Skip to content
secureBLAKE · 512 bits · 2012

BLAKE2b

Faster than MD5, more secure than SHA-3. Quietly powers WireGuard, Argon2, libsodium, and most password managers' KDF inputs.

By ·

BLAKE2b is a 512-bit hash (variable-length output, up to 64 bytes) optimized for 64-bit platforms and designed to be *faster than MD5* while remaining cryptographically secure. It's the hash function inside Argon2's compression step, inside libsodium's `crypto_generichash`, inside WireGuard's noise protocol, and inside an enormous number of password managers. The Achilles heel is awareness: BLAKE2 is less famous than SHA-256 so it gets reached for less often, even when it would be the better choice. BLAKE3 (2020) is its successor and is faster again on modern multi-core CPUs, but BLAKE2b is still the practical default for embedded systems and single-threaded code paths.

Recommended uses

  • ·High-throughput hashing on 64-bit servers without SHA-NI
  • ·Generic-purpose keyed hash (built-in `key` parameter, no HMAC wrapper needed)
  • ·Generating salts, nonces, derivation chains in libsodium-style cryptography

Known attacks / caveats

  • ·None practical.

Designed by

Aumasson, Neves, Wilcox-O'Hearn, Winnerlein, published 2012.

Hash some text →Compare against other algorithms →

Frequently asked questions

Is BLAKE2b secure in 2026?
Yes. BLAKE2b has no practical breaks as of 2026, and no attack better than brute force is known against it.
What is BLAKE2b used for?
High-throughput hashing on 64-bit servers without SHA-NI. Generic-purpose keyed hash (built-in `key` parameter, no HMAC wrapper needed). Generating salts, nonces, derivation chains in libsodium-style cryptography.
How long is the output of BLAKE2b?
512 bits, which is 64 bytes, or 128 characters when written as hexadecimal. The length is fixed regardless of how large the input is.
Can BLAKE2b be used to hash passwords?
No, and this is the most consequential mistake people make with it. BLAKE2b is a fast general-purpose hash, and fast is exactly the wrong property for passwords: it lets an attacker with a stolen database test billions of guesses. Use a purpose-built password hashing function such as Argon2id instead.
Who created BLAKE2b?
Aumasson, Neves, Wilcox-O'Hearn, Winnerlein, published in 2012.