Hundreds of millions of passwords from data breaches are public. Attackers try them first, on every site. Checking whether yours are among them is worth doing, as long as the check itself doesn’t leak them.
How a safe check works
Have I Been Pwned’s password service uses a technique called k-anonymity. Your device:
- hashes the password with SHA-1;
- sends only the first five characters of the hash;
- gets back every breached hash that starts with those five characters, hundreds of them;
- looks for its own among them, on your device.
The service never learns your password, or even which of the hashes you were looking for.
Check them all at once
Vallkey’s Security view checks every password in your vault this way, and lists the ones that appear in breaches, with how often.
When one turns up
- Change it on that site, to a new random password.
- Change it everywhere else you used it.
- Turn on two-factor authentication where the site offers it.
Last updated October 3, 2026