What actually happens when someone cracks a WiFi password
WiFi password cracking is the process of discovering a network's password by testing many guesses in rapid succession, usually with software that automates the work. The attacker does not need physical access to your router — they can sit in a car outside your house or apartment and run the attack from their laptop. The time it takes depends entirely on password strength: a six-character password might fall in minutes, while a 16-character random string could take years even with powerful hardware.
The attack works because WiFi broadcasts a handshake — a brief exchange of encrypted data — every time a device connects. Software like Aircrack-ng or Hashcat captures that handshake and then tests thousands or millions of password guesses against it offline, without alerting your router. If a guess matches, the software confirms it and stops. The attacker never needs to be near your network during the actual cracking; they can capture the handshake once and crack it at home.
This matters because once someone has your password, they can see everything on your network: files shared between computers, passwords stored in browsers, video calls, banking sessions, and any unencrypted traffic. They can also use your internet connection to read illegal content or launch attacks on other networks, leaving your IP address as the source.
Key Takeaways
- WiFi cracking software tests password guesses against a captured handshake, so the attacker does not need to be near your network during the actual attack.
- A password shorter than 12 characters or made of dictionary words is vulnerable to cracking in hours or days with standard laptop hardware.
- WPA2 and WPA3 encryption are equally strong against cracking — the weakness is always the password itself, not the protocol.
- Changing your default router password and using a long random string stops the vast majority of attacks before they start.
- Monitoring which devices are connected to your network is the fastest way to notice an intrusion, since cracking takes time and an attacker must connect to use the network.
Why password length matters more than complexity
A password's strength against cracking depends almost entirely on its length. Each additional character multiplies the number of possible combinations: a 10-character password has roughly 62 billion possibilities if it uses uppercase, lowercase, and numbers. A 12-character password has 475 trillion. A 16-character password has 18 quintillion. Even with a GPU capable of testing billions of guesses per second, the time required becomes impractical.
This is why "P@ssw0rd!" — a password with uppercase, lowercase, numbers, and symbols — cracks faster than "correcthorsebatterystaple", even though the second one looks weaker. The first is 10 characters; the second is 25. Cracking software tests dictionary words and common patterns first, so a random phrase of common words still takes longer than a short string of mixed characters.
The practical threshold is 12 characters. Below that, modern hardware can test enough guesses in a reasonable time that cracking becomes feasible for someone with basic technical knowledge. At 12 characters or longer, the time required jumps into weeks or months even with powerful equipment, which deters most attackers. A 16-character random password is effectively uncrackable with current technology.
How to check if your password is already compromised
Before changing your password, check whether it appears in known breach databases. Sites like Have I Been Pwned let you search by password or email address to see if your credentials have appeared in public leaks from hacked companies. If your password has been breached, change it when ready on your router and anywhere else you use it.
To check your router password, log into your router's admin panel — usually by typing 192.168.1.1 or 192.168.0.1 into a browser — and look for the WiFi or wireless settings. The password is often labeled "Network Key" or "Pre-Shared Key." Write it down, then search for it on Have I Been Pwned. If it appears, change it right away.
Even if your password has not been breached, change it if you have shared it with guests, repair technicians, or previous household members. Anyone who has ever known your password is a potential risk, since they could have written it down or shared it further.
Setting a password that resists cracking
Create a new WiFi password that is at least 16 characters long and contains no dictionary words, names, dates, or patterns. The easiest way is to use a random password generator — most password managers like Bitwarden, 1Password, or KeePass have one built in. Generate a string, copy it, and paste it into your router's WiFi settings.
If you need to remember the password instead of storing it, use a passphrase of random common words: "purple elephant kitchen bicycle" is 28 characters and much easier to remember than a random string, while still being resistant to cracking. Avoid phrases from songs, movies, or books, since those are tested early in dictionary attacks.
After you set the new password, update it on all your devices — phones, laptops, tablets, smart home devices — so they reconnect. Most devices will prompt you to re-enter the password the next time they try to connect. If a device does not reconnect automatically, go to its WiFi settings, forget the network, and reconnect with the new password.
Monitoring your network for unauthorized connections
The fastest way to detect that someone has cracked your password is to check which devices are connected to your network. Log into your router's admin panel and look for a section called "Connected Devices," "DHCP Clients," or "Wireless Clients." Most routers show the device name, IP address, and MAC address for each connection. You should recognize every device listed.
If you see a device you do not recognize, note its MAC address — a string like "AA:BB:CC:DD:EE:FF" — and then disconnect it. Some routers let you block a MAC address so it cannot reconnect. After blocking it, change your WiFi password again, since the attacker now knows it does not work.
Check your connected devices list once a week, especially if you notice your internet is slow or your router is hot. A device running a cracking attack or using your connection to read large files will consume bandwidth and make your network sluggish. Slow internet is often the first sign of an intrusion.
Why WPA2 and WPA3 are equally safe against password attacks
Your router uses either WPA2 or WPA3 encryption to protect the WiFi handshake. Both are equally resistant to cracking attacks — the difference between them is negligible for password security. WPA3 is newer and has other advantages, but if your router only supports WPA2, you are not at a disadvantage against password cracking.
The real vulnerability is never the encryption protocol; it is always the password. A weak password on WPA3 cracks just as easily as a weak password on WPA2. Conversely, a strong password on either protocol is effectively uncrackable. If your router is more than five years old and does not support WPA3, upgrading is worth considering for other reasons — newer routers are faster and more reliable — but password strength matters far more than the protocol version.
Check your router's settings to confirm it is using WPA2 or WPA3, not the older WEP or WPA. If it is set to WEP, change it to WPA2 when ready. WEP has known flaws that allow cracking in minutes regardless of password strength. Most modern routers default to WPA2 or WPA3, but older models or those with default settings unchanged may still use WEP.
What to do if you think your network has been compromised
If you find an unauthorized device on your network or suspect someone has accessed it, disconnect the device when ready and change your WiFi password. Then restart your router by unplugging it for 30 seconds and plugging it back in. This forces all devices to reconnect and confirms which ones are legitimate.
After restarting, log into your router's admin panel and change the admin password as well — the password you use to log into the router settings, not the WiFi password. Many routers ship with default admin passwords like "admin/admin" or "admin/password," and if someone accessed your network, they may have also accessed your router settings. Changing the admin password prevents them from making further changes.
If you suspect the intrusion happened weeks or months ago, assume the attacker saw any unencrypted traffic on your network. Change passwords for email, banking, and other sensitive accounts from a different network — a phone on cellular data or a computer at a library — since those accounts may have been compromised. Monitor your email and bank accounts for unauthorized activity over the next month.
Frequently Asked Questions
Can someone crack my WiFi password if I have a strong password?
Not in a practical timeframe. A 16-character random password would take years to crack even with powerful hardware. Most attackers move on to easier targets. The risk is not cracking; it is someone who already knows your password — a guest, technician, or previous resident — using it to access your network.
Does hiding my WiFi network name make it harder to crack?
No. Hiding the network name (SSID) makes it slightly less obvious that a network exists, but cracking software can still find it and attack it. The security comes from the password strength, not from obscurity. A strong password is what actually protects you.
What should I do if I forget my WiFi password?
Log into your router's admin panel using the default admin password — usually printed on a sticker on the router — and look for WiFi or wireless settings. You can view or change the password there. If you do not know the admin password, you can factory reset the router by holding the reset button for 10 seconds, which erases all settings and returns it to defaults.
Is it illegal to crack a WiFi password?
Yes. Accessing a network without permission is illegal in most countries under computer fraud and unauthorized access laws. This applies even if you do not use the network for anything — connecting to it without permission is the crime. The only legal use of cracking tools is on networks you own or have explicit permission to test.
How often should I change my WiFi password?
Change it whenever you share it with someone who no longer needs access, or if you suspect it has been compromised. If you have not shared it with anyone new and you use a strong password, changing it every few months is not necessary. A strong password that only you know is more important than frequent changes to a weak one.