Data Protection

New Password Cracking Analysis Targets Bcrypt

Hive Systems conducts another study on cracking passwords via brute-force attacks, but it’s no longer targeting MD5.

Hive Systems conducts another study on cracking passwords via brute-force attacks, but it’s no longer targeting MD5.

Cybersecurity firm Hive Systems has released the results of its latest annual analysis on cracking passwords through brute-force attacks.

Hive has been conducting this study for several years and until now it has targeted passwords hashed with the widely used MD5 algorithm. However, MD5 hashes can in many cases be easily cracked and organizations have increasingly turned to more secure algorithms, particularly Bcrypt.

Bcrypt is not the most secure, but based on data collected by Hive from the Have I Been Pwned breach notification service it has been the most widely used in recent years. 

That is why Hive has decided to conduct its testing against Bcrypt password hashes, using a dozen NVIDIA GeForce RTX 4090 GPUs.

The tests showed that any password under seven characters can be cracked within hours. In last year’s tests, weak 11-character passwords were cracked instantly using brute force attacks. With Bcrypt, the same 11-character password now takes 10 hours to crack. 

Hive’s analysis showed that strong passwords (containing numbers, uppercase and lowercase letters, and symbols) and fairly strong passwords (containing uppercase and lowercase letters) are difficult to crack if they are more than eight characters long — it takes months or years to crack such passwords if they are protected with Bcrypt.

Hive’s study assumes that the attacker has obtained a hash associated with a randomly generated password and attempts to crack it.

Advertisement. Scroll to continue reading.

“Non-randomly generated passwords are much easier and faster to crack because humans are fairly predictable. As such, the time frames in these tables serve as a ‘best case’ reference point. Passwords that have not been randomly generated would be cracked significantly faster,” the company explained.

Related: AnyDesk Hacked: Revokes Passwords, Certificates in Response

Related: List Containing Millions of Credentials Distributed on Hacking Forum, but Passwords Old

Related: CISA Urges Manufacturers to Eliminate Default Passwords After Recent ICS Attacks

Related: PoC Tool Exploits Unpatched KeePass Vulnerability to Retrieve Master Passwords

Related Content

Vulnerabilities

The vulnerability can be exploited remotely, without authentication, to circumvent existing authentication controls.

Identity & Access

The most common stolen passwords in 2025 were 123456, admin, and password, according to a Specops study.

Cybercrime

The cybercriminals attempted to steal $28 million from compromised bank accounts through phishing.

Data Breaches

The email addresses were pulled from various sources and 16.4 million of them were not present in previous data breaches.

Network Security

The company sent a new preferences file to less than 5% of customers, urging them to import it into firewalls and reset their passwords.

Identity & Access

Microsoft is prioritizing passwordless sign-in and sign-up methods, and is making new accounts passwordless by default.

Malware & Threats

Juniper Networks says a Mirai botnet is ensnaring session smart router devices that are using default passwords.

Cloud Security

Starting this month, Google Cloud will be rolling out mandatory MFA for all users who sign in with a password.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version