iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Yes, attackers can bring more computing power to password cracking, but AI has not made every password suddenly easy to break. The widely cited estimates model offline guessing against stolen password hashes, not attempts against a live account. They assume particular hardware, hash settings and randomly generated passwords; reused, breached or predictable passwords may fall much sooner.
What the 2025 two-month estimate actually says
HotHardware’s April 30, 2025 article summarized a Hive Systems password table and reported that an eight-character password using digits and uppercase and lowercase letters would take two months to crack in a scenario labeled “ChatGPT 3 (hardware A100 ×10,000).” That is a modeled estimate for a randomly generated password under the table’s assumptions—not a measured forecast for every password with those character types, and not a prediction of how long it takes to break into a live account. HotHardware’s 2025 summary notes that exposed, reused and dictionary-based passwords are easier to attack. [c001] [c004]
The distinction matters because a random password drawn from a large set of possible combinations is a different target from a password based on a familiar word, a predictable pattern or credentials already found in a breach. A table’s brute-force duration can badly overstate protection when an attacker can prioritize likely guesses.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteWhat Hive Systems’ 2026 figures add
In its 2026 explainer, Hive Systems describes its table as modeling offline guesses against stolen password hashes. It reports testing a rented fleet of 16 RTX 5090 GPUs, split between two eight-GPU hosts, at 138,675 bcrypt hashes per second with the hash work factor set to 10. Hive says this was about 24% faster than its 2025 reference setup of 12 RTX 5090 cards, which it reports at 111,490 hashes per second. These are company-produced benchmarks from particular configurations, not a universal measure of what every attacker can rent or achieve. Hive Systems’ 2026 explainer [c002] [c003]
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Using its stated assumptions, Hive models about 132 years to exhaust an eight-character randomly generated password made from digits, uppercase and lowercase letters, and its limited symbol set against bcrypt at cost 10 on the assumed fleet. That is a table estimate, not a safety guarantee: changing the password’s predictability, hash algorithm, work factor or available hardware changes the problem. [c002]
What AI does—and does not—change
Hive Systems says AI-assisted scripting made it easier to rent and orchestrate multiple machines. It does not say AI made an individual GPU faster at bcrypt. In this account, AI can lower the operational barrier to coordinating compute; the hash algorithm and work factor, hardware and how predictable a password is still determine the cracking effort. [c002]
Rank #2
- Requires 3 "AAA" batteries (included)
- Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
That is why “AI cracks passwords” is too broad a description. AI can help people automate tasks around an attack, but these figures do not show that AI can simply defeat a long, unique, randomly generated password. Nor does the 2026 comparison prove that all attackers have access to the same rented fleet or configuration.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Offline hash cracking is not a live login attack
The estimates concern an attacker who has obtained a database of password hashes and can make guesses offline against those copied hashes. Online login systems can impose rate limits, lockouts or other controls on attempts made through their sign-in pages. Those controls do not slow guesses made locally against stolen hashes. [c002] [c003]
Rank #3
For online attacks, service-side protections still matter. But they are not a substitute for strong, unique credentials: a password reused on another service may already be exposed, and a predictable password can be found through guesses informed by wordlists and earlier breaches. [c002]
How to reduce your risk
- Use a unique password for every account. Reuse turns a breach at one service into a risk for others.
- Generate long, unpredictable passwords. A password manager can create and store a separate credential for each account. Length and unpredictability matter more than swapping a few letters for symbols in a short, recognizable password.
- Use a passkey where the service supports it. Check that your account and devices support the passkey method, and understand the service’s recovery options.
- Enable multifactor authentication when available. It adds another barrier to account access, though it does not make a stolen password hash harder to guess offline.
- Consider a FIDO2 security key only if it fits your setup. It is an optional hardware authenticator for supported services and devices, not a requirement for protecting every account.
Buying a GPU is not a defensive measure: the GPUs in these reports are attacker compute, and owning one does not provide the protection described above. [c004]
Rank #4
- FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
- SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
- DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
- DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
- Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
Password cracking is separate from post-quantum cryptography
NIST finalized its first three post-quantum cryptography standards on August 13, 2024 and encouraged administrators to begin integrating them. Those standards address encryption and digital signatures; they do not validate password-cracking table estimates and do not change the distinction between offline hash guessing and public-key cryptography. NIST’s announcement [c005]
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

