Recommended Free Tools
Yes—but that headline describes a 2012 offline password-cracking demonstration, not a current speed for every password or a way to try billions of logins on a website. At Passwords^12 in Oslo, Jeremi Gosney presented five servers containing 25 AMD Radeon GPUs. The Security Ledger reported that the cluster could test 348 billion NTLM password hashes per second. That figure applies to that system and that hash algorithm, not to password cracking in general.
What did the 25-GPU demonstration show?
The cluster was used for an offline attack: an attacker with a copy of password hashes tests candidate passwords against them. The reported 348 billion hashes per second was the NTLM rate cited in The Security Ledger’s 2012 account of Gosney’s demonstration. It is a historical, system-specific result—not a measurement of current hardware or a universal rate for password hashes. The Security Ledger’s report also explains a commonly confused example: its estimate that a 14-character Windows XP password could be cracked in about six minutes referred to the older LM scheme, not NTLM.
LM and NTLM are different algorithms, so the six-minute LM example should not be attached to the 348-billion-per-second NTLM figure. The report’s clarification notes that LM uppercases characters, limits passwords to 14 characters, and splits them into two seven-character chunks. Those properties make its search space and cracking behavior different from NTLM’s. The example is about LM’s weaknesses; it does not mean every 14-character password can be cracked in six minutes.
What does “348 billion hashes per second” mean?
A password hash is the result of processing a password with a hashing algorithm. In an offline attack, the attacker guesses a candidate, hashes it using the relevant algorithm, and checks whether the result matches a stolen hash. A reported rate counts how many such calculations a particular setup can perform per second under the stated conditions.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
- Axial-tech fans now feature a smaller fan hub that facilitates longer blades and a barrier ring that increases downward air pressure
- 2.5-slot design allows for greater build compatibility while maintaining cooling performance
- 0dB technology lets you enjoy light gaming in relative silence
- Dual BIOS switch lets you toggle between Quiet and Performance BIOS profiles
- Dual ball fan bearings last up to twice as long as sleeve bearing designs
The number alone does not reveal how quickly a real password will be found. The hash algorithm and its work factor determine how costly each guess is, while the password’s predictability determines whether an attacker is likely to try it early. A raw NTLM rate cannot be transferred to LM or to modern password-storage schemes designed to make each guess more expensive. The cited reporting does not establish a current, broadly applicable cracking rate that should replace the 2012 figure.
Does this mean attackers can try that many passwords on a website?
No. The demonstration concerns guesses checked against a file of hashes that an attacker has already obtained. A live website can limit failed login attempts, slow them down, or apply other controls. Those measures address online guessing; they do not impose the same per-login barriers when an attacker can work against stolen hashes offline.
Rank #2
- Powered by the NVIDIA Blackwell architecture and DLSS 4
- Powered by GeForce RTX 5070 Ti
- Integrated with 16GB GDDR7 256bit memory interface
- PCIe 5.0
- WINDFORCE cooling system
The two risks need different defenses. Rate limiting helps constrain repeated attempts through an authentication service. Secure password storage is needed to make guessing more costly if password hashes are exposed. NIST’s current guidance addresses both: verifiers should rate-limit failed authentication attempts and store passwords using salted hashes with a suitable password-hashing scheme. NIST SP 800-63B-4 says the scheme’s cost should be as high as practical without harming verifier performance, and should rise over time as computing capability improves. OWASP provides implementation guidance for modern adaptive password hashing in its Password Storage Cheat Sheet.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should users and service operators do?
If you use online accounts
- Use a unique password for each account. Reuse can let a password exposed in one breach put other accounts at risk.
- Use a password manager and its generator. NIST requires verifiers to allow password managers and autofill, and notes that managers can help people choose stronger passwords. Its FAQ describes how they support unique passwords and encrypted vault storage. Read NIST’s password-manager FAQ.
- Use phishing-resistant authentication when a service supports it. A FIDO2 security key is one option. NIST notes that passwords are not phishing-resistant; a security key can add account protection, but it does not make hashes in a stolen password database harder to guess. See NIST’s authentication guidance.
If you operate a service that stores passwords
- Never store passwords in plaintext or reversible encryption. Use a modern, suitable password-hashing scheme with a unique salt for each password, following the scheme’s established implementation guidance.
- Choose a cost factor that is practical for your service while making offline guessing more expensive, then revisit it as computing capability changes.
- Rate-limit failed authentication attempts to reduce online guessing. Treat that control as complementary to secure storage, not a substitute for it.
These controls raise the cost of attacks; they cannot guarantee that a weak or reused password will never be guessed.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteQuick Recap
Best Value
- Axial-tech fans now feature a smaller fan hub that facilitates longer blades and a barrier ring that increases downward air pressure
- Phase-change GPU thermal pad helps ensure optimal heat transfer, lowering GPU temperatures for enhanced performance and reliability
- 2.5-slot design allows for greater build compatibility while maintaining cooling performance
- Dual-ball fan bearings last up to twice as long as standard conventional sleeve bearings designs
- 0dB technology lets you enjoy light gaming in relative silence
Rank #4
- Powered by Radeon RX 9070 XT
- WINDFORCE Cooling System
- Hawk Fan
- Server-grade Thermal Conductive Gel
- RGB Lighting
Rank #3
- Powered by the NVIDIA Blackwell architecture and DLSS 4
- Powered by GeForce RTX 5060
- Integrated with 8GB GDDR7 128bit memory interface
- PCIe 5.0
- WINDFORCE cooling system
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

