The Birthday Paradox: Why 23 People Are Enough for a Match

At the 2014 World Cup, journalists ran a check on all 32 squads. Each squad had exactly 23 players, and in 16 of the 32, half of them, at least two players shared a birthday. No one had arranged this. It is simply what the number 23 does.
That is the birthday paradox: in a room of 23 people, a shared birthday is more likely than not. There are 365 possible birthdays and only 23 people, so the claim sounds absurd, and that reaction is nearly universal. But the result is not a trick, not a statistical illusion, and not sensitive to fine print. It is a short counting argument, and once you see which count intuition performs instead of the right one, the paradox dissolves into something close to obvious.
The Claim, Stated Carefully
Take 23 people whose birthdays are independent and equally likely to fall on any of 365 days, ignoring February 29 for the moment. The claim is:
The probability that at least two of them share a birthday is 50.7%, slightly better than a coin flip.
Two details matter. First, the claim is about any two people matching, not about matching some particular person. Second, "share a birthday" means the same day of the year, like March 14, not the same day and year. Both details sound minor. One of them, as we will see, is the entire paradox.
The Proof Is Just Counting
The direct question, what is the probability that someone matches someone, is awkward to attack head-on, because matches can happen in many overlapping ways. Probability has a standard move for this: compute the probability that nothing happens, then subtract from 1. For a ground-up tour of why that move is legal, see understanding probability intuitively.
Count the opportunities: 23 people form 253 pairs
A shared birthday is a property of a pair of people. With 23 people, the number of distinct pairs is 23 times 22 divided by 2, which is 253. Each pair, considered alone, matches with probability 1/365, which is tiny. But there are 253 tickets in this lottery, not 22, and certainly not 1. This count is the heart of the whole subject.
Compute the probability that all birthdays are different
Line the people up and add them one at a time. The first person takes some day, freely: probability 365/365. The second person avoids a match if they land on any of the 364 remaining days: probability 364/365. The third must avoid two taken days: 363/365. Each new arrival has one more day to dodge, and the 23rd person must avoid 22 occupied days: 343/365. Since the birthdays are independent, the probability that all 23 are different is the product of all these fractions.
Multiply it out and flip
The product 365/365 times 364/365 times 363/365, all the way down to 343/365, works out to 0.4927. That is the probability of no match at all. So the probability of at least one shared birthday is 1 minus 0.4927, which is 0.5073, just over one half. At 22 people the same product gives 47.6%, still below half. The line is crossed at exactly 23.
That is the entire proof: count the pairs to see why a match is plausible, then multiply 23 fractions to see exactly how plausible. No advanced machinery, nothing to take on faith. Every step is checkable with a calculator.
And the curve keeps climbing fast. At 30 people the probability of a match is 70.6%. At 50 people it is 97.0%. At 70 people it is 99.9%: a shared birthday is all but guaranteed while 295 days of the year are still untouched.
Where Intuition Goes Wrong
The birthday paradox reliably fools people, and it fools them in one specific, diagnosable way: they answer the wrong question.
Hear the puzzle, and your mind quietly substitutes a version starring you. What are the odds someone here matches my birthday? That question really does have a small answer. In a room of 23, there are only 22 other people, each matching you with probability 1/365, and the total probability that anyone matches you is about 6%. If the puzzle were about your birthday, the skeptics would be right.
But the puzzle is about any match. You versus each of the others: 22 pairs. But also person 2 versus person 3, person 7 versus person 19, and every other combination that does not involve you at all: 231 more pairs, for 253 in total. Intuition counts the 22 comparisons it can picture from the inside and is structurally blind to the 231 it is not part of. The paradox is not that probability behaves strangely. It is that a room of 23 people contains eleven times more comparisons than any one person experiences.
There is a tidy way to see how big that gap is. To get a 50% chance that someone matches you specifically, 22 others are nowhere near enough: you need 253 people besides yourself. The number of others needed to match one fixed birthday is the same as the number of pairs among 23 people. That is not a coincidence, it is the two questions being solved by the same arithmetic, and it measures precisely how much the "my birthday" framing undersells the situation.
The Fine Print That Makes the Answer Honest
The calculation assumed 365 equally likely birthdays and no leap day. Both assumptions are false in the real world, so it is fair to ask whether the 50.7% survives contact with reality.
It does, and in fact reality helps. Adding February 29 as a rare 366th day nudges the probability down by a sliver, far too little to move the threshold off 23. Uneven birthdays push the other way: real birth data shows seasonal peaks, with certain months reliably more crowded than others. Any such unevenness makes collisions more likely, because bunching probability onto popular days is exactly what collisions feed on. The uniform model is the hardest possible setting for the paradox, and it clears 50% anyway.
This robustness is worth pausing on, because it is the opposite of how paradox-flavored puzzles usually behave. The Monty Hall problem, for instance, is famously sensitive to its fine print: change what the host knows and the answer changes. The birthday paradox is the sturdy sibling. Every realistic deviation from the textbook assumptions pushes the probability up, so the surprise survives every quibble.
From Party Trick to Breaking Hash Functions
The birthday paradox would earn its keep as a party bet, but it also has a serious job. In cryptography it sets the price of finding collisions, and an entire attack strategy is named after it.
A hash function compresses any input into a fixed-size fingerprint, and security often depends on nobody finding two different inputs with the same fingerprint. Suppose the fingerprints are 128 bits, so there are 2 to the power 128 possibilities, an astronomically large number. Guessing an input that hits one specific fingerprint really does take on the order of 2 to the power 128 attempts, hopeless forever. But an attacker who just wants some collision, any two inputs that agree, is playing the birthday game: generate random inputs, and by the square-root rule, a collision is expected after roughly 2 to the power 64 attempts. That is the birthday attack, and 2 to the 64 is a large number but not a safe one; determined attackers have crossed it.
The paradox, in other words, cuts the effective strength of a hash in half, measured in bits. This is why cryptographers who want 128 bits of collision resistance use hashes with 256-bit outputs: the square root of 2 to the 256 is 2 to the 128, putting even the birthday shortcut out of reach. A pattern that decides how many people you invite to a party also decides how many bits protect your bank connection, and it is the same calculation both times.
Try It, Because It Costs Nothing
Like the best probability results, this one is cheap to test. Any group of about 25 people works: a classroom, an office floor, a team roster, a wedding guest list. Ask everyone's birthday and watch for the match. A single group proves nothing either way, of course. The claim is 50.7%, not certainty, so the bet loses almost half the time.
The persuasive version is repetition. Sports rosters are ideal for this, which is why the World Cup keeps showing up in birthday-paradox articles: squads of 23 are the experiment at exactly the threshold size, pre-assembled and public. Check ten squads and you should expect matches in about five. Or simulate it: a few lines of code assigning 23 random numbers from 1 to 365 and checking for repeats, run ten thousand times, will land within a fraction of a percent of 0.507. The multiply-23-fractions argument makes a precise prediction, the world keeps agreeing with it, and there are few faster ways to feel probability become real.
The Zen of It
The birthday paradox endures because it is a perfect miniature of a general failure mode. Intuition evaluates situations from a single point of view, yours, and in combinatorial situations the single point of view is off by a factor that grows with the crowd. Nothing about randomness is misbehaving. The error is entirely in which question gets silently answered.
And the cure is the same as it always is in probability: refuse to guess, and count. Count the pairs and the plausibility appears. Multiply the fractions and the exact number falls out. The same count then reappears, unchanged, in the design of cryptographic systems, which is the quiet lesson of the whole subject: a probability argument does not know whether it is being used for a bar bet or for securing the internet.
Twenty-three people. Two hundred fifty-three chances. The room was never as empty as it looked.
Common Questions
- What is the birthday paradox?
- It is the fact that in a group of just 23 people, the probability that at least two of them share a birthday is slightly better than 50%. With 30 people it is about 71%, with 50 people about 97%, and with 70 people about 99.9%. It is called a paradox not because the math is disputed, but because the number 23 feels far too small. The result follows from ordinary probability, counting every possible pair of people rather than comparing everyone to one fixed birthday.
- Why is 23 the magic number in the birthday paradox?
- Because 23 people form 253 distinct pairs, and each pair is a fresh chance at a match. The probability that all 253 pairs avoid a collision drops below one half at exactly 23 people: the no-match probability is about 49.3%, so a shared birthday has probability about 50.7%. There is also a neat coincidence hiding in the numbers: 365 times the natural logarithm of 2 is almost exactly 253, which is why the fifty-fifty point lands where it does.
- Why does the birthday paradox feel so wrong?
- Because intuition answers a different question. When you hear the puzzle, you instinctively imagine someone matching your birthday, and in a room of 23 there are only 22 chances of that, roughly a 6% probability. But the actual question is whether any two people match, and that involves 253 pairs, most of which have nothing to do with you. Intuition tracks the 22 comparisons it can picture and completely misses the 231 pairs it is not part of.
- What is a birthday attack in cryptography?
- It is an attack strategy named directly after this paradox. A hash function is supposed to make it hard to find two different inputs with the same output. The birthday paradox says collisions among random values appear after roughly the square root of the number of possible values, not the full number. So a hash with 2 to the power 128 possible outputs can be attacked in roughly 2 to the power 64 attempts, which is why cryptographers size hash outputs to keep even the square root out of reach.
- Does the birthday paradox account for leap years and uneven birthdays?
- The standard calculation assumes 365 equally likely birthdays and ignores February 29, which is rare enough to barely move the result. Real birthdays are not perfectly uniform, in many countries there are seasonal peaks, but this only helps the paradox: any unevenness in the birthday distribution makes collisions more likely, not less. So 50.7% at 23 people is a floor in practice, and the real-world probability is a touch higher.
Enjoyed thinking this through?
Math Zen turns this kind of intuition into daily practice, with adaptive problems across 24 math topics.


