreds of years against a fast hash and millions against a slow one.

And most important: none of this replaces using a different password for every service. A 20-character password reused across ten sites falls the moment the weakest of them leaks in plain text.

Related generators

Frequently asked questions

How many characters do I need at a minimum?
If it is random and unique, 12 characters is a reasonable minimum for low-risk accounts and 16 or more for email, banking and your password manager. Passwords a person picks need to be considerably longer to make up for their predictability.
Why does the same password take so much less time against MD5 than against bcrypt?
MD5 was designed to be fast, and a modern GPU computes tens of billions per second. bcrypt was designed to be slow on purpose and is tunable: each extra point of cost doubles the time per guess, so an attacker tests far fewer combinations per second.
Does this table apply to my social media or website password?
It applies to the case where the site's database leaks. Against direct attempts on the login page the site limits guesses and the risk is different (for example, very common passwords). That is why a long, unique password works best combined with two-factor authentication.
Does a multi-word passphrase count as a long password?
Yes, as long as the words are chosen at random and do not form a meaningful sentence. Four or five words picked randomly from a large dictionary can match the entropy of a short password with symbols, and they are easier to remember.
Where do the speed numbers come from?
From public hashcat benchmarks for a high-end GPU (about 155 to 165 billion guesses per second against MD5) and a derived estimate for bcrypt at cost 12. They are reference orders of magnitude: your real case depends on the algorithm and the attacker’s hardware.

Ver esta guía en español →