# bcrypt

URL: https://softwaredictionary.org/terms/bcrypt
Category: Security
Last updated: 2026-10-06
Pronunciation: BEE-kript

In short: bcrypt is a password-hashing function that adds a random salt and is deliberately slow, so stolen password hashes are very expensive to crack by guessing.

## What is bcrypt?

bcrypt is a hash function designed for storing passwords, published by Niels Provos and David Mazières in 1999 and based on the Blowfish cipher. For every password it generates a random 128-bit salt and returns one 60-character string, starting with something like `$2b$12$` and followed by the salt and the hash, which records the version, the cost factor, the salt and the result together. It is the default algorithm behind PHP's `password_hash` and is available in nearly every language.

Ordinary hashes such as SHA-256 are built to be fast, so an attacker with a stolen database and a GPU can test billions of password guesses per second. bcrypt is slow on purpose: its cost factor sets how much work each hash takes, and every increase of 1 doubles it, so a login takes a fraction of a second while millions of guesses become very expensive. It is like a lock that takes a second to turn, no problem for the owner but crippling for a burglar trying thousands of keys. The random salt also makes identical passwords hash differently, so precomputed tables are useless and each account must be attacked separately.

In practice, you call the library's hash function at sign-up and its compare function at login, which reads the salt and cost from the stored string; as hardware gets faster, you raise the cost and re-hash each password at its owner's next login. OWASP recommends a cost of at least 10, and because bcrypt uses only the first 72 bytes of a password, some libraries reject longer input. Argon2id, the winner of the 2015 Password Hashing Competition, is now the usual recommendation for new systems because it is also memory-hard, which makes attacks with GPUs and custom hardware costlier. bcrypt remains widely used and is still considered acceptable.

bcrypt is often confused with general-purpose hashing and with encryption. SHA-256 and MD5 are fast hashes for checksums and signatures and should never be used on their own to store passwords, even with a salt. Encryption can be reversed with a key, while a bcrypt hash can't be turned back into the password; it can only be checked by hashing a guess the same way.

## Key takeaways

- bcrypt is a slow, salted hash designed for storing passwords.
- Its cost factor doubles the work with each step and can be raised over time.
- The version, cost, salt and hash are stored together in one 60-character string.
- Only the first 72 bytes of a password are used.
- Argon2id is the newer recommendation; bcrypt remains acceptable with a cost of at least 10.

## Example: Hashing and checking a password with bcrypt (Python)

```python
import bcrypt

password = "correct horse battery staple".encode()

# At sign-up: the random salt and the cost are stored inside the result
hashed = bcrypt.hashpw(password, bcrypt.gensalt(rounds=12))
print(hashed)  # b'$2b$12$...' (60 characters: version, cost, salt, hash)

# At login: re-hashes the attempt with the stored salt and cost, then compares
print(bcrypt.checkpw(password, hashed))        # True
print(bcrypt.checkpw(b"wrong guess", hashed))  # False
```

## Frequently asked questions

**Is bcrypt still secure?**

Yes. With a cost factor of at least 10 it is still considered acceptable and protects millions of accounts. For new systems, Argon2id is generally recommended because each guess also needs a large amount of memory, which slows down attacks on GPUs.

**What is the difference between bcrypt and SHA-256?**

SHA-256 is a fast, general-purpose hash for checksums, signatures and data integrity. bcrypt is a deliberately slow password hash with a built-in salt, so attackers can test far fewer guesses per second against stolen hashes.

**Can a bcrypt hash be decrypted?**

No. bcrypt is one-way. To check a login, the library hashes the entered password again with the salt and cost stored in the hash and compares the two results.

## Sources

- [Provos and Mazières: A Future-Adaptable Password Scheme (1999)](https://www.usenix.org/legacy/event/usenix99/provos/provos_html/)
- [OWASP Cheat Sheet: Password Storage](https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html)

---

Software Dictionary: https://softwaredictionary.org/ · https://softwaredictionary.org/llms.txt
