Whirlpool
Compute the Whirlpool (512-bit) cryptographic hash of any input.
Calculate Whirlpool (ISO/IEC 10118-3) hashes of any input. 512-bit AES-derived hash. Free, offline, runs client-side. Read more Show less
What is Whirlpool?
Whirlpool is a cryptographic hash function designed by Paulo Barreto and Vincent Rijmen in 2000. It produces a 512-bit (64-byte) digest, shown as 128 hexadecimal characters. It was one of the five finalists in the NESSIE project (the European equivalent of the NIST SHA-3 competition) and is standardized in ISO/IEC 10118-3.
Whirlpool was named after the Whirlpool galaxy and is based on a modified version of the AES block cipher as its compression primitive. It runs on 512-bit state and processes 512-bit message blocks.
It is not widely deployed today, but it appears in a few legacy systems: older PGP keys, some TrueCrypt volumes, and a handful of enterprise products that chose it before SHA-2 was standard. It is included here for completeness and legacy compatibility.
How to compute Whirlpool
Type or paste your input. Choose the input encoding (UTF-8, hex, or Base64). For example, the UTF-8 string abc produces:
4e2448a4c6f486bb16b6562c73b4020bf3043e3a731bce721ae1b303d97e6d4c7181eebdb6c57e277d0e34957114cbd6c797fc9d95d8b582d225292076d4eef5
Design
Whirlpool uses a Miyaguchi-Preneel construction around a 512-bit block cipher derived from AES. The block cipher is applied 10 times per message block. The internal S-boxes are constructed from mini-boxes (E, E-inverse, R, and R-inverse), which gives the algorithm a compact and self-contained structure with no unexplained constants.
The result is a hash function that was designed with the same philosophy as AES: wide diffusion, simple structure, and resistance to known cryptanalysis at the time.
FAQ
Is Whirlpool secure?
No practical attack exists against the full Whirlpool. It is standardized in ISO/IEC 10118-3 and was accepted by NESSIE. Its main weakness is that it has been studied less thoroughly than SHA-2 or SHA-3.
Where is Whirlpool used?
Rarely today. It appears in a few legacy systems: older versions of TrueCrypt (before VeraCrypt), some PGP key formats, and a handful of enterprise products. For new systems, use SHA-256, SHA-3, or BLAKE3.
Why is the output 128 hex characters?
Whirlpool produces 64 bytes (512 bits). Each byte is two hex characters, so 64 x 2 = 128.
Whirlpool vs SHA-512
Both produce 512-bit output. SHA-512 is standardized by NIST, widely deployed, and much faster in software because modern CPUs have SHA-512 instructions. Whirlpool has no hardware acceleration on any mainstream CPU, so it runs 5-10x slower.
Is Whirlpool the same as Whirlpool-0 or Whirlpool-T?
No. Whirlpool had two early revisions (Whirlpool-0 and Whirlpool-T) before the final 2003 version. The current standard is the 2003 version, sometimes called Whirlpool-3. This tool implements the 2003 version, which is what modern libraries use.
Can I use Whirlpool for password hashing?
No. It is a fast hash and provides no protection against offline brute force. Use Argon2id or scrypt instead.
Command line equivalent
# Whirlpool is not in OpenSSL 3.x by default
# Python with pycryptodome
pip install pycryptodome
python3 -c 'from Crypto.Hash import whirlpool; print(whirlpool.new(b"abc").hexdigest())'
# Node with hash-wasm
npm i hash-wasm
node --input-type=module -e '
import { whirlpool } from "hash-wasm";
console.log(await whirlpool(new TextEncoder().encode("abc")));
'
# PHP
php -r 'echo hash("whirlpool", "abc");'
# Command line
# There is no universal CLI tool; most people use a scripting language.