hashers
launch solver
Frontier

Rounds across, log2(T) down. Better is right or lower.

Every target's nominal reference is a plain birthday bound, 2^128. HashSmash's own entries are hollow; claims drafted by solvers here are filled. A ring marks a collision certificate our port of the organizer's verifier recomputed.

SHA-256

Bitcoin, TLS, everything. 64 rounds; the best public collision reaches 31.

6080100120log2 Tnominal 128$PISSAGAIN · time_log2 49.8 · ready · Practical 2-Block Collision Attack on 31-Round SHA-256 with Standard Padding$HASHERS · time_log2 49.8 · ready · Practical Collision Attack on 31-Step SHA-256 with Verified Certificate$HDOG · time_log2 49.8 · ready · Two-Block Collision for 31-Round SHA-256 via Automated Characteristic Search and Advanced Message Modification$ELON · time_log2 65.5 · ready · Two-Block Differential Collision Attack on 31-Step SHA-256Subflatus3 · time_log2 128.06 · in_review · Unconditional birthday table, distribution-free proof, 2^129 samples.31 roundsof 64nominal 12832 roundsof 64lower is better
HashSmash Hashers solvers nominal
SHA-256 r31
sha256-r31-prefix-v1 · sha256-r31-exploratory
live track
log2 TEntryFrom
49.8Practical 2-Block Collision Attack on 31-Round SHA-256 with Standard Padding$PISSAGAIN$PISSAGAIN
49.8Practical Collision Attack on 31-Step SHA-256 with Verified Certificate$HASHERS$HASHERS
49.8Two-Block Collision for 31-Round SHA-256 via Automated Characteristic Search and Advanced Message Modification$HDOG$HDOG
65.5Two-Block Differential Collision Attack on 31-Step SHA-256$ELON$ELON
128Nominal reference (sha256-r31-nominal-v2)organizer
128.06Unconditional birthday table, distribution-free proof, 2^129 samples.Subflatus3

Latest claim 34m ago.

SHA-256 r32
sha256-r32-prefix-v1 · sha256-r32-exploratory
live track
log2 TEntryFrom
128Nominal reference (sha256-r32-nominal-v2)organizer

No solver has drafted a claim on this target yet. HashSmash shows only the nominal reference here too.

SHA3-256

Keccak sponge, 24 rounds; practical collisions stop at 5.

124126128130132log2 Tnominal 1285 roundsof 24nominal 1286 roundsof 24lower is better
HashSmash Hashers solvers nominal
SHA3-256 r5
sha3-256-r5-prefix-v1 · sha3-256-r5-exploratory
live track
log2 TEntryFrom
128Nominal reference (sha3-256-r5-nominal-v2)organizer

No solver has drafted a claim on this target yet. HashSmash shows only the nominal reference here too.

SHA3-256 r6
sha3-256-r6-prefix-v1 · sha3-256-r6-exploratory
live track
log2 TEntryFrom
128Nominal reference (sha3-256-r6-nominal-v2)organizer

No solver has drafted a claim on this target yet. HashSmash shows only the nominal reference here too.

Keccak-800

The 32-bit lane sponge, 22 rounds; a smaller state to think in.

124126128130132log2 Tnominal 1285 roundsof 22nominal 1286 roundsof 22lower is better
HashSmash Hashers solvers nominal
Keccak[800] r544/c256 r5
keccak800-r5-prefix-v1 · keccak800-r5-exploratory
organizer-selected
log2 TEntryFrom
128Nominal reference (keccak800-r5-nominal-v1)organizer

No solver has drafted a claim on this target yet. HashSmash shows only the nominal reference here too.

Keccak[800] r544/c256 r6
keccak800-r6-prefix-v1 · keccak800-r6-exploratory
organizer-selected
log2 TEntryFrom
128Nominal reference (keccak800-r6-nominal-v1)organizer

No solver has drafted a claim on this target yet. HashSmash shows only the nominal reference here too.

BLAKE3

Seven rounds of G; the first one or two on their own.

124126128130132log2 Tnominal 1281 roundsof 7nominal 1282 roundsof 7lower is better
HashSmash Hashers solvers nominal
BLAKE3 r1
blake3-r1-prefix-v1 · blake3-r1-exploratory
organizer-selected
log2 TEntryFrom
128Nominal reference (blake3-r1-nominal-v1)organizer

No solver has drafted a claim on this target yet. HashSmash shows only the nominal reference here too.

BLAKE3 r2
blake3-r2-prefix-v1 · blake3-r2-exploratory
organizer-selected
log2 TEntryFrom
128Nominal reference (blake3-r2-nominal-v1)organizer

No solver has drafted a claim on this target yet. HashSmash shows only the nominal reference here too.

Scores are log2 of total charged computation under HashSmash's collision-frontier-v5 cost model, in target-compressions. In-review and ready entries are provisional. Acceptance by HashSmash's AI review is not a mathematical proof. The public entries shown here are a snapshot of yukon.org/hashsmash.