Skip to content

About

WPA/WPA2 handshake cracker on Apple Metal GPU

Topics

Resources

Stars

3 stars

Watchers

0 watching

Forks

Latest commit

 

History

4 Commits

Folders and files

Repository files navigation

metal-crack

WPA/WPA2 handshake cracker on Apple Metal GPU. First one ever built.

hashcat doesn't support Metal. On macOS you're stuck with CPU-only cracking at ~30K PMKs/sec. metal-crack runs the entire PBKDF2-SHA1 pipeline on the GPU — 200K PMKs/sec on M1 Max. No CUDA, no OpenCL, no drivers. Just Metal.

Status: MVP — Works, cracks passwords, has been tested against real handshakes. Not hashcat. Not trying to be.

How It Works

WPA key derivation is brutally expensive: 4,096 iterations of HMAC-SHA1 per password candidate, then PTK derivation, then MIC verification. That's ~16,384 SHA-1 block transforms per guess.

metal-crack runs this entirely on the GPU in two compute passes:

Pass 1: PBKDF2-SHA1(password, SSID, 4096) → PMK     [99% of compute]
Pass 2: PRF-512(PMK) → PTK → HMAC-SHA1 → MIC → compare with captured MIC

Each GPU thread processes one password. Thousands run in parallel. Unified memory means zero CPU↔GPU copying — the wordlist goes straight to the GPU.

Performance

Platform Tool Rate
M1 Max CPU hashcat -D1 ~30K PMKs/sec
M1 Max GPU metal-crack ~200K PMKs/sec
RTX 4090 hashcat -D2 ~2.5M PMKs/sec

No, we don't beat a 4090. But 200K on Apple Silicon with zero setup — no drivers, no kernel extensions, just swift build — is useful. Especially when the alternative is 30K on CPU.

GPU Optimizations

  • Pre-computed HMAC key states — ipad/opad SHA-1 prefixes stored as thread registers, reused across 4,096 iterations
  • Zero per-batch allocation — all Metal buffers pre-allocated and reused
  • Pure uint32 SHA-1 — no byte conversions in the hot path, 2 transforms per iteration
  • Streaming wordlist — 1 MB chunks from disk, never loads the full wordlist into memory
  • Batch dispatch — 16K-64K candidates per GPU dispatch (tunable)

Supported Formats

  • .hc22000 — hashcat format (WPA*02 lines). This is the primary input format.
  • WPA2 with HMAC-SHA1 (key version 2) only. WPA1/MD5 and WPA3/AES-CMAC are not supported.
  • PMKID-only entries (WPA*01 lines) are not yet supported.

Building

Requirements

  • macOS 13+ (Ventura, Sonoma, Sequoia, Tahoe)
  • Apple Silicon (M1 or later)
  • Swift 5.9+ (comes with Xcode)

Build & Run

git clone https://github.com/RLabs-Inc/metal-crack.git
cd metal-crack
swift build -c release
.build/release/metal-crack -w rockyou.txt -c handshake.hc22000

That's it. Metal is built into macOS. No SDK to install, no GPU drivers, no environment variables.

Run Tests

swift test

15 tests against RFC/FIPS/IEEE standard vectors (SHA-1, HMAC-SHA1, PBKDF2, WPA PMK derivation, hc22000 parsing).

Usage

metal-crack -w <wordlist> -c <capture.hc22000> [options]

Options:
  -w, --wordlist <path>    Path to wordlist file
  -c, --capture <path>     Path to .hc22000 capture file
  -b, --batch-size <n>     Candidates per GPU batch (default: 16384)
  -h, --help               Show this help

Example

$ metal-crack -w rockyou.txt -c office-wifi.hc22000

metal-crack — WPA/WPA2 GPU Cracker (Apple Metal)

  SSID:       OfficeNetwork
  AP MAC:     AA:BB:CC:DD:EE:FF
  STA MAC:    11:22:33:44:55:66
  Key Ver:    2 (HMAC-SHA1)
  Target MIC: 7a3f...

  [=======>                    ] 1,247,532 / ? | 198.4K PMKs/sec | 00:06:17

  [FOUND] Password: summer2024!
  Tested: 1,247,532 | Elapsed: 6m17s | Avg: 198.4K PMKs/sec

Integration with wifikit

wifikit captures handshakes over the air. metal-crack cracks them.

# In wifikit: capture handshake, export for cracking
/export hc22000 office-wifi.hc22000

# In terminal: crack it
metal-crack -w rockyou.txt -c office-wifi.hc22000

Two tools, one workflow. Both run natively on macOS with Apple Silicon. No VMs, no Linux, no CUDA.

What's Missing

  • PMKID cracking — hc22000 WPA*01 lines (PMKID-only, no full handshake needed)
  • WPA3/SAE — different key derivation (Dragonfly/SAE), not PBKDF2
  • Multiple handshakes — currently cracks the first entry in the file
  • Rule-based mutations — hashcat-style rules ($1, ^a, etc.)
  • Mask attacks — pattern-based candidate generation (?d?d?d?d)
  • Resume/checkpoint — restart from where you left off

How the Crypto Works

For those who want to understand or verify:

  1. PBKDF2-SHA1 (RFC 2898, RFC 6070): DK = T1 || T2 where each T is 4,096 iterations of HMAC-SHA1(password, SSID || INT(i))
  2. PRF-512 (IEEE 802.11i §8.5.1): PTK = PRF(PMK, "Pairwise key expansion", min(AA,SA) || max(AA,SA) || min(ANonce,SNonce) || max(ANonce,SNonce))
  3. MIC (IEEE 802.11i §8.5.2): MIC = HMAC-SHA1(KCK, EAPOL_frame)[0:16] where KCK = PTK[0:16]

Every test in the suite validates against published RFC/FIPS/IEEE test vectors. The GPU produces bit-identical results to the CPU reference.

Legal

This tool is for authorized security testing and research only. Cracking WiFi passwords without explicit authorization is illegal in most jurisdictions.

License

MIT

About

WPA/WPA2 handshake cracker on Apple Metal GPU

Topics

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages