Can AI Crack 51% of Passwords in Under a Minute? What PassGAN Really Shows

Can AI really crack 51% of passwords in under a minute? Explore what the PassGAN benchmark measured, where its claims fall short, and why account security is more nuanced.

A headline claiming that artificial intelligence can crack half of all passwords in seconds makes account security sound hopeless. It also leaves out the details that matter most: Which passwords? Tested how? Against what defenses?

Home Security Heroes, now redirecting readers to Security Hero, reported that the AI-based password-guessing tool PassGAN could crack 51% of common passwords in less than a minute. That is a publisher-reported benchmark—not evidence that attackers can compromise 51% of today’s online accounts in that time.

The useful lesson is not that AI has defeated cryptography. It is that predictable, reused passwords remain dangerous. Understanding what the benchmark measures helps you choose protections that address the actual risks.

What Did the PassGAN Study Actually Report?

The publisher’s study page reported the following results for common passwords:

  • Less than one minute: 51% cracked.
  • Less than one hour: 65% cracked.
  • Less than one day: 71% cracked.
  • Less than one month: 81% cracked.

Its methodology describes a RockYou-derived dataset of 15,680,000 passwords used for training and testing, excluding passwords shorter than four or longer than 18 characters. It calls the timing metric “estimated prediction time.”

Those qualifications matter. A collection of previously leaked passwords is not a representative sample of every password used today. Excluding longer passwords also limits what the results can establish about long, randomly generated credentials.

The published methodology does not provide hardware specifications, a password-hashing configuration, a reproducible timing procedure, or a clear explanation of training/test separation. Without those details, readers cannot independently validate the timing claim or confidently apply it to their accounts. The page’s title mentioning 2026, while its findings remain labeled 2023, does not establish a fresh benchmark.

A percentage and a stopwatch are not enough to measure account security. The dataset, attack conditions, and authentication defenses determine what the result means.

What Is PassGAN—and What Does AI Actually Do?

PassGAN uses a generative adversarial network, or GAN, to learn patterns in leaked passwords and generate likely guesses. The original research was first submitted in September 2017; PassGAN was not a new invention in 2023.

Traditional guessing tools use dictionaries and transformation rules. PassGAN learns patterns from examples, potentially producing useful guesses that complement conventional methods. But each candidate still needs to be tested against the target. AI improves guessing; it does not bypass cryptography.

There is also a separate statistic to distinguish: the research paper reported matching 51%–73% more passwords when combining PassGAN and HashCat output than with HashCat alone. That relative improvement is not the same as cracking 51% of passwords within one minute.

Why a Cracked Password Is Not Necessarily a Compromised Account

Different attacks encounter different defenses. Treating them as interchangeable makes the headline more frightening—and less useful.

Offline cracking

If attackers steal password hashes, they can test guesses on their own computers without a website’s login rate limits. Speed depends on hardware, the hashing algorithm, and its configured cost. As OWASP explains, purpose-built password hashing makes each guess more expensive.

Online guessing

Attackers submitting guesses to a live login page face rate limits, monitoring, and potentially multifactor authentication. Finding the correct password may still leave them unable to complete authentication. Offline estimates cannot simply be translated into online account-takeover times.

Credential stuffing

Sometimes no cracking is necessary. Attackers try credentials stolen from one service against another. For example, reusing a shopping-site password for email can turn an unrelated breach into an email-account threat. Password uniqueness directly addresses this risk.

Phishing and malware

A convincing fake login page can capture a long password. Malware can steal credentials or sessions. Password strength protects against guessing, not every route into an account.

What You Should Do Now

1. Secure your email and other high-impact accounts first

Your primary email often controls password resets elsewhere. Protect it before working through less consequential accounts, then prioritize your password manager, financial accounts, and administrative access. Check recovery addresses and phone numbers as well as the login method.

2. Generate a different random password for every account

For accounts that still require passwords, use a password manager to generate and store independent passwords. Aim for at least 15 characters, and longer where practical. Avoid variations built from the same word, season, company name, or predictable suffix.

If you must memorize a password, use a long passphrase made from independently selected words rather than a familiar quotation. Length helps, but predictable construction still matters. Never copy a published example into a real account.

NIST recommends password managers and choosing one that supports MFA. The tradeoff is concentration: the manager becomes an especially important account. Protect its login, secure recovery information, and understand how you will regain access after losing a device.

3. Prefer passkeys where available

Passkeys replace shared passwords with cryptographic credentials tied to the legitimate service. They resist phishing because a look-alike website cannot use the credential intended for the real site. A device PIN or biometric can authorize their use.

  • Synced passkeys offer convenient access across supported devices, but require understanding the provider’s account security and recovery process.
  • Device-bound passkeys remain on a particular device or security key, making a backup authenticator especially important.

Before replacing a phone or removing an older login method, confirm backup access. As the FIDO Alliance’s deployment guidance emphasizes, recovery planning belongs alongside enrollment.

4. Add MFA wherever passwords remain

CISA recommends moving toward phishing-resistant MFA, such as appropriately configured FIDO authentication. Authenticator-app codes still add protection, but manually entered codes can be relayed through a phishing site. All MFA methods are not equivalent.

5. Replace exposed passwords—not just aging ones

Change passwords when they are weak, reused, exposed, or associated with suspicious activity. Routine changes that merely replace one predictable suffix with another do little to address the underlying problem.

What Businesses and Website Owners Should Change

User education cannot compensate for weak authentication design. The final NIST SP 800-63B-4 guidance, published July 31, 2025, provides a stronger baseline for systems within its scope:

  • Require at least 15 characters for password-only authentication. Passwords used as part of MFA may have an eight-character minimum.
  • Permit a maximum password length of at least 64 characters.
  • Screen new passwords against common and compromised values.
  • Do not impose mandatory character-mixture rules or routine periodic password changes; require changes when there is evidence of compromise.

These are system requirements, not guarantees that every password meeting a length threshold is safe.

Protect stored credentials. OWASP recommends purpose-built password hashing, including Argon2id with a minimum configuration of 19 MiB memory, two iterations, and parallelism of one. Use unique salts and benchmark stronger settings against operational capacity. Higher costs impede attackers but also consume legitimate server resources.

Defend authentication and recovery together. Combine rate limiting, MFA, suspicious-login detection, and session controls. Do not rely solely on IP blocking against distributed attacks. Give users visibility into active sessions and a way to revoke them. Recovery procedures must not become an easy route around stronger login protections.

If You Suspect an Account Is Already Compromised

Do not wait to establish whether AI was involved. From a trusted device, follow the provider’s official recovery process. The FTC recommends changing the password, signing out other sessions, strengthening authentication, and checking recovery information. For email, remove forwarding rules you did not create.

Check potentially affected devices for malware, and replace the exposed password anywhere else it was reused. Changing one account does not invalidate the same credential on another service.

Your Account-Security Checklist

  • Secure your primary email account first.
  • Replace reused passwords with independently generated ones.
  • Use long passwords and protect your password manager with MFA.
  • Enable passkeys or phishing-resistant MFA where supported.
  • Arrange backup access before changing devices.
  • Review recovery settings and unfamiliar sessions.
  • Act on compromise alerts rather than waiting for a scheduled password change.

The Bottom Line: Address the Risk, Not Just the Headline

PassGAN illustrates how machine learning can improve password guessing. It does not establish that half of all accounts are instantly accessible or that cryptography has become obsolete.

Start with your primary email today: eliminate password reuse, enable a passkey or strong MFA, and verify recovery access. Then extend those protections to your other important accounts. That layered approach addresses AI-assisted guessing—and the attacks that never need to guess a password at all.

Browse all insights · Contact Bart McDonough