RTX 5090 beats $30,000 NVIDIA H200 in password cracking benchmarks

RTX 5090 outperforms the Nvidia H200 and AMD MI300X in every password cracking benchmark, at a tenth of the price

Cybersecurity firm Specops published research this April putting three high-end GPUs head to head in a password cracking competition: the Nvidia H200, the AMD MI300X, and the Nvidia RTX 5090. The goal was simple, find out if the $30,000 AI accelerators used in data centers around the world can outperform a consumer gaming GPU when it comes to brute-forcing password hashes. The results were not even close.

Using Hashcat, one of the most widely used password recovery tools in the industry, Specops benchmarked five hashing algorithms: MD5, NTLM, bcrypt, SHA-256, and SHA-512. Across every single one of them, the RTX 5090 came out on top. On average, the gaming card was 63.7% faster than the H200 and 20% faster than the MI300X. In SHA-512 specifically, the RTX 5090 was up to 93.5% faster than the H200, nearly double the speed. The H200 costs at least ten times more than the RTX 5090, which retails around $2,000.

AI GPUs are built for one thing, and password cracking isn’t it

The reason behind these results comes down to how AI accelerators are designed. GPUs like the H200 and MI300X are optimized for deep learning workloads, which rely heavily on reduced precision formats like FP8, INT8, and BF16, operations handled almost entirely by their Tensor cores. Password cracking works completely differently. It depends on 32-bit integer operations, or INT32, and those are not what AI chips are built for.

MSI RTX 5090 bursts into flames during first boot

The H200, for example, has only half as many INT32 cores as FP32 cores, and significantly fewer than the RTX 5090 overall. The MI300X technically has strong theoretical INT32 performance, but it still loses, the Nvidia-specific optimizations baked into Hashcat’s code give the RTX 5090 an advantage that AMD can’t overcome. Consumer gaming GPUs, on the other hand, are built to handle a wide range of workloads, which makes them naturally more versatile when running tools like Hashcat.

Specops put it plainly: AI accelerators are so specialized for their intended role that there’s not much they can do beyond it. For now, consumer desktop GPUs remain the fastest hardware available for cracking passwords.

A nine-year-old GPU rig still beats today’s $30,000 AI hardware

One of the more striking data points from this research involves hardware from 2017. That year, IBM built a password-cracking rig using eight Nvidia GTX 1080s, the flagship consumer GPU of the time, and achieved an NTLM hash cracking rate of 334 GH/s. That nine-year-old consumer GPU cluster delivers results comparable to, and in some cases better than, what today’s flagship AI accelerators manage in this same workload, despite costing a fraction of the price.

The RTX 5090, for its part, pushes those numbers significantly further. Verified Hashcat benchmarks show a single RTX 5090 hitting around 220 billion hashes per second on MD5, and an estimated 420 billion on NTLM. A single card can crack a numerical eight-character password hash in just three hours, one hour faster than the RTX 4090, representing a 33% improvement. Scale that up to a cluster of twelve RTX 5090s and the same password falls in under fifteen minutes.

This matters beyond the hardware comparison. It means that attackers don’t need exotic or expensive AI infrastructure to pose a serious threat. A well-equipped gaming PC is already enough to tear through weak password hashes at a terrifying pace. The Hive Systems 2025 password cracking benchmark confirmed this, noting that an eight-character password using only lowercase letters and numbers could be cracked by twelve RTX 5090s in just three weeks, while adding uppercase letters pushes that estimate to fifteen years.

The practical takeaway for organizations is straightforward. The real protection doesn’t come from betting on attackers not having powerful hardware, they already do. It comes from longer passphrases, genuine password complexity, multi-factor authentication, and continuous monitoring for breached credentials. The hashing algorithm also matters: bcrypt is deliberately slow by design, making brute-force attacks far less viable, while older algorithms like MD5 and NTLM are fast by nature and should be avoided wherever possible.

If there’s one conclusion from the Specops research, it’s this: spending $30,000 on an H200 will not make your passwords harder to crack. A $2,000 gaming GPU will do that job better.

So what do you think, does it surprise you that a gaming GPU beats a $30,000 AI chip at this? Tell us in the comments, we’d love to know your take!