Why are MD5 and SHA-1 “broken”?

Last updated: September 28, 2026

“Broken” does not mean “reversed”. We still cannot recover an input from an MD5 hash. But we can produce collisions, and that is enough to make these functions dangerous for security.

What is a collision?

A collision is two different inputs that have the same hash. Since the hash has a fixed size, there are necessarily infinitely many collisions; the question is whether they can be crafted deliberately. A good hash function must make that impossible in practice.

MD5: collisions in a few seconds

MD5 collisions were demonstrated as early as 2004. Today, an ordinary computer crafts one in a few seconds. Two different files (two contracts, two certificates) with the same MD5 hash can thus be created: a signature on one would be valid for the other. MD5 should therefore no longer be used for anything sensitive.

SHA-1: the “SHAttered” collision (2017)

In 2017, Google and CWI published SHAttered: two distinct PDF files with the same SHA-1 hash. The attack was still expensive, but the demonstration sealed the fate of SHA-1, which has since been withdrawn from browsers and certificate authorities.

So, are they still useful?

Yes, but only as checksums against accidental errors (a corrupted transfer, a failing disk). No adversary is involved in that case. For any security use — signatures, integrity against tampering, passwords — use:

  • SHA-256 or SHA-3 for integrity and signatures;
  • a dedicated function (bcrypt,Argon2) for passwords.

In the generator, MD5 and SHA-1 are marked “broken” for this reason.