WPA/WPA2 handshake cracker on Apple Metal GPU. First one ever built.
hashcat doesn't support Metal. On macOS you're stuck with CPU-only cracking at ~30K PMKs/sec. metal-crack runs the entire PBKDF2-SHA1 pipeline on the GPU — 200K PMKs/sec on M1 Max. No CUDA, no OpenCL, no drivers. Just Metal.
Status: MVP — Works, cracks passwords, has been tested against real handshakes. Not hashcat. Not trying to be.
WPA key derivation is brutally expensive: 4,096 iterations of HMAC-SHA1 per password candidate, then PTK derivation, then MIC verification. That's ~16,384 SHA-1 block transforms per guess.
metal-crack runs this entirely on the GPU in two compute passes:
Pass 1: PBKDF2-SHA1(password, SSID, 4096) → PMK [99% of compute]
Pass 2: PRF-512(PMK) → PTK → HMAC-SHA1 → MIC → compare with captured MIC
Each GPU thread processes one password. Thousands run in parallel. Unified memory means zero CPU↔GPU copying — the wordlist goes straight to the GPU.
| Platform | Tool | Rate |
|---|---|---|
| M1 Max CPU | hashcat -D1 | ~30K PMKs/sec |
| M1 Max GPU | metal-crack | ~200K PMKs/sec |
| RTX 4090 | hashcat -D2 | ~2.5M PMKs/sec |
No, we don't beat a 4090. But 200K on Apple Silicon with zero setup — no drivers, no kernel extensions, just swift build — is useful. Especially when the alternative is 30K on CPU.
- Pre-computed HMAC key states — ipad/opad SHA-1 prefixes stored as thread registers, reused across 4,096 iterations
- Zero per-batch allocation — all Metal buffers pre-allocated and reused
- Pure uint32 SHA-1 — no byte conversions in the hot path, 2 transforms per iteration
- Streaming wordlist — 1 MB chunks from disk, never loads the full wordlist into memory
- Batch dispatch — 16K-64K candidates per GPU dispatch (tunable)
.hc22000— hashcat format (WPA*02 lines). This is the primary input format.- WPA2 with HMAC-SHA1 (key version 2) only. WPA1/MD5 and WPA3/AES-CMAC are not supported.
- PMKID-only entries (WPA*01 lines) are not yet supported.
- macOS 13+ (Ventura, Sonoma, Sequoia, Tahoe)
- Apple Silicon (M1 or later)
- Swift 5.9+ (comes with Xcode)
git clone https://github.com/RLabs-Inc/metal-crack.git
cd metal-crack
swift build -c release
.build/release/metal-crack -w rockyou.txt -c handshake.hc22000That's it. Metal is built into macOS. No SDK to install, no GPU drivers, no environment variables.
swift test15 tests against RFC/FIPS/IEEE standard vectors (SHA-1, HMAC-SHA1, PBKDF2, WPA PMK derivation, hc22000 parsing).
metal-crack -w <wordlist> -c <capture.hc22000> [options]
Options:
-w, --wordlist <path> Path to wordlist file
-c, --capture <path> Path to .hc22000 capture file
-b, --batch-size <n> Candidates per GPU batch (default: 16384)
-h, --help Show this help
$ metal-crack -w rockyou.txt -c office-wifi.hc22000
metal-crack — WPA/WPA2 GPU Cracker (Apple Metal)
SSID: OfficeNetwork
AP MAC: AA:BB:CC:DD:EE:FF
STA MAC: 11:22:33:44:55:66
Key Ver: 2 (HMAC-SHA1)
Target MIC: 7a3f...
[=======> ] 1,247,532 / ? | 198.4K PMKs/sec | 00:06:17
[FOUND] Password: summer2024!
Tested: 1,247,532 | Elapsed: 6m17s | Avg: 198.4K PMKs/secwifikit captures handshakes over the air. metal-crack cracks them.
# In wifikit: capture handshake, export for cracking
/export hc22000 office-wifi.hc22000
# In terminal: crack it
metal-crack -w rockyou.txt -c office-wifi.hc22000Two tools, one workflow. Both run natively on macOS with Apple Silicon. No VMs, no Linux, no CUDA.
- PMKID cracking — hc22000 WPA*01 lines (PMKID-only, no full handshake needed)
- WPA3/SAE — different key derivation (Dragonfly/SAE), not PBKDF2
- Multiple handshakes — currently cracks the first entry in the file
- Rule-based mutations — hashcat-style rules ($1, ^a, etc.)
- Mask attacks — pattern-based candidate generation (?d?d?d?d)
- Resume/checkpoint — restart from where you left off
For those who want to understand or verify:
- PBKDF2-SHA1 (RFC 2898, RFC 6070):
DK = T1 || T2where each T is 4,096 iterations ofHMAC-SHA1(password, SSID || INT(i)) - PRF-512 (IEEE 802.11i §8.5.1):
PTK = PRF(PMK, "Pairwise key expansion", min(AA,SA) || max(AA,SA) || min(ANonce,SNonce) || max(ANonce,SNonce)) - MIC (IEEE 802.11i §8.5.2):
MIC = HMAC-SHA1(KCK, EAPOL_frame)[0:16]where KCK = PTK[0:16]
Every test in the suite validates against published RFC/FIPS/IEEE test vectors. The GPU produces bit-identical results to the CPU reference.
This tool is for authorized security testing and research only. Cracking WiFi passwords without explicit authorization is illegal in most jurisdictions.
MIT