MD6 Hash Generator

Generate MD6 hashes with custom digest size and key.

0 chars
MD6

Result will appear here...

MD6 Hash Generator

Generate MD6 hashes with a selectable digest size (MD6-128 up to MD6-512) and an optional key. Type text, paste hex or Base64 bytes, or pick a file — the result is calculated locally in your browser.

About MD6

MD6 was designed in 2008 by a team led by Ron Rivest at MIT as a candidate for the SHA-3 competition. Unlike the MD4/MD5 line, MD6 is built around a hash tree: the message is cut into 512-byte chunks, each chunk is compressed to 128 bytes, and the results are combined four at a time until a single node remains. This makes MD6 naturally parallel, so multi-core processors can hash very large inputs faster.

The compression function operates on 89 words of 64 bits (15 constant words derived from √6, an 8-word key, node identifiers, and the data) and runs 40 + d/4 rounds, where d is the digest size. Default parameters give these reference values:

  • MD6-256("") = bca38b24a804aa37d821d31af00f5598230122c5bbfc4c4ad5ed40e4258f04ca
  • MD6-256("abc") = 230637d4e6845cf0d092b558e87625f03881dd53a7439da34cf3b94ed0d8b2c5

Options

  • Digest size – choose the output length. MD6-256 is the most widely quoted variant.
  • Key – an optional secret (UTF-8, up to 64 bytes) that turns MD6 into a keyed hash.
  • Output – hex, uppercase hex, or Base64.

This implementation uses the standard mode parameter L = 64 (fully hierarchical) and has been checked against the published test vectors.

Where to use it

MD6 is mostly used in research, cryptography courses, CTF puzzles, and a handful of applications that picked it during the SHA-3 era. For production systems, standardized algorithms such as SHA3-256 or SHA-512 are the safer choice.

Frequently Asked Questions

MD6 was withdrawn from the NIST SHA-3 competition in 2009 because the authors could not yet prove its security at a speed that was competitive. The Keccak design won instead and became SHA-3, so MD6 stayed a research algorithm.

MD6 has a built-in key input of up to 64 bytes, so it can act as a MAC without an HMAC wrapper. A non-empty key also raises the minimum number of rounds to 80. Leave it empty for a normal unkeyed hash.

MD6 allows any output length from 1 to 512 bits. This tool offers the common sizes 128, 160, 224, 256, 384, and 512 bits. The number of rounds grows with the size (40 + size/4), so longer digests take slightly longer.