RC4 Encrypt
Encrypt text with RC4. Legacy compatibility only.
Encrypt text with RC4 in your browser. Legacy compatibility only - RC4 is broken. Free, offline, runs entirely client-side. Read more Show less
What is RC4?
RC4 (Rivest Cipher 4) is a stream cipher designed by Ron Rivest in 1987. It was the workhorse of the early web: WEP, WPA (before TKIP), SSL/TLS (before TLS 1.2), Microsoft RDP, and Adobe PDF all used it. It is extremely fast and trivial to implement.
RC4 is broken. Practical attacks exist against TLS, WPA, and RC4 in general. It was deprecated by RFC 7465 in 2015 and banned from TLS 1.3. This tool exists only for users who need to work with legacy data. Never use RC4 for new systems; use ChaCha20-Poly1305 or AES-GCM.
How to use
RC4 is symmetric: encrypt and decrypt use the exact same operation. This page produces ciphertext from plaintext. To go the other direction, use RC4 Decrypt - it runs the same algorithm with the same key.
The key
RC4 accepts keys of 1 to 256 bytes. In practice, 16 bytes (128 bits) is the minimum and 32 bytes (256 bits) is common. The key is used directly, not hashed. A short or predictable key is trivially broken.
Because RC4 has no IV or nonce, using the same key to encrypt two different messages leaks information about both. Do not reuse keys.
FAQ
Why is RC4 still available if it is broken?
Legacy data. Some old databases, network captures, and encrypted files use RC4. If you need to inspect or migrate one of them, an RC4 implementation is required. This tool provides one without a Python or OpenSSL install.
What is the "RC4 bias" I keep hearing about?
The first few bytes of the RC4 keystream are not uniformly distributed. Attackers can exploit this to recover plaintext from many captured messages. Modern implementations discard the first 256-1024 bytes (called "RC4-drop") to mitigate this, but the fundamental problem remains.
Is RC4 fast?
Extremely fast. It runs at several hundred megabytes per second in pure software. That speed was its appeal in the 1990s. Modern ciphers like ChaCha20 are comparably fast and secure.
RC4 vs RC4-drop?
RC4-drop discards the first N bytes of the keystream before using the rest. It mitigates the bias issue but does not fix the underlying cryptanalysis. This tool implements standard RC4 without dropping.
Can I break RC4 ciphertext with this tool?
Not directly. RC4 is a cipher; without the key, decryption produces garbage. Cryptanalysis of RC4 uses statistical techniques over many ciphertexts and is beyond the scope of a browser tool.
Command line equivalent
# OpenSSL (RC4 support removed in OpenSSL 3.x by default)
# OpenSSL 1.1.1:
echo -n "hello" | openssl rc4 -K 00112233445566778899aabbccddeeff -nosalt -base64
# Python
python3 -c '
from Crypto.Cipher import ARC4
key = bytes.fromhex("00112233445566778899aabbccddeeff")
c = ARC4.new(key)
ct = c.encrypt(b"hello")
import base64
print(base64.b64encode(ct).decode())
'
# Node with rc4 npm package
npm i rc4
node -e 'const RC4 = require("rc4"); const c = new RC4("mykey"); console.log(c.update("hello"))'