secureSHA-3 · 512 bits · 2015
SHA3-512
The 512-bit member of the SHA-3 family. Same sponge construction, more capacity, slower throughput.
By Deepak Gupta ·
SHA3-512 is the 512-bit variant of the Keccak-derived SHA-3 family. Capacity is doubled (which boosts the security margin against generic attacks) but throughput drops correspondingly. It's the right choice when an enterprise policy mandates a SHA-3 family hash *and* the larger 256-bit security level; otherwise SHA3-256 is the more common pick.
Recommended uses
- ·Compliance scenarios requiring SHA-3 family + 256-bit security
Known attacks / caveats
- ·None practical.
Designed by
Bertoni, Daemen, Peeters, Van Assche (Keccak team), published 2015.
Frequently asked questions
- Is SHA3-512 secure in 2026?
- Yes. SHA3-512 has no practical breaks as of 2026, and no attack better than brute force is known against it.
- What is SHA3-512 used for?
- Compliance scenarios requiring SHA-3 family + 256-bit security.
- How long is the output of SHA3-512?
- 512 bits, which is 64 bytes, or 128 characters when written as hexadecimal. The length is fixed regardless of how large the input is.
- Can SHA3-512 be used to hash passwords?
- No, and this is the most consequential mistake people make with it. SHA3-512 is a fast general-purpose hash, and fast is exactly the wrong property for passwords: it lets an attacker with a stolen database test billions of guesses. Use a purpose-built password hashing function such as Argon2id instead.
- Who created SHA3-512?
- Bertoni, Daemen, Peeters, Van Assche (Keccak team), published in 2015.