Hash Recovery by Brute Force

Test every possible combination against a hash, with a time estimate before starting and GPU acceleration (WebGPU). Authorized use only.

Only use this on your own hashes or in an authorized context (audit, penetration test with written consent). A hash cannot be “decrypted”: candidates are tested and compared.

Character set

100% local processing, nothing is uploaded

How does it work?

Brute force tests every combination of a character set (digits, letters, symbols…) for a range of lengths. Before starting, the tool measures your machine’s real rate (a short calibration phase) and shows the estimated time. If the search space is out of reach, it refuses to start rather than waste hours of your time.

For MD5, SHA-1 and SHA-256 without salt or prefix, the computation can run on the graphics card (WebGPU), which is much faster, with automatic fallback to the multi-threaded processor. The GPU’s accuracy is rechecked against the processor before each use. Nothing is uploaded.

Examples

A 4-digit PIN

“Digits” set, lengths 4 to 4: only 10,000 combinations, found in a fraction of a second. Ideal for understanding the principle.

The mathematical wall

An 8-character password from 95 possible characters is 95⁸ ≈ 6.6 × 10¹⁵ combinations. Even at a billion per second, that takes more than two months — and each additional character multiplies it by 95 again.

Frequently asked questions

Does this “decrypt” the hash?
No, and that is impossible: a hash is one-way. The tool computes the hash of candidates (words from a list, or combinations) and compares it with the target. If none matches, nothing is found.
Why refuse to start some searches?
Because they would take centuries. A browser, even with WebGPU, remains far behind a native tool such as hashcat, which accesses the GPU driver directly. Beyond a certain space, brute force is futile: better to know that beforehand.
Am I allowed to use this tool?
Only on your own hashes, or in an explicitly authorized context (security audit, penetration test with written consent). Trying to recover someone else’s password without authorization is illegal. Everything happens locally: nothing is sent or stored.
Is my data sent anywhere?
No. All the computation happens in your browser, in JavaScript and WebAssembly. Your text, your files and your hashes never leave your device: no network request is made during hashing, and nothing is stored on a server.