XXTEA Encrypt
Encrypt text with XXTEA using a password.
Encrypt text with XXTEA (Corrected Block TEA) in your browser. Variable-length blocks, PBKDF2 key derivation. Free, offline, runs client-side. Read more Show less
What is XXTEA?
XXTEA (Corrected Block TEA) is a block cipher published by David Wheeler and Roger Needham in 1998. It is a correction to the earlier Block TEA algorithm, which had a serious weakness. XXTEA works on variable-length blocks - not just the fixed 64-bit or 128-bit blocks of AES or SPECK - which makes it unusually flexible for encrypting messages of arbitrary length.
XXTEA is used in some embedded systems, in certain Chinese enterprise applications, and in a handful of messaging protocols. It is a legacy cipher: it has no known practical attack on the full algorithm, but it has received far less third-party analysis than AES.
A note on trust
This tool is included for interoperability with systems that specify XXTEA. For new encryption work, use AES-GCM or ChaCha20-Poly1305. Those are authenticated (they detect tampering), standardized by NIST and IETF, and have had decades of public cryptanalysis.
How to use
Enter your plaintext, enter a password, and press Encrypt. The output is a single Base64 string containing the random salt and the ciphertext. Copy it and paste into XXTEA Decrypt with the same password.
The password is used to derive a 128-bit XXTEA key via PBKDF2-SHA-256 with 100,000 iterations.
Variable-length blocks
Unlike AES, which always encrypts exactly 16 bytes at a time, XXTEA operates on a message of any length. The algorithm internally uses the message length as part of the encryption, so the length is preserved on decryption without any external padding scheme.
The minimum message is 8 bytes (2 words). This tool handles shorter inputs automatically.
FAQ
Is XXTEA secure?
No known practical attack exists against the full XXTEA. But it has been analyzed much less thoroughly than AES or ChaCha20. Some cryptographers prefer to avoid it on principle. Use it only where a specific system requires it.
Why is it called "Corrected" Block TEA?
The original Block TEA had a weakness where an attacker could flip bits in one block and predict the change in another. XXTEA fixed this by mixing the data differently. The name "Corrected" is part of the formal name.
XXTEA vs TEA vs XTEA
All three are from Wheeler and Needham. TEA (1994) is the original, with a 64-bit block. XTEA (1997) is a slight improvement with better key schedule. XXTEA (1998) is the variable-length version, structurally different from the other two.
Is XXTEA authenticated?
No. XXTEA provides confidentiality only. An attacker who can modify the ciphertext may be able to cause predictable changes to the plaintext. For authenticated encryption, use AES-GCM or ChaCha20-Poly1305.
Can I decrypt data from another XXTEA implementation?
Only if that implementation uses the same byte order and key derivation. XXTEA has multiple byte-order conventions in the wild. This tool uses little-endian, matching the reference C implementation by the original authors.
Command line equivalent
# Python with xxtea
pip install xxtea
python3 -c '
import xxtea, base64
key = b"0123456789abcdef"
ct = xxtea.encrypt(b"hello world", key)
print(base64.b64encode(ct).decode())
'
# Node with xxtea npm package
npm i xxtea
node -e '
const xxtea = require("xxtea");
const key = "0123456789abcdef";
console.log(xxtea.encryptToString("hello world", key));
'
# XXTEA reference test vector
# Key: 0x00000000 0x00000000 0x00000000 0x00000000
# Pt: 0x00000000 0x00000000
# Ct: (see the reference implementation)
# Command line
# No standard CLI tool ships XXTEA.