bcrypt scenario · cost 10

bcrypt Password Cracking Calculator

Compare random-password resistance for bcrypt cost 10 on a GPU cluster, then switch to cost 5 or 12.

Attack model

Choose a hash family and hardware profile; the table updates immediately.

Maximum time for a complete brute-force search. Human-chosen passwords can be weaker than the same length suggests.
Length 0-9 a-z a-z, A-Z a-z, A-Z, 0-9 a-z, A-Z, 0-9, symbols
> 10 years (Safe)
1–10 years
1 day – 1 year
1 sec – 1 day
< 1 sec (Cracked)
What matters

Length beats complexity

A long random passphrase usually outperforms a short password with symbols. Use a password manager and unique passwords.

Where this applies

Offline hashes only

The model assumes an attacker already has the hash and can test guesses locally. Online logins behave very differently.

For organizations

Prefer slow hashes

bcrypt, Argon2id, scrypt, and high-cost PBKDF2 make every guess expensive and change the table dramatically.

How to read the estimate

bcrypt makes every guess deliberately expensive through its configurable cost. This page starts at cost 10 and 16× RTX 5090 for the Hive 2026 scenario; both cost and hardware remain editable.

Frequently asked questions

What does bcrypt cost mean?

The cost controls the work factor; increasing it by one approximately doubles the computation required per guess.

What password length is safe?

For random passwords, added length rapidly expands the search space, but the outcome still depends on cost and attacker hardware.

Can I compare cost 10 and cost 12?

Yes. Switch the hash option while keeping hardware and length constant to compare the tables.

Methodology

Scope of Applicability

Assumptions & Limitations

    References