Can AI crack your passwords?
Can AI crack passwords? A reality check on PassGAN and the 51% headline, what AI really changes for attackers (phishing, voice clones) and how to stay safe.

On this page
Can AI crack passwords? It can help attackers guess the passwords people invent, but so far it has not beaten the tools password crackers already use, and it cannot guess a truly random password any faster than arithmetic allows. The bigger AI risk sits elsewhere: convincing phishing messages and cloned voices that trick you into handing a password over.
Below: how password cracking actually works, what the famous "AI cracks half of all passwords in a minute" story measured, where machine learning genuinely helps attackers, and a short checklist that holds up whether or not the attacker uses AI.
How password cracking works today
Most websites do not store your password itself. They store a hash of it: the output of a one-way function that turns sunflower42 into a fixed-length string of gibberish. When you sign in, the site hashes what you typed and compares the results.
- Hash
- A one-way fingerprint of some data. The same input always gives the same fingerprint, but you cannot run the function backward to get the input. The only way to "reverse" a password hash is to guess inputs, hash each guess, and look for a match.
Cracking starts when a database of hashes leaks in a breach. The attacker copies it to their own machines and guesses offline, with no website to slow them down. A free tool called hashcat does the heavy lifting on graphics cards (GPUs). For a fast, outdated hash like MD5, one RTX 5090 tries about 220 billion guesses per second.
With that much speed, the question becomes which guesses to try first. Crackers answer it with four techniques that long predate the current AI wave:
- Lists of real passwords. The 2009 RockYou leak alone exposed about 32.5 million passwords in plain text, and later breaches added far more. People reuse the same favorites, so these lists hit often.
- Dictionaries. Words, names, places, sports teams, song titles.
- Rules. Hashcat's rule engine transforms each word the way people do: capitalize the first letter, add a year, swap
afor@, add!at the end. One word becomes hundreds of candidates. - Masks. A mask attack tries every password with a given shape, such as one capital letter, six lowercase letters and two digits.
Breach
A site's database of password hashes is stolen and copied.
Guess generator
Leaked lists, dictionaries, rules, masks, and sometimes a trained model.
GPU hashing
Each guess is hashed the same way the site did it.
Match
A matching hash reveals the password, which is then tried on other sites.
There is also a shortcut that needs no cracking at all. Credential stuffing takes email and password pairs from one breach and tries them automatically on other sites, betting that you reused the password. It is common enough that OWASP, a nonprofit that publishes security guidance for developers, keeps a whole guide on defending against it.
Can AI crack passwords? The PassGAN headlines
In April 2023, a website called Home Security Heroes published a study that went viral: an AI tool, PassGAN, "cracked" 51% of common passwords in under a minute, 65% in under an hour and 81% within a month. The test used 15.68 million passwords from the RockYou leak. The page does not say which hash was attacked or what hardware ran the test, and both decide how long "cracking" takes.
PassGAN itself is real research. Hitaj, Gasti, Ateniese and Perez-Cruz first published it in 2017 and revised it through 2019. It uses a generative adversarial network (GAN): two neural networks trained against each other until one produces strings that look like real human passwords. The idea was to learn human habits from leaked data instead of writing rules by hand.
What the PassGAN paper actually found
The paper's own numbers are more modest than the headlines. The authors trained every tool on part of RockYou, limited to passwords of 10 characters or fewer, and tested on RockYou passwords the tools had not seen:
| Tool | Guesses tried | Share of test passwords matched |
|---|---|---|
| Hashcat with its standard "Best64" rules | about 360 million | 31.84% |
| PassGAN, to beat that result | about 5.06 billion | 31.86% |
| PassGAN, largest run reported | about 7 billion | 34.19% |
To edge past Best64, a small rule set that ships with hashcat, PassGAN needed about 14 times as many guesses. Where it helped was in combination: run after the rules, 7 billion PassGAN guesses cracked about 51% more RockYou test passwords than the rules had found on their own. The model found different passwords, which is useful to a cracker who runs both, but it did not replace the classic tools.
When the 2023 study went viral, Ars Technica's senior security editor called PassGAN mostly hype, concluding that it "performs no better than more conventional cracking methods." Jeremi Gosney, the password-cracking expert quoted in the piece, called PassGAN an interesting early experiment whose "time in the sun has come and gone", and noted that another neural-network method from 2016 already does slightly better.
Why "51% in under a minute" says little
- Common passwords fall to any method. RockYou is full of
123456andiloveyou. A plain list of leaked passwords cracks most of them just as fast. - The model learned from the same kind of data it was tested on. Guessing RockYou-style passwords after training on RockYou is the easiest possible test.
- Time depends on the hash. A minute of MD5 guessing on one modern GPU is trillions of guesses. The same minute against Argon2id with Cappa's settings is about a hundred thousand.
Research has moved on since 2023. A benchmark called MAYA (accepted at IEEE Security & Privacy 2026) compared six generative models across eight leaked datasets. It found that models which write a password one character at a time (similar in approach to today's chatbots) beat the other deep-learning designs, that older statistical methods stayed surprisingly competitive, and that results varied significantly with long and complex passwords. So yes, machine learning does improve guessing of human-chosen passwords. It improves on human habits, not on randomness.
Where AI genuinely helps attackers
Guessing your password from what it knows about you
The most worrying research is not about crowds but about individuals. In 2016, Wang and colleagues built TarGuess, a set of statistical models that guess one specific person's password using their personal details (name, birthday, phone number) plus a password of theirs leaked from another site. With both kinds of information, two of their models guessed more than 73% of ordinary users' passwords, and more than 32% of security-savvy users' passwords, within just 100 attempts.
That is few enough to try on a live sign-in page before any lockout. TarGuess used statistics rather than today's language models, but the lesson carries over: once a password is built from your life and your old passwords, it is not random. It is our inference, not a measured result, that modern AI tools make the research step (collecting your details from social media and old breaches) cheaper and faster.
Better phishing and cloned voices
Here the evidence is direct. In December 2024 the FBI warned that criminals use generative AI to write convincing messages without spelling mistakes, to create fake profiles and documents, and to clone a relative's voice from a short clip to ask for emergency money. The FBI's advice: agree on a secret word or phrase with your family, and verify a caller by hanging up and dialing a number you already know.
In Poland, CERT Polska's report on 2025 (published April 2026) registered 260,783 unique incidents, 97% of them fraud such as phishing and fake investments. The team says it observes dozens of campaigns generated with AI tools, and deepfake images and videos have become a standard part of investment scams.
A phishing page that steals your password does not need to crack anything. It simply asks, and AI makes the asking more convincing.
Scale
AI also lets one criminal do the work of many: translating scams into any language, running chat conversations with hundreds of victims at once, and building look-alike websites faster. None of this touches the math of passwords. It targets the person typing them.
What AI can't do: beat the math of a random password
Every guessing method, from dictionaries to neural networks, works the same way: it bets that your password follows a pattern that people share. A password chosen at random by a generator follows no pattern. Every possible candidate is equally likely, so there is nothing for a model to learn, and the attacker is back to trying possibilities one by one.
That makes the numbers from our master password guide hold regardless of AI. Six random words from the EFF list give about 77.5 bits of unpredictability. Even for a pessimistic cluster of 10,000 top GPUs guessing an Argon2id-protected password at 30 million guesses per second (our estimate, as of September 2026), the average time to find them is about 120 million years.
AI also does not make hashing faster. With Cappa's settings (64 MiB of memory, 3 passes), every guess must fill and walk through 64 MiB of memory, and hashcat's own benchmark measures about 1,703 guesses per second on an RTX 4090. A smarter guess list changes the order of guesses, never the cost of each one. Our Argon2 explainer shows why memory is the bottleneck.
What AI changes
- Guesses for human-made passwords come in a smarter order
- Personal details and old leaks are easier to collect and combine
- Phishing messages read naturally in any language
- A few seconds of your voice can be enough for a convincing clone
What AI doesn't change
- A random password has no pattern to learn
- Each guess against a slow hash like Argon2id costs just as much
- A unique password is useless on other sites even if one site leaks
- A passkey cannot be typed into a fake site, so it cannot be phished
Attacks, the role of AI, and the defense that works
| Attack | What the attacker needs | What AI adds | What stops it |
|---|---|---|---|
| Offline cracking of a leaked hash | A stolen database | Somewhat better guesses for human-made passwords | A random password; the site using a slow hash |
| Credential stuffing | Your password from another breach | Little | A unique password for every site |
| Targeted guessing | Your personal details, old passwords | Faster research | A random password unrelated to your life |
| Phishing page | You typing your password | Convincing, error-free messages | A password manager that won't fill on a fake domain; passkeys |
| Voice or video impersonation | A sample of someone's voice or face | Realistic clones | Calling back on a known number; a family code word |
How to protect your passwords from AI-assisted attacks
- Use a password manager and let it generate a random, unique password for every account.
- Make your master password long and random: 16 or more random characters, or six random words (five at the very least).
- Never reuse a password. When your browser or password manager warns that a password appeared in a breach, change it on that site.
- Turn on passkeys where a service offers them. They cannot be guessed and only work on the real site; our passkeys guide explains how.
- Where passkeys are not available, turn on two-step verification, preferably with an app or a security key rather than SMS.
- Treat any urgent request for money, codes or passwords as suspicious. Verify it through a second channel: call back on a number you already know, or ask a question only the real person can answer.
- If your password manager does not offer to fill a password on a page, stop and check the address before typing it yourself.
What Cappa does, and what it can't do
Cappa is an end-to-end encrypted notes app, so the password that matters most is your master password: it both signs you in and unlocks your encrypted notes. Here is how Cappa handles the threats above, as of September 2026.
- It refuses predictable master passwords. When you set a new master password, your browser checks it with the open-source estimator zxcvbn-ts against bundled lists of common and leaked passwords, words and names, and rejects anything estimated at fewer than about 10 billion guesses, anything shorter than 16 characters, and a few famous passphrases. The check runs entirely in the browser; the password is never sent to a breach-lookup service, so a password that leaked elsewhere but is missing from the bundled lists can still pass.
- Every offline guess costs a full Argon2id run. If Cappa's database were stolen, each guess at your master password would need 64 MiB of memory and three passes, as described above.
- Guessing through the sign-in page is slow. The server limits sign-in attempts from each network address.
FAQ
Can ChatGPT crack my password?
A chatbot does not crack password hashes. Cracking is done by tools like hashcat running on graphics cards, and a language model is not needed for that. What a chatbot can do is help a criminal write a convincing phishing message or collect details about you, which is why verifying unusual requests matters more than ever.
Is PassGAN still a threat?
PassGAN is a 2017 research model. Its own paper shows it needed far more guesses than standard hashcat rules to match the same share of passwords, and newer models have since overtaken it. The real lesson from PassGAN is older than AI: passwords that people invent follow patterns, and patterns can be learned.
Can AI crack a 16-character password?
If the 16 characters were chosen at random by a password manager, no: there is no pattern to learn, so AI falls back to trying possibilities one by one, which takes far longer than any attacker has. If the 16 characters are a phrase, a name plus a year or an old password with changes, they can fall quickly, with or without AI.
Are passkeys safe from AI?
Passkeys are not guessable, because they are cryptographic keys rather than something a person chose, and they only work on the website they were created for. An AI-written phishing page cannot trick your device into using them on the wrong domain. Protect the device and the account that syncs your passkeys, since anyone who can unlock them can use them.
How can I tell if a message or call was made with AI?
Often you can't, and that is the point. Instead of judging how real something sounds, check the request itself: if it asks for money, codes or passwords, contact the person or company through a channel you already trust before doing anything.


