MD5 hash generator
MD5 for the places that still ask for it: legacy checksums, old mirrors and database fingerprints. With the honest health warning attached.
Guide
How to use it
- Type text or pick a file. MD5 sits at the top of the results with the SHA family beneath for comparison.
- Click the MD5 row to copy the 32-character digest.
- Matching a published md5sum? Paste it into the compare field and look for the green badge.
- Choosing an algorithm for something new? Use SHA-256 instead.
Examples
Worked examples
An old firmware archive publishes MD5: 3f2a…. Hash your download in File mode, paste the published value and the badge settles it in seconds.
Type abc: MD5 is 900150983cd24fb0d6963f7d28e17f72, straight from the RFC. This page checks itself against that vector on load.
Legacy databases often key deduplication on MD5 of a field. Hash the two suspect values here and compare, matching digests mean matching text.
Method
How it works, and why not for passwords
MD5 dates from 1992 and produces a 128-bit digest. Collisions, two different inputs with the same hash, were demonstrated in 2004 and are now trivial to manufacture, which ended its security career: no signatures, no certificates and absolutely no password storage, where its raw speed lets attackers test billions of guesses per second.
What survives is the checksum role: catching accidental corruption and matching sums that old systems already published. This page computes MD5 with a small local implementation that self-tests against the RFC 1321 vectors, alongside the SHA family for anything new. Built by Wolds Cyber; nothing you hash leaves your device.
FAQ
Frequently asked questions
Is MD5 still safe to use?
For security, no: collisions can be manufactured on a laptop, so never use it for signatures, certificates or passwords. For spotting accidental corruption or matching a legacy checksum, it still does the job.
Why do so many systems still use MD5?
Inertia. Decades of mirrors, package archives and databases published MD5 sums, and cheap fast hashing is convenient. New systems should publish SHA-256 instead.
Can I decrypt an MD5 hash?
No, hashes are one-way. Sites that appear to reverse MD5 are lookup tables of previously hashed values. A common word's hash is instantly found; random data's is not.
Why is MD5 terrible for passwords?
It is extremely fast, and fast is fatal for password storage: commodity GPUs try tens of billions of MD5 guesses per second. Password storage needs deliberately slow algorithms like bcrypt, scrypt or Argon2. Our strength checker shows the effect on real passwords.
What does an MD5 hash look like?
32 hexadecimal characters, 128 bits. If a published checksum is 40 characters it is SHA-1, and 64 characters means SHA-256; the compare field here detects which one matches automatically.
Is my input uploaded?
No. MD5 is computed by a small implementation running in this page, which self-tests against the published test vectors. Nothing leaves your device.
More tools