A single server processor costing about $2,100 can crack passwords hashed with the memory-hard Argon2 algorithm faster than a rig of eight high-end graphics cards worth more than $5,000 each, according to new research from Specops Software, the identity and access management division of Outpost24.
The finding, published as part of Specops’ latest time-to-crack research, illustrates how Argon2’s memory-hard design changes the economics of password cracking. Tested against eight Nvidia RTX 5090 cards, Argon2id managed just 490 hashes per second, compared with 221 billion hashes per second for SHA256 on the same hardware — a difference of roughly 451 million times. In practical terms, a password that would fall in one second under SHA256 could hold out for more than 14 years under Argon2id.
Where the cost curve bends
The more counterintuitive part of the research is where the price-to-performance curve shifts. The cracking tool mdxfind reached 730 hashes per second running on a single AMD EPYC processor costing around $2,100 — outpacing the eight-card GPU rig built from cards priced above $5,000 apiece. Against Argon2, the algorithm that won the 2015 Password Hashing Competition, raw GPU spending stops buying attackers much additional speed, and cheaper, well-matched hardware can still recover some hashes.
Specops noted that none of this helps against a password an attacker already holds from a breach, a phishing attack or an infostealer infection — the cracking resistance of an algorithm is irrelevant once a plaintext credential has been stolen outright. The research recommends organisations enforce a minimum password length of 15 characters as a baseline defence.
Tied to a broader breached password update
The research lands alongside an update to Specops’ Breached Password Protection service, which has added more than 60 million newly compromised passwords gathered from the company’s honeypot network and threat intelligence sources. Specops says it protects more than 3,000 organisations across 65 countries, with native Active Directory integration and a database of more than 6 billion compromised passwords updated daily.
For enterprise security teams, the takeaway is less about which hashing algorithm to pick — Argon2 is already well regarded — and more about layering defences: strong, long passwords, breached-password screening, and monitoring for credential exposure remain necessary even when the underlying hash is difficult to brute-force.



Share your thoughts