100% Client-Side Privacy

Password Leak & Breach Checker

Check if your password has appeared in historical data breaches and credential leaks. Powered by mathematical k-anonymity SHA-1 hashing, your plain-text password is never sent over the network or stored on any server.

k-Anonymity Mathematical Privacy Zero Plaintext Transmission Real-Time Entropy & Crack Time
Mathematical Privacy Guaranteed: Your browser hashes the password locally via Web Crypto API. Only the first 5 characters of the SHA-1 hash leave your device. The plain text password is never stored, sent, or seen by anyone.
0 characters
12+ Characters
Uppercase Letter
Lowercase Letter
Number (0-9)
Special Symbol (!@#$)
Client-Side SHA-1 Hash (k-Anonymity)
---
Prefix sent to API: None | Suffix matched locally: None
Estimated Brute-Force Crack Time
---
Entropy: 0 bits | Character Pool: 0

The Mathematics of k-Anonymity: How Zero-Knowledge Password Auditing Works

Auditing passwords against compromised databases presents a classic privacy paradox: how can an online service verify whether a user's password appears in a list of billions of leaked credentials without learning what the password is? Sending the plain-text password to a server exposes it to eavesdropping, rogue log files, and man-in-the-middle attacks.

In 2017, security researcher Troy Hunt and Cloudflare revolutionized credential auditing by deploying the mathematical principle of k-Anonymity:

  1. Local Cryptographic Hashing: When you enter a password into this tool, your device computes its 160-bit SHA-1 digest entirely inside your web browser using the native browser crypto.subtle.digest API. For example, the password password123 hashes to CBFDAC6008F9CAB4083784CBD1874F76618D2A97.
  2. Prefix Splitting: The 40-character hexadecimal hash is divided into two distinct components:
    • 5-character Prefix: CBFDA
    • 35-character Suffix: C6008F9CAB4083784CBD1874F76618D2A97
  3. Anonymized Query: The browser transmits only the 5-character prefix (CBFDA) to the secure Cloudflare-backed API endpoint.
  4. Bucket Response: The database returns a list of all hash suffixes that begin with CBFDA, along with their respective breach frequencies (often 500 to 1,500 candidate suffixes).
  5. Local Memory Match: The browser parses the returned suffix bucket and checks if your 35-character suffix is present. If it matches, the tool informs you exactly how many times it was leaked. The API server learns only that someone queried a 5-character prefix, leaving your actual password mathematically indiscernible among hundreds of possibilities.
k-Anonymity Privacy Formula:
P(Identifying Password | Prefix = "CBFDA") = 1 / Total Hashes in Bucket ≈ 1 / 1,000

The query yields an ambiguity set of size k ≥ 500. It is mathematically impossible for any intermediary or API host to reconstruct your password from a 5-character hash snippet.

What Is Credential Stuffing and Why Breached Passwords Are Dangerous

When major corporate platforms (such as LinkedIn, Adobe, Yahoo, or Canva) suffer data breaches, malicious actors compile the leaked credentials into massive wordlists such as RockYou and Compilation of Many Breaches (COMB). Automated botnets then execute credential stuffing attacks:

Password Entropy Explained: How Crack Time Is Estimated

Information entropy, formulated by Claude Shannon, measures the fundamental unpredictability or randomness of an information string in bits. The entropy $E$ of a password is given by the formula:

E = L × log2(R)

Where:
L = Length of the password (number of characters)
R = Size of the character pool based on diversity:
 • Lowercase letters only: R = 26 (4.7 bits/char)
 • Mixed Case (a-z, A-Z): R = 52 (5.7 bits/char)
 • Letters + Digits (a-z, A-Z, 0-9): R = 62 (5.95 bits/char)
 • Letters + Digits + Symbols: R = 94 (6.55 bits/char)

A standard 8-character password using only lowercase letters has an entropy of just $8 \times 4.7 = 37.6$ bits. Modern consumer GPU rigs (such as an NVIDIA RTX 4090 executing over 100 billion NTLM/MD5 hashes per second) can crack a 37-bit password in less than 3 seconds. Conversely, a 16-character passphrase has an entropy exceeding 104 bits, requiring billions of years of distributed computational power to crack.

Frequently Asked Questions

Is it safe to type my password into this online tool?
Yes, 100%. Your plain-text password is never sent across the internet, logged, or stored on any server. This tool implements the industry-standard k-Anonymity model: your browser hashes the password locally using the Web Crypto API (SHA-1). Only the first 5 hexadecimal characters of the hash are transmitted to query known breach ranges. The remaining 35 characters of the hash are compared strictly inside your device's memory.
How does k-Anonymity protect my password privacy?
Under k-anonymity, a 40-character SHA-1 hash (e.g. 21BD1...) is split into a 5-character prefix ('21BD1') and a 35-character suffix. When querying the breach database, only the 5-character prefix is sent. The database responds with hundreds of candidate suffixes matching that prefix. Your browser then checks locally if your full hash suffix is in that list. The API server has no way of knowing which of the hundreds of returned passwords belongs to you.
What should I do if my password was found in a data breach?
If your password was found in a breach, change it immediately on every website and service where you have used it. Automated cybercriminals execute 'credential stuffing' attacks using breached password lists to compromise user accounts across thousands of web platforms. Always create a unique, complex passphrase and enable Two-Factor Authentication (2FA).
How is password entropy and crack time calculated?
Password entropy measures informational unpredictability in bits using the formula E = L × log2(R), where L is character length and R is the size of the character pool (lowercase, uppercase, numbers, symbols). Crack time estimates how long a brute-force GPU rig executing billions of guesses per second would require to exhaust the search space.
What makes a truly strong, unbreachable password?
A strong password has at least 16 characters, combines random words or mixed character sets (lowercase, uppercase, digits, symbols), is completely unique to a single account, and has never been compromised in any public data breach. Using a dedicated password manager like Bitwarden or 1Password is the most reliable way to generate and maintain strong passwords.
Does this tool work if I am offline?
The local password strength audit, entropy calculation, character composition meter, and crack time estimator operate 100% offline inside your browser without any network connection. Querying the live global breach database requires an active internet connection to download the 5-character k-anonymity hash bucket.
Copied to clipboard!