Vrmac.Pwned 1.0.0

dotnet add package Vrmac.Pwned --version 1.0.0
                    
NuGet\Install-Package Vrmac.Pwned -Version 1.0.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Vrmac.Pwned" Version="1.0.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Vrmac.Pwned" Version="1.0.0" />
                    
Directory.Packages.props
<PackageReference Include="Vrmac.Pwned" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Vrmac.Pwned --version 1.0.0
                    
#r "nuget: Vrmac.Pwned, 1.0.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Vrmac.Pwned@1.0.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Vrmac.Pwned&version=1.0.0
                    
Install as a Cake Addin
#tool nuget:?package=Vrmac.Pwned&version=1.0.0
                    
Install as a Cake Tool

Vrmac.Pwned

This project builds a .NET library to test passwords against the “Have I Been Pwned?” dataset maintained by Troy Hunt.

To save storage and memory, the OG dataset is compressed into a Bloom filter.
The source dataset contains 38.5 GB of binary hashes (text files are much larger, over 75 GB), whilst the Bloom filter is a much more manageable 4 GB.

Note that Bloom filters are probabilistic: there is a non-zero probability of false positives.
Specifically, with this implementation that probability is 0.033%, which is not terribly bad for most purposes.

Usage

The only public class in this library is PwnedQuery.
Construct it by passing the path to the Bloom filter file on disk.
Network-mounted paths are not recommended and may not work reliably.

Once constructed, call public bool query( string passwordText ) method, passing the password to test.
The method is thread-safe and reentrant.

When query returns false, the password is definitely not in the breached dataset.
When it returns true, the password is most likely in the breached dataset, with a 0.033% chance of being a false positive.

Filter File

You may be wondering where to obtain the 4 GB filter file.

See “Vrmac.PwnedFilter” project in this repository for the tool that builds it from the original dataset.

Alternatively, if you would rather not download 75.6 GB of ASCII text files, use Pwned.2026-09-26.torrent file in this repository to download a pre-built filter. The torrent contains a single file pwned.bin. Download that file, and pass the absolute path to the constructor of the PwnedQuery class.

Ideally, verify SHA-512 checksum of that file after the download. On Windows:

certutil -hashfile pwned.bin SHA512
SHA512 hash of pwned.bin:
91b0723c4324c1d599099e4ef47cd19169a65849ed591308c394d1799aec45ad31c1ad2b3796d753dccc50e2a6488c62ff3330c082db823aa6667c3722ac3aa1
CertUtil: -hashfile command completed successfully.

On Linux:

sha512sum pwned.bin
91b0723c4324c1d599099e4ef47cd19169a65849ed591308c394d1799aec45ad31c1ad2b3796d753dccc50e2a6488c62ff3330c082db823aa6667c3722ac3aa1  pwned.bin

I can’t promise I will update that binary file regularly, or at all. If you want timely updates, please use the Vrmac.PwnedFilter tool to build your own version of the binary file.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • net10.0

    • No dependencies.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.0.0 57 9/30/2026