RIPEMD-160
The hash inside every Bitcoin and Ethereum address. Cryptographically strong-ish, but mostly here because Satoshi picked it.
By Deepak Gupta ·
RIPEMD-160 is a 160-bit hash from a European academic team, designed in the mid-1990s as an alternative to MD5 and SHA-1. It would have remained an obscure footnote if Satoshi Nakamoto hadn't chosen it as the second hash in Bitcoin's address derivation (`RIPEMD160(SHA256(pubkey))`). Today every Bitcoin and Ethereum address depends on its collision resistance. There's no known practical attack (the best public result is on the closely related RIPEMD-128), but the algorithm is also not actively analyzed, which makes it an awkward dependency for the world's biggest cryptocurrencies. Pick RIPEMD-160 only when you're interoperating with cryptocurrency tooling.
Recommended uses
- ·Bitcoin / Ethereum address derivation and interop
Known attacks / caveats
- ·Theoretical preimage attacks on reduced rounds (Mendel et al., 2011)
Designed by
Dobbertin, Bosselaers, Preneel (KU Leuven), published 1996.
Frequently asked questions
- Is RIPEMD-160 secure in 2026?
- Not for new designs. RIPEMD-160 is deprecated rather than broken, which means it still resists the attacks it was built for but is no longer the right default. Theoretical preimage attacks on reduced rounds (Mendel et al., 2011).
- What is RIPEMD-160 used for?
- Bitcoin / Ethereum address derivation and interop.
- How long is the output of RIPEMD-160?
- 160 bits, which is 20 bytes, or 40 characters when written as hexadecimal. The length is fixed regardless of how large the input is.
- Can RIPEMD-160 be used to hash passwords?
- No, and this is the most consequential mistake people make with it. RIPEMD-160 is a fast general-purpose hash, and fast is exactly the wrong property for passwords: it lets an attacker with a stolen database test billions of guesses. Use a purpose-built password hashing function such as Argon2id instead.
- Who created RIPEMD-160?
- Dobbertin, Bosselaers, Preneel (KU Leuven), published in 1996.