ToolNest logoToolNest.

MD5 vs SHA-256: What's the Difference

MD5 and SHA-256 are both hash functions — they turn any input into a fixed-length fingerprint — but MD5's 128-bit digest is cryptographically broken, while SHA-256 produces a 256-bit digest and remains secure. Use SHA-256 for passwords, signatures, and integrity checks; MD5 is only fine for non-security uses like checksums. Compare both on our free hash generator.

The short answer

A hash function takes any input — a password, a file, a novel — and produces a fixed-length 'fingerprint' called a digest. MD5 always outputs 128 bits (written as 32 hex characters); SHA-256 always outputs 256 bits (64 hex characters). Both are deterministic: the same input always gives the same digest, and changing one letter of the input scrambles the output completely. The difference that matters is security: researchers can now craft two different inputs with the same MD5 digest — a collision — which breaks MD5 for anything adversarial, like certificates or file verification against attackers. SHA-256 has no practical collision attack and is the current standard. So: SHA-256 for security, MD5 only where no attacker is involved.

What a hash function actually does

Three properties define a cryptographic hash. Determinism: hash the same file a thousand times, get the same digest a thousand times — this is what makes checksums useful. The avalanche effect: flip one bit of input and roughly half the output bits change, so similar inputs have wildly different digests — there is no 'close' in hash space. One-wayness: given only the digest, reconstructing the input should be infeasible — you can verify a password by hashing the guess and comparing digests without ever storing the password itself. A fourth property, collision resistance, says nobody should be able to find two different inputs with the same digest. MD5 fails this fourth property today, which is precisely what 'broken' means — the first three still hold. Understanding which property your use case needs is the key to choosing correctly.

MD5: the 128-bit workhorse

MD5 was designed by Ronald Rivest in 1991 as a fast message digest for integrity checking, and for over a decade it was everywhere: file checksums, password storage (regrettably), data deduplication. Its 128-bit output fits in 32 hex characters — short enough to eyeball-compare and cheap to store. It is also fast: on modern hardware MD5 chews through gigabytes per second, noticeably quicker than SHA-256. That speed-plus-compactness combination is why it refuses to die. It survives legitimately in non-adversarial roles: checksumming downloads against accidental corruption, fingerprinting files for deduplication, generating deterministic ids from content. The rule is simple: if the worst case is random corruption rather than a motivated attacker, MD5 remains a perfectly good tool. The moment an attacker enters the picture, retire it.

SHA-256: the 256-bit standard

SHA-256 is one of the SHA-2 family, published by NIST in 2001, and it is the workhorse of modern security infrastructure. Its 64-hex-character digest gives 2²⁵⁶ possible outputs — a number so large that brute force is physically meaningless; you would need more energy than the sun will ever produce to have a real chance. SHA-256 secures TLS certificates, signs software updates, anchors the Bitcoin blockchain (miners race to find inputs whose SHA-256 digest starts with enough zeros), and sits inside password-hashing schemes and HMAC constructions — including the signatures on JWT tokens. It is slower than MD5 by design-adjacent accident (more rounds, bigger state), but on modern CPUs the difference is irrelevant for anything short of bulk data processing. When in doubt, SHA-256 is the default answer.

Head to head: MD5 vs SHA-256

Digest size: 128 bits vs 256 bits — SHA-256's space is 2¹²⁸ times larger, which is the entire security story in one number. Output length: 32 vs 64 hex characters. Speed: MD5 is roughly twice as fast in software, though both exceed a gigabyte per second on modern hardware. Collision resistance: MD5 is broken — practical collision attacks exist and run in seconds on a laptop; SHA-256 has no practical attack, with the best known results still purely theoretical. Preimage resistance (reversing a digest): both still hold, though MD5's margin is thinner. Adoption: MD5 lingers in legacy systems and checksums; SHA-256 is mandated or default in TLS, code signing, Git's transition plans, and cryptocurrencies. Bottom line: they are not competitors anymore — MD5 is a legacy utility, SHA-256 is the standard. The comparison matters only because so much MD5-era infrastructure still needs migrating.

How MD5 broke — and what 'broken' really means

The fall took a decade. In 2004 researchers demonstrated practical MD5 collisions — two different inputs, same digest — and by 2008 the attack was weaponized: researchers forged a rogue certificate authority certificate by colliding certificate requests, undermining the web's trust model. In 2012 the Flame malware used an MD5 collision to fake Microsoft code-signing. 'Broken' here has a precise meaning: collision resistance is dead. But nuance matters — preimage attacks (finding an input for a given digest, i.e., reversing a hash) remain infeasible at around 2¹²³ operations, so MD5 still hides passwords from casual reversal. The practical upshot: MD5 is unsafe wherever an attacker can choose the inputs — signatures, certificates, file verification against tampering. It is fine where inputs are not attacker-controlled — accidental-corruption checksums, hash tables, content fingerprints. 'Broken' does not mean 'useless'; it means 'know exactly which property you are relying on.'

Which should you use? A decision guide

Verifying downloads or files against tampering: SHA-256, always — checksums from a vendor assume an attacker might swap the file. Checksumming against accidental corruption (did my copy complete?): MD5 is fine and faster, though SHA-256 costs little. Storing passwords: neither raw — use Argon2, bcrypt, or scrypt, which are deliberately slow to blunt brute force; raw SHA-256 of a password falls to GPUs in hours, and MD5 in minutes. Signing data or tokens: SHA-256 inside HMAC or RSA/ECDSA — this is what JWT signatures use. Deduplicating files or generating content ids: MD5 is acceptable, SHA-256 if you want margin. Checksums in legacy protocols that mandate MD5: use it, but understand the protocol is the weak link. And if you are building something new and unsure: SHA-256. It is never the wrong choice; MD5 sometimes is.

See it yourself: the word 'hello', hashed

Here are real digests, computed for this article — paste 'hello' into any hash tool to confirm. MD5('hello') = 5d41402abc4b2a76b9719d911017c592 (32 characters). SHA-256('hello') = 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824 (64 characters). Now change one letter — 'Hello' with a capital H — and both digests change beyond recognition: that is the avalanche effect, and you can watch it live in our free hash generator. Notice the lengths: you can identify the algorithm from digest length alone, a handy trick when staring at an unknown hash in a config file or database. Also notice neither digest reveals anything about the input — 'hello' is nowhere visible in either string, which is the one-way property at work.

Verifying a download with a checksum, step by step

This is the most common real-world use of hashing, and it takes thirty seconds. Step 1: the software vendor publishes a SHA-256 checksum alongside the download — a 64-character string on their download page. Step 2: download the file. Step 3: hash the file locally — on our hash generator you can drop the file itself in, no upload involved, or use shasum -a 256 filename on Mac/Linux. Step 4: compare the two strings character by character. Match: the file is exactly what the vendor published — no corruption, no tampering. Mismatch: delete it and re-download; never install a mismatched binary. This single habit defeats corrupted downloads, man-in-the-middle swaps, and compromised mirrors. Vendors publish MD5 checksums too on older pages — they still catch accidental corruption, but for security-sensitive software, insist on SHA-256.

Generate MD5, SHA-256, and more in one click

Our free hash generator computes MD5, SHA-1, SHA-256, and SHA-512 from typed text or a dropped file — instantly, in your browser, with nothing uploaded. It is the fastest way to compare algorithms side by side, verify a checksum, or fingerprint a file. Hashing passwords? Read how to create a strong password first — then hash it properly. Curious where hashes guard web logins? That is how JWT tokens work, signatures included. And for the data formats hashes usually protect, see what JSON is.

Do it in one click

Generate MD5, SHA-256 & more — free, files never uploaded.

Open the Free Tool →