Twofish is a symmetric-key block cipher designed by Bruce Schneier and his team in 1998 as the successor to Blowfish. It encrypts data in 128-bit blocks with keys of 128, 192, or 256 bits, and was one of the five finalists in NIST’s competition to select AES. Twofish is unpatented, free to use, and still considered secure.
Twofish is a symmetric-key block cipher created by Bruce Schneier and his team as the successor to Blowfish. It encrypts data in 128-bit blocks using keys of 128, 192, or 256 bits, and was one of the five finalists in NIST’s competition to choose the Advanced Encryption Standard (AES). Although Rijndael won and became AES, Twofish remains unbroken and secure. It is unpatented and free to use.
Key Takeaways
- Twofish is a symmetric-key block cipher (128-bit block; 128, 192, or 256-bit keys) designed by Bruce Schneier and team.
- It succeeded Blowfish and was one of the five AES finalists; Rijndael won and became AES in 2001.
- Twofish is unpatented, license-free, and in the public domain, so anyone can use it without royalties.
- It is still considered secure: there is no practical attack on the full cipher, though it is far less used than AES.
- As a symmetric cipher, Twofish is quantum-resistant: Grover’s algorithm only halves its strength, so Twofish-256 keeps roughly 128-bit security against quantum attacks.
What Is Twofish?
Twofish is a symmetric-key block cipher, meaning the same key encrypts and decrypts, and it processes data in fixed-size blocks. It was developed by Bruce Schneier and a team at Counterpane as the successor to the earlier Blowfish cipher, in response to the need to replace the aging Data Encryption Standard (DES). In 1997, NIST launched an open competition to select a modern replacement for DES, addressing the criticism that DES had been designed behind closed doors.
NIST’s criteria called for a 128-bit block cipher supporting key lengths from 128 to 256 bits, with no weak keys, a clean design that is easy to analyze, and good performance on a wide range of platforms, including low-power devices. Twofish met all of these, using a 16-round Feistel structure with key-dependent substitution boxes (S-boxes). It became one of the five finalists, alongside Rijndael, Serpent, RC6, and MARS. NIST selected Rijndael as AES in 2000 (standardized in 2001), but Twofish was widely respected for its strong security margin.
Twofish Is Free to Use
Unlike some ciphers, Twofish was deliberately placed in the public domain by its designers. It is unpatented, license-free, and carries no royalties or usage restrictions. This was a selling point during the AES competition and remains one today: any developer or product can implement Twofish freely. (The earlier article listed possible ‘legal caution’ as a disadvantage, but there is no patent to worry about, Twofish has always been free.)
Is Twofish Secure?
Yes. Twofish is still considered a secure cipher. In the decades since its release, no practical cryptanalytic attack has been found against the full 16-round algorithm. The theoretical results that exist apply only to reduced-round variants or specific conditions and do not threaten real-world use. Its large security margin was one reason it reached the AES final round. That said, it is not without practical considerations:
- Side-channel attacks: Like most ciphers, a careless implementation can leak information through timing or power analysis. This is an implementation issue, not a flaw in the algorithm, and is mitigated by constant-time, side-channel-resistant coding.
- Implementation complexity: Twofish’s key-dependent S-boxes and Feistel structure make it more complex to implement correctly than some ciphers, so careful, well-reviewed code matters.
- Performance and adoption: Twofish performs well in software and hardware, but modern CPUs include dedicated AES acceleration (AES-NI) that Twofish does not benefit from, so AES is usually faster in practice. This, plus AES winning standardization, is why Twofish is far less widely deployed.
In short, Twofish is secure but niche. It appears in tools like GnuPG (OpenPGP) and disk-encryption software such as VeraCrypt, where it is offered as a strong alternative or complement to AES, but it never achieved AES’s ubiquity.
Twofish vs AES
Because Twofish and AES (Rijndael) competed head-to-head, the natural question is how they compare:
| Aspect | Twofish | AES (Rijndael) |
| Type | Symmetric block cipher | Symmetric block cipher |
| Block size | 128-bit | 128-bit |
| Key sizes | 128, 192, 256-bit | 128, 192, 256-bit |
| Structure | 16-round Feistel, key-dependent S-boxes | Substitution-permutation network |
| Standardization | AES finalist (not selected) | Selected as AES (FIPS 197, 2001) |
| Hardware acceleration | None built into CPUs | AES-NI on modern CPUs (much faster) |
| Adoption | Niche (GnuPG, VeraCrypt) | Global standard, near-universal |
| Security status | Secure, no practical break | Secure, no practical break |
Both are strong, unbroken ciphers with the same block and key sizes. The practical difference is ecosystem: AES is the standard, is supported everywhere, and runs faster thanks to CPU acceleration, so it is the default choice. Twofish remains a solid, freely available alternative.
Is Twofish Quantum-Safe? The 2026 Outlook
Twofish is in a strong position for the quantum era, for the same reason AES is. As a symmetric cipher, it is not threatened by Shor’s algorithm, which breaks public-key algorithms like RSA and ECC but does not apply to symmetric encryption. The only relevant quantum attack is Grover’s algorithm, which speeds up brute-force key search, effectively halving a cipher’s key strength. In practice, that means Twofish with a 256-bit key retains roughly 128 bits of security even against a future quantum computer, which is considered safe. So while the post-quantum transition urgently affects public-key cryptography (where NIST finalized ML-KEM, ML-DSA, and SLH-DSA in 2024, and plans to retire RSA and ECC by 2030 to 2035), strong symmetric ciphers like Twofish-256 and AES-256 remain quantum-resistant and do not need replacing. The main guidance is simply to use a 256-bit key.
How Encryption Consulting Helps
Whether you use AES, Twofish, or a mix of algorithms, the important thing is knowing what is deployed where and whether it is configured securely. Encryption Consulting’s Encryption Advisory Services assess your cryptographic posture, inventory the algorithms and key sizes in use, identify weak configurations or implementations, and align everything to standards like NIST and FIPS 140-3, including planning for the post-quantum transition of your public-key cryptography. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.
Frequently Asked Questions
What is Twofish?
Twofish is a symmetric-key block cipher designed by Bruce Schneier and his team as the successor to Blowfish. It encrypts data in 128-bit blocks using keys of 128, 192, or 256 bits, built on a 16-round Feistel structure with key-dependent substitution boxes. Twofish was one of the five finalists in NIST’s competition to select the Advanced Encryption Standard (AES). It is unpatented, free to use, and still considered secure, though it is far less widely deployed than AES.
Is Twofish secure?
Yes. Twofish is still considered secure. In the decades since its release, no practical cryptanalytic attack has been found against the full 16-round cipher. The theoretical results that exist apply only to reduced-round versions and do not affect real-world use. Its large security margin helped it reach the AES final round. The main practical considerations are implementation quality (avoiding side-channel leaks) and performance, since modern CPUs accelerate AES but not Twofish.
Why did Twofish lose to AES?
Twofish was one of five AES finalists, but NIST selected Rijndael, which became AES, in 2000. The decision was not because Twofish was insecure; all finalists were strong. Rijndael was chosen largely for its combination of security, speed, and simplicity across a wide range of hardware and software. Twofish is somewhat more complex to implement, and after AES became the standard, CPUs added dedicated AES acceleration, which cemented AES as the faster, more widely supported default.
What is Twofish used for?
Twofish is used as a strong, freely available alternative to AES in various security tools. It appears in GnuPG (the OpenPGP implementation) and in disk-encryption software such as VeraCrypt, sometimes chained with other ciphers for added assurance. Because it is unpatented and royalty-free, developers can implement it without licensing concerns. However, it is niche compared with AES, which dominates because it is the standard and benefits from hardware acceleration.
Is Twofish better than AES?
Neither is clearly better; both are secure, unbroken block ciphers with the same 128-bit block and 128, 192, or 256-bit key sizes. AES is the global standard, is supported almost everywhere, and runs faster because modern CPUs include AES hardware acceleration, which makes it the practical default. Twofish is an equally strong alternative that is unpatented and freely available, but it is far less widely deployed and lacks hardware acceleration, so AES is usually the better practical choice.
Is Twofish quantum-safe?
Largely, yes. As a symmetric cipher, Twofish is not threatened by Shor’s algorithm, which breaks public-key algorithms like RSA and ECC but does not apply to symmetric encryption. The only relevant quantum attack is Grover’s algorithm, which halves effective key strength, so Twofish with a 256-bit key retains roughly 128 bits of security against a quantum computer, which is considered safe. Using a 256-bit key keeps Twofish quantum-resistant, just as it does for AES.
Get Clarity on Your Encryption
Whether you rely on AES, Twofish, or both, knowing what is deployed and whether it is quantum-ready is what matters. Explore Encryption Consulting’s Encryption Advisory Services to inventory your cryptography and build a roadmap to post-quantum readiness.
