The domain sha3.si is for sale. Make an offer or buy it now →

SHA-3 vs Keccak-256

The most common SHA-3 bug in blockchain code: calling a SHA3-256 function when Ethereum expects Keccak-256. Same algorithm core, one different padding byte, totally different result.

The one difference

Keccak won the NIST competition in 2012. When NIST published the final standard (FIPS 202, 2015), it added domain-separation bits to the padding so SHA-3 and SHAKE outputs can never collide with each other:

VariantPadding starts withUsed by
Keccak-256 (original)0x01Ethereum and EVM chains (addresses, tx hashes, function selectors)
SHA3-256 (FIPS 202)0x06NIST standard, OpenSSL, Python hashlib, Java, .NET
SHAKE128 / SHAKE2560x1FNIST XOFs, post-quantum standards

Ethereum's design was fixed before FIPS 202 was final, so it kept the original padding. Many Ethereum libraries still call it "sha3", which is where the confusion comes from: Solidity's old sha3() was an alias of keccak256().

Proof, with real digests

InputKeccak-256 (Ethereum)SHA3-256 (NIST)
"" (empty)c5d2460186f7233c927e7db2dcc703c0e500b653ca82273b7bfad8045d85a470a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
"abc"4e03657aea45a94fc7d47ba826c8d667c0d1e6e33a64a036ec44f58fa12d6c453a985da74fe225b2045c172d6bd390bd855f086e3e9d525b46bfe24511431532
"hello world"47173285a8d7341e5e972fc677286384f802f8ef42a5ec5f03bbfa254cb01fad644bcc7e564373040999aac89e7622f3ca71fba1d972fd94a31c3bfbf24e3938

If your empty-string hash starts with c5d24601, you have Keccak-256. If it starts with a7ffc6f8, you have SHA3-256.

Computing each

# Python: NIST SHA3-256
import hashlib
hashlib.sha3_256(b"abc").hexdigest()

# Python: Ethereum Keccak-256 (pip install pycryptodome)
from Crypto.Hash import keccak
k = keccak.new(digest_bits=256)
k.update(b"abc")
k.hexdigest()
// JavaScript (ethers v6): Ethereum Keccak-256
import { keccak256, toUtf8Bytes } from "ethers";
keccak256(toUtf8Bytes("abc"));

// Node.js: NIST SHA3-256
import { createHash } from "node:crypto";
createHash("sha3-256").update("abc").digest("hex");

Frequently asked

Is Ethereum keccak256 the same as SHA3-256?

No. Ethereum uses the original Keccak submission padding (domain byte 0x01). NIST SHA3-256 adds two domain bits (byte 0x06). The outputs are completely different.

Which libraries give Ethereum-compatible Keccak-256?

Use functions explicitly named keccak256 or Keccak-256: ethers.js and web3.js keccak256, pycryptodome Crypto.Hash.keccak, Go golang.org/x/crypto/sha3 NewLegacyKeccak256, the Rust sha3 crate Keccak256.

Own sha3.si

A short, exact-match domain for one of the world's core cryptographic standards. Ideal for a security, cryptography, blockchain or developer-tools brand.

Buy now or make an offer Why this name