SHA-256
The default cryptographic hash for the modern web. TLS certificates, Bitcoin, GitHub's new object IDs: all SHA-256 underneath.
By Deepak Gupta ·
SHA-256 is one member of the SHA-2 family designed by the NSA and standardized by NIST in 2001. It's the default cryptographic hash for new systems: TLS certificate signatures, the Bitcoin proof-of-work hash, JWT's HS256 / RS256 signing, AWS Signature V4, Git's next-generation content addressing. Anywhere you'd reach for a hash today and don't have a reason to pick something else, the right answer is usually SHA-256. It produces a 256-bit (32-byte) digest and is implemented natively in every CPU shipped in the last decade via the Intel SHA-NI / ARMv8 cryptography extensions, so its real-world throughput is excellent. There are no known practical attacks against SHA-256; the closest theoretical result is a length-extension attack which is mitigated by using HMAC-SHA256 (or by switching to SHA-3 / BLAKE3 which are immune by construction).
Recommended uses
- ·Default cryptographic hash for new designs
- ·File integrity checksums shared publicly
- ·HMAC-SHA256 for API request signing
- ·Building blocks for Merkle trees (Bitcoin, Git, ZK proofs)
Known attacks / caveats
- ·Length-extension attack on the bare construction; use HMAC-SHA256 if you need MAC semantics
Designed by
NSA, published 2001.
Frequently asked questions
- Is SHA-256 secure in 2026?
- Yes. SHA-256 has no practical breaks as of 2026. Caveats worth knowing: Length-extension attack on the bare construction; use HMAC-SHA256 if you need MAC semantics.
- What is SHA-256 used for?
- Default cryptographic hash for new designs. File integrity checksums shared publicly. HMAC-SHA256 for API request signing. Building blocks for Merkle trees (Bitcoin, Git, ZK proofs).
- How long is the output of SHA-256?
- 256 bits, which is 32 bytes, or 64 characters when written as hexadecimal. The length is fixed regardless of how large the input is.
- Can SHA-256 be used to hash passwords?
- No, and this is the most consequential mistake people make with it. SHA-256 is a fast general-purpose hash, and fast is exactly the wrong property for passwords: it lets an attacker with a stolen database test billions of guesses. Use a purpose-built password hashing function such as Argon2id instead.
- Who created SHA-256?
- NSA, published in 2001.