MD4 generator
MD4 in Depth
MD4 (1990) was built for speed on 32-bit machines and became the ancestor of MD5, SHA-0, and SHA-1 — nearly every hash you know descends from its three-round structure. NTLM password hashes are literally MD4 of UTF-16 passwords, which is why it still haunts Windows security.
How It Broke
Collisions were demonstrated in 1995 and have only gotten cheaper — today they take seconds. Its speed, once a virtue, is now a liability for password hashing: attackers try billions of MD4 guesses per second.
Legitimate Remnants
Matching NTLM hashes during audits, verifying ancient checksums, and teaching: MD4's elegant simplicity makes it the best hash to study before tackling SHA-2's complexity.
How to Use the MD4 Hash Generator
MD4 is the influential 128-bit hash from RFC 1320 that became the core of Windows NTLM password hashing and the eDonkey file-sharing network — broken today, but historically important.
- Paste the string you want to fingerprint — MD4 is fast but cryptographically broken, fit only for non-security checksums.
- Click the hash button to compute the 128-bit MD4 digest.
- Copy the 32-character hexadecimal result for legacy research, NTLM-format study or old-protocol compatibility.
Example
Hashing the word hello with MD4 always produces 866437cb7a794bce2b727acc0362ee27 — the standard test vector from the original MD4 specification.
Frequently Asked Questions
Where was MD4 actually used?
Microsoft built NTLM authentication on MD4, and the eDonkey/eMule networks used MD4-based ed2k links for file identification. Both are legacy now.
Is MD4 completely broken?
Yes — collisions were demonstrated as early as 1995 and attacks have only become trivial since. It should never be used for security, and NTLM itself is deprecated.
How does MD4 relate to MD5 and RIPEMD?
MD5 was Rivest direct hardening of MD4, and the European RIPEMD family was built on MD4 design ideas — so MD4 is the ancestor of a whole generation of hashes.