Guide

MD5 vs SHA-256: Which Hash Should You Use?

Published 26 August 2026

Both are called "hash functions" and both produce that familiar string of hex characters, so it's easy to reach for whichever one you've used before without thinking about why the choice matters. It matters more than it looks like it should — one of these is genuinely broken for security purposes, and the other one isn't.

What a hash function actually does

Feed it any input — a file, a password, a string — and it returns a fixed-size output that acts as a fingerprint of that input. The same input always produces the same output. Change even one byte of the input and the output changes completely and unpredictably. And critically, it only runs one way: you can't reverse a hash back into the original input, only compare a new hash against a known one to check whether the underlying data matches.

MD5: fast, ubiquitous, and cryptographically broken

MD5 produces a 128-bit hash and was the default choice for decades — it's fast, and support for it is everywhere. The problem is that it's cryptographically broken: researchers can deliberately construct two different inputs that produce the exact same MD5 hash, a real and practical attack, not a theoretical one. That makes MD5 unsafe for anything where a motivated adversary might benefit from forging a match — digital signatures, certificate validation, or verifying that a download hasn't been tampered with by someone who wants it to look legitimate.

It's worth being precise about what "broken" means here, though: MD5 is broken against a deliberate attacker trying to craft a collision. It's still perfectly fine for catching accidental corruption — confirming a file transferred over a flaky connection came through byte-for-byte intact. Nobody is attacking your download; the risk there is a dropped packet, not an adversary.

SHA-256: the standard for anything security-sensitive

SHA-256 produces a 256-bit hash and belongs to the SHA-2 family. No practical collision attack against it is currently known, which is exactly why it's the standard behind TLS certificates, code-signing, blockchain, and verifying software downloads against a checksum the publisher wants you to actually trust. Where MD5 protects against accidents, SHA-256 protects against an adversary too.

The one thing neither of them should be used for

Storing passwords. Neither MD5 nor plain SHA-256 is designed for that job — both are built to be fast, which is exactly the wrong property for password storage, since it makes brute-forcing every possible password dramatically cheaper for an attacker who steals the hash database. Password storage needs a deliberately slow, salted algorithm — bcrypt, Argon2, or PBKDF2 — that's a genuinely different tool for a genuinely different job, not a stronger version of the same one.

The practical rule

Use SHA-256 (or better) for anything where the integrity check matters against a real adversary — verifying a download, signing something, checksumming data you need to trust. MD5 is still fine for quick, low-stakes integrity checks — deduplicating files, confirming a routine transfer wasn't corrupted — where speed matters more than resistance to a deliberate forger. When in doubt, SHA-256 costs you almost nothing extra and closes the door on the attack MD5 is actually vulnerable to.

Our Hash Generator computes MD5, SHA-1, SHA-256, and SHA-512 for any text or file instantly in your browser.

Try the tools mentioned here