Back to News
Market Impact: 0.2

Kaspersky warns that passwords hashed with MD5 algorithm can be cracked in minutes using a GPU

Cybersecurity & Data PrivacyTechnology & InnovationArtificial Intelligence
Kaspersky warns that passwords hashed with MD5 algorithm can be cracked in minutes using a GPU

Kaspersky says password-cracking speeds are worsening, with 60% of tested passwords crackable in under an hour and 48% in under 60 seconds using a single GeForce RTX 5090 GPU. The firm warned that MD5 remains a major liability for password storage and recommended moving to slower hashing methods such as bcrypt or Argon2, plus MFA and passkeys. The article is broadly a cybersecurity warning rather than a market-moving event.

Analysis

The second-order takeaway is not just that weak passwords remain weak, but that the economics of credential attacks are improving faster than most enterprise security budgets are. When a single consumer GPU can compress large swaths of the attack surface into minutes, the marginal value of password-only defenses collapses; this raises the expected payoff for criminals targeting credential stuffing, account takeover, and downstream fraud rather than bespoke intrusion. The weakest link becomes identity recovery flows, help desks, and any business whose revenue depends on consumer logins rather than hardened enterprise controls. This is structurally bullish for vendors selling passwordless authentication, phishing-resistant MFA, and identity governance, but only if they can prove deployment friction is low. The real spend shift should show up first in regulated verticals and consumer platforms with high fraud loss rates, because they can justify incremental security spend with direct ROI. Over 6-18 months, the biggest beneficiaries are likely to be products that reduce reliance on human-chosen secrets and that can be rolled out without breaking UX; the laggards are pure password manager or legacy IAM vendors with weaker passkey roadmaps. The contrarian point: this may be more of a security operations problem than a headline platform replacement story. Many breaches still occur because attackers reuse credentials obtained elsewhere, so the near-term monetization is in detection, risk scoring, and adaptive authentication rather than a wholesale elimination of passwords. If passkey adoption stalls due to interoperability or recovery concerns, the market could overestimate the pace of wallet-share shift into next-gen auth, making security-software multiples vulnerable to disappointment. Catalyst-wise, watch for a rise in fraud disclosures, consumer-platform login incidents, and enterprise passkey rollout announcements over the next 1-2 quarters; those should validate the thesis. The tail risk is a major consumer-brand account-takeover event that accelerates board-level spending, but the more likely path is gradual budget reallocation from perimeter tools toward identity and access.

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request Demo

Market Sentiment

Overall Sentiment

mildly negative

Sentiment Score

-0.20

Key Decisions for Investors

  • Long CRWD / short a basket of legacy IAM or endpoint names with weaker identity franchises over 3-6 months; the trade works if security budgets rotate toward risk-based authentication and away from static perimeter spend.
  • Initiate a tactical long in ZS on any post-earnings pullback over the next 1-2 quarters; phishing-resistant access and zero-trust identity should see outsized attach rates as password cracking becomes cheaper.
  • Buy medium-dated calls in Okta (OKTA) or a similar identity platform ahead of next earnings if management comments on passkey adoption and MFA expansion improve; downside is capped, upside is driven by surprise acceleration in customer rollout cadence.
  • Short consumer internet or fintech names with weak MFA/friction-heavy recovery flows into any disclosure of credential stuffing or account-takeover losses; the asymmetry is 10-20% downside on trust damage versus limited upside from incremental security fixes.
  • For pairs, long cybersecurity identity beneficiaries versus short broad software index exposure for 6-12 months; if the market discounts this as a minor hygiene issue, the relative multiple rerating can still be meaningful while enterprise spend remains defensive.