Catalog
affaan-m/nodejs-keccak256

affaan-m

nodejs-keccak256

Prevent Ethereum hashing bugs in JavaScript and TypeScript. Node's sha3-256 is NIST SHA3, not Ethereum Keccak-256, and silently breaks selectors, signatures, storage slots, and address derivation.

global
origin:ECC direct-port adaptation
New~687
v1.2Saved Jul 14, 2026

Node.js Keccak-256

Ethereum uses Keccak-256, not the NIST-standardized SHA3 variant exposed by Node's crypto.createHash('sha3-256').

When to Use

  • Computing Ethereum function selectors or event topics
  • Building EIP-712, signature, Merkle, or storage-slot helpers in JS/TS
  • Reviewing any code that hashes Ethereum data with Node crypto directly

How It Works

The two algorithms produce different outputs for the same input, and Node will not warn you.

import crypto from 'crypto';
import { keccak256, toUtf8Bytes } from 'ethers';

const data = 'hello';
const nistSha3 = crypto.createHash('sha3-256').update(data).digest('hex');
const keccak = keccak256(toUtf8Bytes(data)).slice(2);

console.log(nistSha3 === keccak); // false

Examples

ethers v6

import { keccak256, toUtf8Bytes, solidityPackedKeccak256, id } from 'ethers';

const hash = keccak256(new Uint8Array([0x01, 0x02]));
const hash2 = keccak256(toUtf8Bytes('hello'));
const topic = id('Transfer(address,address,uint256)');
const packed = solidityPackedKeccak256(
  ['address', 'uint256'],
  ['0x742d35Cc6634C0532925a3b8D4C9B569890FaC1c', 100n],
);

viem

import { keccak256, toBytes } from 'viem';

const hash = keccak256(toBytes('hello'));

web3.js

const hash = web3.utils.keccak256('hello');
const packed = web3.utils.soliditySha3(
  { type: 'address', value: '0x742d35Cc6634C0532925a3b8D4C9B569890FaC1c' },
  { type: 'uint256', value: '100' },
);

Common patterns

import { id, keccak256, AbiCoder } from 'ethers';

const selector = id('transfer(address,uint256)').slice(0, 10);
const typeHash = keccak256(toUtf8Bytes('Transfer(address from,address to,uint256 value)'));

function getMappingSlot(key: string, mappingSlot: number): string {
  return keccak256(
    AbiCoder.defaultAbiCoder().encode(['address', 'uint256'], [key, mappingSlot]),
  );
}

Address from public key

import { keccak256 } from 'ethers';

function pubkeyToAddress(pubkeyBytes: Uint8Array): string {
  const hash = keccak256(pubkeyBytes.slice(1));
  return '0x' + hash.slice(-40);
}

Audit your codebase

grep -rn "createHash.*sha3" --include="*.ts" --include="*.js" --exclude-dir=node_modules .
grep -rn "keccak256" --include="*.ts" --include="*.js" . | grep -v node_modules

Rule

For Ethereum contexts, never use crypto.createHash('sha3-256'). Use Keccak-aware helpers from ethers, viem, web3, or another explicit Keccak implementation.

Files1
1 files · 1.0 KB

Select a file to preview

Overall Score

88/100

Grade

A

Excellent

Safety

95

Quality

85

Clarity

92

Completeness

78

Summary

This skill teaches developers to avoid a critical cryptographic mistake in Ethereum development: using Node.js's built-in SHA3-256 (NIST variant) instead of Ethereum's Keccak-256. It explains the difference, provides concrete examples across three major libraries (ethers, viem, web3.js), and includes patterns for common use cases like function selectors, storage slots, and address derivation. The skill is read-only and educational — it does not write code or execute commands.

Detected Capabilities

code pattern matchingeducational guidanceread-only file audit

Trigger Keywords

Phrases that MCP clients use to match this skill to user intent.

ethereum keccak hashingavoid sha3 mistakefunction selector hashmerkle tree ethereumstorage slot calculationaddress from public key

Use Cases

  • Verify Ethereum hash computations in JavaScript projects
  • Fix silent cryptographic failures in smart contract interaction code
  • Audit codebases for incorrect Node crypto usage in Ethereum contexts
  • Build EIP-712 signatures and Merkle trees correctly
  • Derive Ethereum addresses from public keys
  • Compute function selectors and event topics for contract ABIs

Quality Notes

  • Clear explanation of the cryptographic difference with runnable comparison code
  • Three popular library examples (ethers, viem, web3.js) provide multiple implementation paths
  • Common use-case patterns documented: selectors, topics, storage slots, address derivation
  • Includes grep patterns for auditing existing codebases — practical and actionable
  • Well-structured with 'When to Use', 'How It Works', 'Examples', and 'Rule' sections
  • Educational framing ('Never use...') is clear and unambiguous
  • No ambiguity about which patterns are wrong — the rule is explicit
Model: claude-haiku-4-5-20251001Analyzed: Jul 14, 2026

Reviews

Add this skill to your library to leave a review.

No reviews yet

Be the first to share your experience.

Version History

v1.2

Content updated

2026-07-14

Latest
v1.1

Content updated

2026-04-20

v1.0

No changelog

2026-04-12

Use affaan-m/nodejs-keccak256 in your dev environment

Command Palette

Search for a command to run...