SHA-3 vs Keccak-256
The most common SHA-3 bug in blockchain code: calling a SHA3-256 function when Ethereum expects Keccak-256. Same algorithm core, one different padding byte, totally different result.
The one difference
Keccak won the NIST competition in 2012. When NIST published the final standard (FIPS 202, 2015), it added domain-separation bits to the padding so SHA-3 and SHAKE outputs can never collide with each other:
| Variant | Padding starts with | Used by |
|---|---|---|
| Keccak-256 (original) | 0x01 | Ethereum and EVM chains (addresses, tx hashes, function selectors) |
| SHA3-256 (FIPS 202) | 0x06 | NIST standard, OpenSSL, Python hashlib, Java, .NET |
| SHAKE128 / SHAKE256 | 0x1F | NIST XOFs, post-quantum standards |
Ethereum's design was fixed before FIPS 202 was final, so it kept the original padding. Many Ethereum libraries still call it "sha3", which is where the confusion comes from: Solidity's old sha3() was an alias of keccak256().
Proof, with real digests
| Input | Keccak-256 (Ethereum) | SHA3-256 (NIST) |
|---|---|---|
| "" (empty) | c5d2460186f7233c927e7db2dcc703c0e500b653ca82273b7bfad8045d85a470 | a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a |
| "abc" | 4e03657aea45a94fc7d47ba826c8d667c0d1e6e33a64a036ec44f58fa12d6c45 | 3a985da74fe225b2045c172d6bd390bd855f086e3e9d525b46bfe24511431532 |
| "hello world" | 47173285a8d7341e5e972fc677286384f802f8ef42a5ec5f03bbfa254cb01fad | 644bcc7e564373040999aac89e7622f3ca71fba1d972fd94a31c3bfbf24e3938 |
If your empty-string hash starts with c5d24601, you have Keccak-256. If it starts with a7ffc6f8, you have SHA3-256.
Computing each
# Python: NIST SHA3-256
import hashlib
hashlib.sha3_256(b"abc").hexdigest()
# Python: Ethereum Keccak-256 (pip install pycryptodome)
from Crypto.Hash import keccak
k = keccak.new(digest_bits=256)
k.update(b"abc")
k.hexdigest()
// JavaScript (ethers v6): Ethereum Keccak-256
import { keccak256, toUtf8Bytes } from "ethers";
keccak256(toUtf8Bytes("abc"));
// Node.js: NIST SHA3-256
import { createHash } from "node:crypto";
createHash("sha3-256").update("abc").digest("hex");
Frequently asked
Is Ethereum keccak256 the same as SHA3-256?
No. Ethereum uses the original Keccak submission padding (domain byte 0x01). NIST SHA3-256 adds two domain bits (byte 0x06). The outputs are completely different.
Which libraries give Ethereum-compatible Keccak-256?
Use functions explicitly named keccak256 or Keccak-256: ethers.js and web3.js keccak256, pycryptodome Crypto.Hash.keccak, Go golang.org/x/crypto/sha3 NewLegacyKeccak256, the Rust sha3 crate Keccak256.
Own sha3.si
A short, exact-match domain for one of the world's core cryptographic standards. Ideal for a security, cryptography, blockchain or developer-tools brand.
Buy now or make an offer Why this name