Keccak

Advanced
Update shuda Sep 30, 2026

What Is Keccak?

Keccak is a cryptographic hash function that forms the basis of SHA-3, the newest member of the Secure Hash Algorithm (SHA) family.

What Is SHA?

SHA stands for Secure Hash Algorithm, a set of cryptographic hash function standards published by the US National Institute of Standards and Technology (NIST). 

Keccak was designed by Guido Bertoni, Joan Daemen, Michaël Peeters, and Gilles Van Assche, a team of European cryptographers (Daemen also co-designed the AES cipher). 

Although Keccak can serve other purposes like data encryption, it is best known as a hash function. It produces the same output sizes as SHA-2 (224, 256, 384, and 512 bits), but its internal mechanism is quite different, which is why it is often described as a more modern alternative rather than just a more secure one.

From SHA-1 to SHA-2

Theoretical attacks against SHA-1 emerged in 2004 and 2005, raising concerns about its long-term reliability. SHA-2, designed by the US National Security Agency (NSA), had been published by NIST in 2001, but the migration from SHA-1 was slow. 

By early 2017, major browsers and certificate authorities had largely completed the transition. In February 2017, researchers from Google and CWI Amsterdam announced SHAttered, the first practical collision attack (where an attacker finds two different inputs that trick a security system into generating the same hash) against SHA-1. Since then, SHA-1 has been considered unsafe for collision resistance, and the NIST announced plans to disallow SHA-1 for all applications by 2030.

The SHA-3 Competition

NIST launched a public competition in 2007 to develop a new hash algorithm. At the time, no significant attack against SHA-2 had been demonstrated, but NIST wanted a successor ready before one appeared, since developing and standardizing a new function takes years. Keccak was submitted to the competition in 2008 by the four-member team, and in October 2012 NIST selected it as the winning algorithm. It was standardized as FIPS 202 (Federal Information Processing Standards) in 2015, officially joining the SHA family as SHA-3.

How Keccak Works: The Sponge Construction

One reason Keccak was chosen is its innovative internal structure. SHA-1 and SHA-2 rely on the Merkle-Damgård construction, which processes data in fixed-size blocks and chains each block’s result into the next. Keccak instead uses the sponge construction, which absorbs input into an internal state and then squeezes out output of the desired length. This design differs fundamentally from earlier SHA functions and supports flexible output lengths, including the extendable-output functions SHAKE128 and SHAKE256.

Keccak in Crypto

SHA-2 remains widely used and is still considered secure. SHA-256, for instance, is central to Bitcoin’s proof of work system, where mining involves repeatedly hashing block data while searching for a valid block.
Ethereum uses Keccak-256 as its core hash function for account addresses, transaction hashes, and other protocol operations. A technical nuance is worth knowing: Ethereum adopted Keccak-256 before the final SHA-3 standard was published, so it uses the original Keccak padding rather than the one specified in FIPS 202. As a result, the keccak256 function available in smart contracts on Ethereum does not produce the same output as the standardized SHA3-256, a common source of confusion for developers.

Looking ahead, SHA-3 adoption may grow as newer systems favor its different structure, though SHA-2 remains far from being successfully attacked.

Learn more: What Is Hashing?
Posts share karein
Mutaliqa Glossaries

Binance Academy Editorial

Account register karein
Aaj hi Binance ka account khol kar apnay ilm ka amli tor par istemal karein