Skip to main content
Calcimator

Brute Force Attack Time Calculator

Calculate brute force attack time, cost, energy consumption, and feasibility for cryptographic systems.

About this calculator

A brute-force attack tries possible keys until it finds the right one, and how long that takes comes down to a simple ratio: how many keys have to be tried, divided by how fast the attacker can try them. For an exhaustive search over a key space of size N, an attacker doesn't need to try every single key -- on average, the correct key turns up after checking about half the space, since a random key is equally likely to sit anywhere in that range. This is why key space size matters so much for cryptographic strength: since key space typically grows as a power of 2 (a 128-bit key has 2^128 possible values), each additional bit of key length DOUBLES the average number of attempts needed, making brute force exponentially harder against longer keys even though the attacker's speed stays the same.

This calculator divides the average number of attempts by your combined computing power (operations per second times the number of parallel processors) to estimate total attack time, then converts that into years and millennia for readability, along with a rough cost and electricity estimate assuming a flat rate per processor-hour. A dictionary attack works differently -- it only tries a curated list of likely candidates rather than the full key space -- so this calculator models it as a much smaller fraction of the same key-space figure as an illustrative simplification, since a real dictionary attack's actual search space depends on the specific word list used, not a formula derived from key length.

Inputs

Results

Attack Time

5,391,450,000,000,000,000 years

Estimated Cost

$4,726,143,985,013,035,000,000.00

Attack Time5,391,450,000,000,000 millennia
Energy Consumption4,726,143,985,013,035,000,000 kWh
Average Attempts170,141,000,000,000,000,000,000,000,000,000,000,000
How to Use This Calculator
  1. Enter the Key Space Size — the total number of possible keys (e.g., 2^128 for a 128-bit key).
  2. Set Operations per Second — the computational speed of a single attacking processor.
  3. Enter Parallel Processors — how many of those processors are running the attack simultaneously.
  4. Choose Attack Type: Exhaustive Search checks the full key space, Dictionary Attack targets a smaller candidate list.
  5. Review Attack Time in years and millennia, plus the Estimated Cost and Energy Consumption of running the attack that long.

How the result changes with Operations per Second

Operations per SecondAttack TimeEstimated Cost
500,000,000,00010,782,900,000,000,000,000 years$9,452,287,970,026,070,000,000.00
750,000,000,0007,188,600,000,000,000,000 years$6,301,525,313,350,713,000,000.00
1,500,000,000,0003,594,300,000,000,000,000 years$3,150,762,656,675,356,700,000.00
2,500,000,000,0002,156,580,000,000,000,000 years$1,890,457,594,005,214,000,000.00

What each input means

Key Space Size
Total number of possible keys (e.g., 2^128)
Operations per Second
Computational speed per processor
Parallel Processors
Number of parallel processors
Attack Type
Type of brute force attack

How this is calculated

Formula

Time = (Key Space / 2) / (Operations/sec × Processors)

Worked example, using the default values

  1. Identify Input Parameters
    4 parameters
    Key Space Size = 3.402823669209385e+38, Operations per Second = 1000000000000, Parallel Processors = 1, Attack Type = 0 = 4 input(s) provided
  2. Calculate Attack Time
    Attack Time
    5391450000000000000 = 5391450000000000000
  3. Calculate Estimated Cost
    Estimated Cost
    4.726143985013035e+21 = $4,726,143,985,013,035,000,000
  4. Calculate Attack Time
    Attack Time
    5391450000000000 = 5391450000000000
  5. Calculate Energy Consumption
    Energy Consumption
    4.726143985013035e+21 = 4.726143985013035e+21

Engine last updated . Checked against 4 independently-derived tests — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.

Frequently Asked Questions

Why does adding just one more bit to a key roughly double the attack time?

Key space size doubles with every additional bit, since each new bit doubles the number of possible key values. Since brute-force attack time is directly proportional to the size of the key space being searched, doubling the key space roughly doubles the average number of attempts needed and therefore roughly doubles attack time, assuming the attacker's computing power stays the same.

Why does the calculator use half the key space instead of the full key space for exhaustive search?

An attacker doesn't need to check every possible key to succeed -- since the correct key is equally likely to be anywhere in the space, on average it will be found after about half the space has been checked. Using the full key space as "worst case" would overstate typical attack time; averaging over many attack attempts, half the key space is the statistically expected number of tries.

How does adding more parallel processors affect attack time?

Combined computing power in this calculator is operations per second multiplied by the number of parallel processors working simultaneously, so doubling the processor count roughly halves attack time for the same key space and per-processor speed -- provided the attack genuinely parallelizes cleanly across processors, which is generally true for brute force since each processor can independently test a different subset of keys.

Is the dictionary attack estimate as reliable as the exhaustive search estimate?

No -- exhaustive search has a well-defined mathematical basis (half of a known key space), but a real dictionary attack's actual search space depends entirely on the specific word list, common-password list, or rule set the attacker uses, which varies enormously in practice. This calculator models dictionary attacks as a smaller illustrative fraction of the key-space figure rather than a precisely modeled real-world word list, so treat that result as a rough comparison, not a precise prediction.

The questions that sit next to this one — chosen by subject, including calculators filed under a different category.

More in Technology & Computing.