MD5 Hash Generator — Free Online Tool

Generate a 128-bit MD5 digest from any text, and understand exactly what MD5 is still safe for. Enter your text below and press MD5.
Accepts HTML, text file
0 Characters0 Words
Hash Generator Online Tool

MD5 Hash Generator

Generate a 128-bit MD5 digest from any text, and understand exactly what MD5 is still safe for.

MD5128-bit1992Cryptographically broken

What MD5 Is

MD5 was designed by Ronald Rivest in 1992 as the successor to MD4 and became, for a decade, the default hash function of the internet. It produces a 128-bit digest, written as 32 hexadecimal characters, and it is very fast. Both of those properties are now the reasons not to use it for anything security-related.

MD5 specification
AlgorithmMD5 (MD family)
Digest length128 bits — 32 hexadecimal characters
Block size512 bits
Designed byRonald Rivest, 1992
SpecificationRFC 1321
Status in 2026Cryptographically broken

A worked example

Hashing the five characters hello with MD5 gives:

5d41402abc4b2a76b9719d911017c592

Change a single character of the input and the entire digest changes, with no resemblance to the previous one. That property is called the avalanche effect, and every cryptographic hash is designed to have it.

How MD5 Got Here

Cracks appeared early. Den Boer and Bosselaers found a pseudo-collision in the compression function in 1993, a year after publication. Dobbertin demonstrated a full collision in the compression function in 1996, and cryptographers began advising against MD5 for new designs from that point. The decisive break came in 2004, when Wang, Feng, Lai and Yu published a differential attack that produced full MD5 collisions in hours on ordinary hardware. By 2008 researchers had used chosen-prefix collisions to forge a certificate authority certificate that browsers accepted, and in 2012 the Flame malware used an MD5 collision to forge a Microsoft code-signing certificate and spread through Windows Update. Producing an MD5 collision today takes seconds on a laptop.

Security Status of MD5

MD5 is broken against collisions, meaning an attacker can construct two different inputs with the same digest. It is not broken against preimages - given a digest, recovering the original input is still computationally hard in the general case - but that is thin protection, because rainbow tables and GPU brute force defeat MD5 for anything with low entropy such as a human-chosen password. A modern GPU computes tens of billions of MD5 hashes per second.

Use MD5 for

  • Detecting accidental file corruption after a download or a copy, where nobody is trying to deceive you.
  • Cache keys, ETags and content-addressed lookups inside your own system.
  • De-duplicating files or records where a deliberate collision would cost the attacker nothing worth having.
  • Non-security bucketing, such as sharding a dataset by hashing an identifier.

Do not use MD5 for

  • Password storage. Use bcrypt, scrypt or Argon2id, which are deliberately slow and salted.
  • Digital signatures, certificates, or anything a trust decision depends on.
  • Verifying a download against tampering by an attacker who controls the file and the checksum.
  • Deduplicating content where an attacker chooses the content - collisions let them displace a file.

How to Use This MD5 Generator

  1. Paste or type your text into the input box above, or upload a plain-text file.
  2. Press the MD5 button.
  3. The digest appears in the output box, ready to copy.

The same input always produces the same output@if($algo['status'] === 'password') — except with bcrypt, where the random salt makes every result different@endif, on this page or in any correct implementation. If a digest from another tool disagrees with this one, the cause is almost always a difference in the input: a trailing newline, a different character encoding, or invisible whitespace.

Frequently Asked Questions About MD5

Can an MD5 hash be decrypted back to the original text?

No. MD5 is a one-way function, not encryption, so there is no key and no decryption step. What lookup sites actually do is compare your digest against a precomputed table of hashes for common inputs. That works for "password123" and fails completely for a long random string, which is why MD5 lookup sites can appear to reverse a hash without reversing anything.

Why is MD5 still everywhere if it is broken?

Because it is fast, it is implemented in every language and toolchain, and most of the places it is used are not adversarial. A build system checking that a copied artefact is intact does not care that a determined attacker could construct a collision. The problem is only when MD5 is used where an attacker is assumed - passwords, signatures, and tamper detection.

Is a salted MD5 hash safe for passwords?

Salting defeats precomputed rainbow tables, so it is better than unsalted MD5, but it does not fix the underlying problem. MD5 is fast, and a fast hash means an attacker with a leaked database can try billions of candidate passwords per second per GPU against each salt. Password hashing needs a deliberately slow algorithm with a tunable work factor.

How long is an MD5 hash?

Always 128 bits, written as 32 hexadecimal characters, regardless of whether the input was one character or one gigabyte. That fixed length is a property of every hash function and is why digests can be stored in a fixed-width column.

Hashing in One Minute

A hash function takes input of any length and returns a fixed-length digest. Three properties define a cryptographic hash: the same input always yields the same digest, it is infeasible to recover the input from the digest, and it is infeasible to find two inputs that produce the same digest. Hashing is one-way and keyless, which is what separates it from encryption — there is nothing to decrypt, because nothing was encrypted.

Where hashes go wrong is almost always a mismatch between the job and the tool. A checksum for detecting a corrupted download and a password hash protecting a leaked database are different problems, and an algorithm that is excellent at one can be disqualifying at the other. For the full treatment — how the algorithms work internally, salting, HMAC, rainbow tables and the rest — see the complete guide to hash generation.

The Other Algorithms in This Tool

The generator above supports every algorithm below. Each has its own page explaining what it is for.