About Chad Hamad
I'm Chad Hamad a cybersecurity strategist and Virtual CISO. Over 15 years I've built and led security programs for startups through Fortune 500 enterprises, and run incident response when things went wrong.
RedHacker (redhacker.ai) came out of that work. Password auditing is part of almost every assessment I run: dump the hashes, find out how many are recoverable, show leadership the real number. The public tools for that are either tiny, plastered in ads, or quietly log what you paste. So I built the one I actually wanted.
It searches a precomputed index of 6.4 billion real passwords every major public wordlist, merged and deduplicated across MD5, SHA-1, SHA-256 and NTLM. Free, no signup, results in milliseconds.
What it costs to run: a server, ~600 GB of storage for the index, and the compute to rebuild it as new breach corpora appear. There are no ads and no tracker scripts, deliberately a page where people paste password hashes is the last place third-party JavaScript belongs. Hashes submitted for lookup aren't stored.
Be clear about what it can't do: salted hashes bcrypt, scrypt, argon2 are immune by design. No lookup table can exist for them. If your organisation is using them, that's the correct answer, and it's exactly what I'd tell you in an assessment.
If RedHacker saved you time on an engagement, a coffee helps keep it free and ad-free for everyone else.
Recent supporters
