How long until it's cracked?

A random secret's strength is just charset × length, fed through log₂Each bit doubles the search space. n bits means 2ⁿ possible secrets — and a guesser, on average, needs half of that to land on yours.. An attacker's strength is guesses per second. Divide and you get time. The adversarial twin of the ID collision calculator — same combinatorics, opposite question.

A random-character secret from.
12 characters × log₂(62) ≈ 71.5 bits · 3.2 × 10²¹ possible secrets
5.1 × 10⁶ yearsaverage crack time

At offline, fast hash rates (10⁷⁄s), an attacker needs about 5.1 × 10⁶ years on average to land your secret. Comfortably out of reach.

71.5bits of entropy
3.2 × 10²¹combinations
5.1 × 10⁶ yearsat chosen rate
AttackerAverage crack time
10⁄sOnline, throttled
rate-limited login form
5.1 × 10¹² years
10³⁄sOnline, unthrottled
no rate limit, plain API
5.1 × 10¹⁰ years
10⁴⁄sOffline, slow hash
bcrypt / argon2 stolen dump
5.1 × 10⁹ years
10⁷⁄sOffline, fast hash
single GPU on SHA-256
5.1 × 10⁶ years
10¹¹⁄sGPU farm
cluster on MD5 / SHA-1
511 years
10¹⁵⁄sNation-state
dedicated cracker on weak hashes
18.7 days

"Average" assumes the attacker stumbles on your secret halfway through the space — the worst case is twice as long, the best is instant. Rule of thumb: under 60 bits is brittle, ~80 bits is OK against online attack, 100+ for offlineA common rough guideline: 80 bits resists patient online attack, 100 bits resists offline hashes, 128 bits is comfortable today, 256 bits is post-quantum margin. Real strength depends on the hash and the attacker — these are orders of magnitude, not promises., 128+ for "I don't want to think about it again."

Entropy = length · log₂(alphabet); average crack time = 2H / (2 · rate). Assumes uniformly random — re-used or human-chosen secrets are far weaker.