Birthday Attack Calculator
Calculate birthday attack parameters, collision probability, time to collision, and attack feasibility for hash functions.
About this calculator
The birthday attack exploits the same counterintuitive math as the "birthday paradox" -- in a room of just 23 people, there's better than even odds that two share a birthday, even though there are 365 possible birthdays, because you're comparing every pair of people, not looking for a match to one specific date. Applied to hash functions, an attacker hunting for ANY two inputs that produce the same hash output (a collision) needs far fewer attempts than one hunting for a SPECIFIC hash value: roughly the square root of the total hash space, not the full space itself.
That square-root relationship is why hash output length matters so much for collision resistance -- a hash function is generally considered to offer only n/2 bits of collision resistance for an n-bit output, half its apparent strength, which is exactly why cryptographic hash functions are built with long outputs (SHA-256's 256 bits gives 128 bits of birthday-attack resistance, still enormous) and why 128-bit or shorter hash outputs are considered too weak for new cryptographic use. This calculator computes the number of hash attempts needed to reach a target collision probability using the standard birthday-bound approximation, then converts that attempt count into wall-clock time and rough storage cost given an assumed attack speed -- storage matters because most practical birthday-attack implementations need to remember every hash computed so far to check new ones against it.
Inputs
Results
Birthday Bound
400,651,869,298,001,200,000,000,000,000,000,000,000
50% Probability Bound
400,651,869,298,001,200,000,000,000,000,000,000,000
Time to Collision
12,695,900,000,000,000,000,000 years
How to Use This Calculator
- Enter the hash function output size in bits.
- Set the number of hashes the attacker can compute per second.
- Review the number of hash computations needed for a 50% collision probability.
- Verify that your hash function output size is at least 2x the desired security level in bits.
- For 128-bit security, use SHA-256 or stronger -- MD5 and SHA-1 are vulnerable.
How the result changes with Hash Length
| Hash Length | Birthday Bound | 50% Probability Bound | Time to Collision |
|---|---|---|---|
| 128 | 21,719,381,355,163,560,000 | 21,719,381,355,163,560,000 | 688.25 years |
| 192 | 93,284,032,609,779,660,000,000,000,000 | 93,284,032,609,779,660,000,000,000,000 | 2,955,990,000,000 years |
| 384 | 7,390,722,495,593,557,000,000,000,000,000,000,000,000,000,000,000,000,000,000 | 7,390,722,495,593,557,000,000,000,000,000,000,000,000,000,000,000,000,000,000 | 234,198,000,000,000,000,000,000,000,000,000,000,000,000 years |
| 512 | 136,334,766,396,022,310,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000 | 136,334,766,396,022,310,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000 | 4,320,190,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000 years |
What each input means
- Hash Length
- Hash output length in bits
- Target Collision Probability
- Desired probability of finding collision
- Hash Operations per Second
- Computational power available
How this is calculated
Formula
Birthday Bound ≈ √(2 × m × ln(1/(1-P)))Worked example, using the default values
- Identify Input Parameters3 parametersHash Length = 256, Target Collision Probability = 50, Hash Operations per Second = 1000000000 = 3 input(s) provided
- Calculate Birthday BoundBirthday Bound4.006518692980012e+38 = 4.006518692980012e+38
- Calculate 50% Probability Bound50% Probability Bound4.006518692980012e+38 = 4.006518692980012e+38
- Calculate Time to CollisionTime to Collision1.26959e+22 = 1.26959e+22
- Calculate Storage RequiredStorage Required1.1940356174051796e+31 = 1.1940356174051796e+31
- Calculate Estimated CostEstimated Cost4.0065186929800117e+30 = $4,006,518,692,980,011,700,000,000,000,000
Engine last updated . Checked against 1 independently-derived test — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.
Frequently Asked Questions
Why does a birthday attack need so much less work than a brute-force preimage attack?
A preimage attack is looking for an input that hashes to one SPECIFIC target value, which takes on the order of the full hash space (2^n attempts) on average. A birthday (collision) attack is looking for ANY two inputs that hash to the same value as each other, and because it's comparing every pair of attempts against every other pair rather than against one fixed target, the number of attempts needed drops to roughly the square root of the hash space -- a dramatically smaller number for large n.
Why is a hash function's collision resistance only half its output length?
Because the birthday bound scales with the square root of the hash space size, and the hash space size is 2 raised to the output length in bits -- taking a square root of 2^n is the same as 2^(n/2). So an n-bit hash function offers roughly n/2 bits of actual security against collision attacks, even though brute-force resistance to finding one specific hash value (a preimage attack) still requires the full n bits of work.
Why does storage matter for a birthday attack?
To detect that two of your hash attempts collide, you generally need to keep every previously computed hash around so a new one can be checked against the whole set -- unlike a preimage attack, which can discard each failed guess immediately since it's only comparing against one fixed target. As the number of attempts approaches the square root of the hash space, the storage needed to remember them all becomes a real, sometimes limiting, practical cost.
Why does raising the target collision probability increase the number of attempts needed?
The birthday-bound formula includes a ln(1/(1-P)) term that grows as the target probability P approaches 100% -- pushing for near-certainty requires substantially more attempts than settling for 50% odds, since the marginal attempts needed to close the gap toward certainty keep growing. This is the same reason a 50% collision probability is treated as the standard reference point for describing a hash function's practical collision resistance.
Related Calculators
The questions that sit next to this one — chosen by subject, including calculators filed under a different category.
Hash Collision Probability Calculator
Calculate hash collision probability using birthday paradox. Find collision probability and birthday bound for hash functions.
Cryptography & SecurityBrute Force Attack Time Calculator
Calculate brute force attack time, cost, energy consumption, and feasibility for cryptographic systems.
Cryptography & SecurityAttack Probability Calculator
Comprehensive cryptographic attack analysis. Brute force, birthday attacks, side-channel risks, password strength, and key derivation security.
Space TechnologySpace Debris Risk Calculator
Collision probability from object density and orbital altitude.
Technology & ComputingHash Properties Calculator
Compare cryptographic hash function properties. See output size, collision resistance, brute force time, and security status for MD5, SHA-1, SHA-256, SHA-512, and bcrypt.
More in Technology & Computing.