Tooleux

Compute SHA-256 applied twice, as used by Bitcoin and other proof-of-work systems.

Runs in your browser. Nothing leaves your device.
Calculate Double SHA-256 (SHA-256d) hashes. The hash used by Bitcoin for blocks, transactions, and addresses. Free, offline, runs client-side. Read more Show less

What is Double SHA-256?

Double SHA-256 (also written SHA-256d or SHA256^2) is the result of applying SHA-256 twice: sha256(sha256(input)). It is used extensively in Bitcoin and other proof-of-work cryptocurrencies, where it appears in block header hashing, transaction IDs (txids), and address derivation.

It is not the same as SHA-512, SHA-384, or SHA-256 with a longer output. It is two sequential applications of the same 256-bit hash, producing a 256-bit result.

How to compute Double SHA-256

Type or paste your input. Choose the input encoding (UTF-8, hex, or Base64). For example, the UTF-8 string hello produces:

9595c9df90075148eb06860365df33584b75bff782a510c6cd4883a419833d50

Why double?

Satoshi Nakamoto chose double SHA-256 for Bitcoin in 2008, and the choice has stuck across the whole cryptocurrency ecosystem. The extra round was originally intended as protection against length-extension attacks on the Merkle-Damgard construction of SHA-256, though SHA-256's length encoding already handles most of that. Whatever the original reasoning, double SHA-256 is now a de facto standard for blockchain data and any tool that touches Bitcoin needs it.

Where Double SHA-256 is used

Bitcoin block headers - the hash of the 80-byte block header, which miners race to find, is double SHA-256.

Transaction IDs (txids) - the identifier of every Bitcoin transaction is the double SHA-256 of the serialized transaction.

Address generation - Bitcoin addresses start from a public key, apply SHA-256 then RIPEMD-160, and append a checksum computed with double SHA-256.

BIP32 and HD wallets - hierarchical deterministic wallets use HMAC-SHA512 with double-SHA256-derived keys.

Merkle trees - every internal node of a Bitcoin Merkle tree is the double SHA-256 of its children.

FAQ

Is Double SHA-256 more secure than single SHA-256?

Marginally, against length-extension attacks specifically. SHA-256 is already secure against all practical attacks, so double hashing provides no meaningful additional security for general use. It exists in Bitcoin for historical reasons and legacy compatibility.

How is this different from the SHA-256 tool's "double" option?

Functionally, it is the same computation. This page exists as a dedicated tool because "double sha256" and "sha256d" are common search terms in the Bitcoin developer community, and a dedicated page answers that query directly.

Does Bitcoin use SHA-256 or Double SHA-256?

Bitcoin uses Double SHA-256 for almost everything at the protocol level. Some ancillary uses (like HMAC in BIP32) use single SHA-256 or SHA-512 internally, but any hash that appears on-chain is Double SHA-256.

Can I reverse Double SHA-256?

No. Two applications of a one-way function are still one-way. There is no known attack that recovers the input from a Double SHA-256 hash.

What about Triple SHA-256?

Some systems use triple hashing as an extra paranoia measure (notably in Namecoin's merged mining and in some altcoins). It provides no additional security over double hashing in practice. This tool implements only the standard double variant.

Command line equivalent
# Bitcoin Core RPC (requires bitcoind)
bitcoin-cli getblockhash 0

# Python
python3 -c '
import hashlib
data = b"hello"
first = hashlib.sha256(data).digest()
second = hashlib.sha256(first).hexdigest()
print(second)
'

# Node
node -e '
const c = require("crypto");
const data = Buffer.from("hello");
const first = c.createHash("sha256").update(data).digest();
const second = c.createHash("sha256").update(first).digest("hex");
console.log(second);
'

# Command line
echo -n "hello" | openssl dgst -sha256 -binary | openssl dgst -sha256
Loads a test value into the form
Input
Double SHA-256