BREAKING: Awaiting the latest intelligence wire...
Back to Wire
AI-Generated Passwords: Seemingly Strong, Easily Cracked
Security
CRITICAL

AI-Generated Passwords: Seemingly Strong, Easily Cracked

Source: Theregister Original Author: Connor Jones Intelligence Analysis by Gemini

Sonic Intelligence

00:00 / 00:00

The Gist

Experts warn that AI-generated passwords from tools like Claude, ChatGPT, and Gemini often exhibit predictable patterns, making them vulnerable to hacking.

Explain Like I'm Five

"Imagine AI making secret codes, but it uses the same tricks over and over. Bad guys can learn those tricks and break the codes easily! It's better to use a random mix of letters, numbers, and symbols."

Deep Intelligence Analysis

A recent study by AI security company Irregular reveals that passwords generated by AI tools such as Claude, ChatGPT, and Gemini are surprisingly predictable and easily crackable. Despite appearing complex and passing online password strength checkers, these passwords exhibit common patterns that hackers can exploit. The researchers prompted each tool to generate 16-character passwords with special characters, numbers, and letters in different cases. However, the resulting passwords were not truly random and contained consistencies, particularly at the beginning of the strings.

Irregular's tests with Claude, using the Opus 4.6 model, showed that only 30 out of 50 generated passwords were unique, with many starting and ending with the same characters. Similar patterns were observed when prompting OpenAI's GPT-5.2 and Google's Gemini 3 Flash. The team estimated the entropy of the LLM-generated passwords using the Shannon entropy formula and found that the 16-character entropies were around 20-27 bits, significantly lower than the expected 98 bits for truly random passwords.

These findings highlight a critical security vulnerability. Users who rely on AI-generated passwords may be at increased risk of unauthorized access and data breaches. The study underscores the need for improved AI password generation algorithms and for users to adopt more robust password management practices, such as using third-party password managers and avoiding passwords generated by AI chatbots.

Transparency is essential in cybersecurity research. This analysis is based on publicly available information and aims to raise awareness about the risks associated with AI-generated passwords. As per EU AI Act Article 50, this deep analysis is intended for informational purposes and does not constitute professional advice.

_Context: This intelligence report was compiled by the DailyAIWire Strategy Engine. Verified for Art. 50 Compliance._

Impact Assessment

The findings expose a critical security flaw in AI-generated passwords. Users relying on these passwords may be at increased risk of unauthorized access and data breaches.

Read Full Story on Theregister

Key Details

  • AI chatbots like Claude, ChatGPT, and Gemini generate passwords with common patterns.
  • Irregular found that only 30 out of 50 passwords generated by Claude were unique.
  • LLM-generated passwords have an estimated entropy of around 20-27 bits, far below the expected 98 bits for truly random passwords.

Optimistic Outlook

The discovery of these vulnerabilities can lead to improvements in AI password generation algorithms. Password managers and security tools can adapt to identify and flag weak AI-generated passwords.

Pessimistic Outlook

Widespread use of predictable AI-generated passwords could create a significant attack surface for hackers. Users may overestimate the security of these passwords, leading to complacency and risky behavior.

DailyAIWire Logo

The Signal, Not
the Noise|

Get the week's top 1% of AI intelligence synthesized into a 5-minute read. Join 25,000+ AI leaders.

Unsubscribe anytime. No spam, ever.