A cryptogram keeps its word spaces, and that is the whole of the weakness. A cipher word standing alone with one letter is almost always A or I. A three-letter word made of three different letters is THE about a third of the time. A word whose letters repeat has a shape, and shapes are rare enough to name a word outright before a single character has been identified.
None of those facts is about the cipher. They are facts about English, and a simple substitution leaves every one of them untouched, because it swaps letters without moving them. Edgar Allan Poe put it in one line in 1841: the basis of the whole art of solution "is found in the general principles of the formation of language itself, and thus is altogether independent of the particular laws which govern any cipher, or the construction of its key".
Take the spaces away and almost all of it evaporates. The puzzle world has a name for each of the two forms, and the difference between them is not a matter of degree.
Key Takeaways
- A simple substitution hides which letter is which, but not where the words end, so word divisions are what an attack without the key actually uses.
- The American Cryptogram Association calls the form with word divisions an Aristocrat and the form set in five-letter groups without them a Patristocrat. Only the first can be attacked by word shape.
- An 1840 newspaper demonstration collapsed a cipher using three short words and no letter counts at all, and its enumeration of every two-letter English word missed IS, AS and WE.
- Armies removed the spaces deliberately, though the two standard manuals disagree about how much it buys. Friedman's 1923 pamphlet lists denying word formations as a reason for five-letter groups; Hitt's 1916 manual calls the gain more apparent than real.
- Shannon put the point where a simple substitution stops having one answer at about 27 letters, tested between 20 and 30.
The rules a puzzle cryptogram still keeps, set in a newspaper in 1840
The conventions were fixed in public, in a Philadelphia weekly, across the winter and spring of 1840. The cipher columns in Alexander's Weekly Messenger are unsigned; they are attributed to Poe on the strength of Clarence S. Brigham's 1942 study for the American Antiquarian Society, which identified them by content and style. Who invented the puzzle, and how much of it Poe really solved, is the story told under the Daily Cryptogram.
The terms he set were narrow. On 26 February 1840 he restated them: he would read any English writing in which arbitrary marks stand in for the ordinary letters, and added, "The same character must always stand for the same letter."
Correspondents broke them constantly, and the complaint that recurs is about the spaces. C. B. "has run all his characters together without interval", which drew the reply that "we made it a condition that the arbitrary letters should be used as the ordinary alphabet". Six weeks earlier the objection had been to a correspondent who had split implement into two words in his own ciphertext and left the punctuation out, and the verdict was flat: "The difficulty of deciphering is, of course, increased."
What is being defended in those complaints is not secrecy. It is solvability. A cipher set without word divisions is a different exercise, and the puzzle world would eventually give it a name of its own.
Thirty two-letter words, then ten, then one
The February column carries the demonstration, and it is still the clearest short account of why boundaries beat frequencies. A correspondent named G. W. Kulp had sent in a cipher. Three of its words did all the work: a two-letter word, a three-letter word that was the same two letters with something inserted between them, and a four-letter word of the shape 1-2-2-3.
The reasoning runs down the sizes. Every two-letter English word was enumerated by brute force, prefixing each vowel to every consonant and then reversing the order, and the count came out at thirty: "There, in fact, are but thirty". One was struck out on positional grounds, leaving twenty-nine. The three-letter word then had to be one of those twenty-nine with a letter pushed into its middle, and only ten survive that test. The four-letter word had to begin with the inserted letter, end with the first letter of the two-letter word, and carry a doubled pair in between. Poe found that one candidate fitted, and concluded that Kulp's cipher was a fabrication rather than a real message.
Three of the shortest words in the message settled it. That is the mechanism, and no amount of counting Es would have produced it.
The enumeration is not actually complete, which is worth knowing because it is the point. Counted directly from the 97,565-word Google Books English word list that Peter Norvig publishes, the list of thirty omits IS, AS and WE, which rank seventh, eleventh and thirty-seventh among all English words. Re-running the deduction with those three restored yields no further consistent reading, so the answer survives the gap. A second claim in the same paragraph does not survive. Poe had already ruled the cipher out on the ground that no English word ends in two doubled pairs, which is the shape of Kulp's VSMUKKSS. COFFEE and COMMITTEE both do.
Neither slip is a failure of the method. They are the reason the tradition stopped enumerating by hand and started publishing word lists. The American Cryptogram Association's own two-letter list runs to 120 entries against Poe's thirty.
Aristocrat and Patristocrat: the two shapes a cryptogram comes in
The association's beginners' guide defines the pair in a line each. An aristocrat is a "simple substitution cipher with word divisions". A patristocrat is "an Aristocrat cipher in 5-letter groups without word divisions". The sample issue of the association's journal puts it from the other end: "Patristocrats are similar in construction to Aristocrats, except that they do not use normal word divisions. They are presented in 5-letter groups."
Its tutorial for new members is candid about why the second exists. As the solving techniques for the first became routine, "another cipher came upon the scene eliminating word divisions". A Patristocrat is not a harder Aristocrat. It is the same enciphered text with its most informative feature deleted.
| Form |
Word divisions |
What an attack can start from |
| Aristocrat |
Kept, along with the punctuation |
Word patterns, one- and two-letter words, an apostrophe, doubled letters |
| Patristocrat |
Removed, the text set in groups of five |
Letter counts, letter pairs, and a crib where one is given |
The tradition concedes the difference in the way it sets the puzzles. A Patristocrat printed in The Cryptogram usually arrives with a crib, a fragment of the plaintext supplied in Caesar-shifted form in parentheses, and the solver's first job is to work out where that fragment fits. Both Patristocrats in that sample issue carry one; the first of its two Aristocrats does not. The Aristocrat is also the form a general reader will have met, being the cipher the association's tutorial describes as the one that "retains word breaks and is seen most often in your local daily newspaper".
The punctuation stays with the spaces, which is why an apostrophe counts as a starting point on one form and not on the other. The two Aristocrats in that sample issue print a full stop, commas, quotation marks, an exclamation mark, and an apostrophe sitting inside a cipher word.
Why the armies took the word spaces out
Military practice went the other way, and the two standard manuals do not agree about what it was worth.
Parker Hitt's Manual for the Solution of Military Ciphers, printed at Fort Leavenworth in 1916, records the practice and gives one reason for it, which is not concealment: "the common practice is to put cipher text into groups of five or ten letters each and eliminate word forms", because an operator who knows a group must hold five letters knows at once when one has been dropped. Hitt is dismissive about what the grouping buys against a professional, writing that the increase in difficulty "is more apparent than real", since an examiner works without word forms as a matter of course.
The same page lets slip what the exception is worth to him: "the occurrence of a cipher with word forms usually means that he has an easy one to handle".
William Friedman's Elements of Cryptanalysis, issued as Training Pamphlet No. 3 by the Office of the Chief Signal Officer in May 1923, states the other reason outright. A footnote gives two grounds for the five-letter group. The first is Hitt's error check. The second is that grouping "breaks up word lengths so that the enemy cryptanalysts gain no clues as to word formations, information which would, of course, be of great assistance to them in their attempts for solution".
Seven years apart, then: both manuals treat word divisions as something the sender destroys as a matter of course, and only the later one calls the destruction a security measure. Neither disputes what the divisions are worth to whoever reads the intercept.
Which family a message belongs to is a separate question, and it comes first. A cipher identifier exists because a transposition and a substitution look equally like nonsense on the page and need entirely different attacks, which is where Hitt's own chapters begin.
What letter frequency finishes, and what it does not
Frequency analysis is the part everybody has heard of, and on its own it is a weak finisher. E is the commonest letter in English by a distance, at 12.49 per cent of the 3,563,505,777,820 letters in the Google Books word counts. The trouble is that a table built from billions of letters describes a long text, and a newspaper cryptogram is about twenty words. The order behind E is not fixed either: a frequency-ordering compilation the association publishes has the Brown corpus and the British National Corpus agreeing letter for letter, while David Copperfield puts H, S and R in a different order again.
The structural facts are sturdier, and they are what pattern-based solving leans on. Counting the Google Books list directly gives the size of each clue.
| Clue in the ciphertext |
What English allows |
How far it narrows the field |
| A word of one letter |
A or I |
86 per cent of one-letter word tokens are A or I |
| A word of three different letters |
THE leads by a distance |
THE is 36 per cent of all such tokens, and 35 per cent of all three-letter word tokens |
| A doubled pair of letters |
LL, SS and EE dominate |
Those three are 54 per cent of doubled-letter pairs, which are themselves two and a half per cent of all letter pairs |
| A six-letter word shaped like PEOPLE |
16 of the 13,341 six-letter words in the list |
PEOPLE accounts for 77 per cent of the times any of the sixteen is used |
That is the arithmetic behind the whole approach. There are 403,291,461,126,605,635,584,000,000 ways to permute an alphabet of 26 letters, and fixing three of them by identifying one common word divides the field by 15,600 in a single step. Do that twice and the puzzle is effectively over.
There is also a floor, and Claude Shannon put a number on it in 1949. Working out how much intercepted text a simple substitution needs before it has only one reading, he reported that "the unicity point, at about 27 letters, can be shown experimentally to lie between the limits 20 and 30. With 30 letters there is nearly always a unique solution to a cryptogram of this type and with 20 it is usually easy to find a number of solutions." Below that a message is not hard, it is genuinely ambiguous, and no method recovers what the text never carried. Shannon put the same kind of floor under the other systems in the same paper, giving the Vigenère a unicity point at about twice its key length, so the shortfall belongs to the cipher rather than to whoever is attacking it. The rest of that family is at codes and ciphers.
Frequently asked questions
Why do cryptogram puzzles keep the word spaces if that is what makes them solvable?
Because a puzzle is set to be solved. Word divisions were a condition of Poe's 1840 newspaper challenge, and he objected in print when correspondents ran their characters together or split a word in two; the American Cryptogram Association still sets its Aristocrats with the spaces and the punctuation left in place. Removing them is a real option and the association has a separate name for the result, the Patristocrat, which it usually publishes with a crib to compensate. Military practice went the other way for a different reason, and the two standard manuals disagree about how much it bought.
What is a Patristocrat?
A Patristocrat is a simple substitution cipher written out in five-letter groups with the word divisions removed. The American Cryptogram Association's beginners' guide defines it as "an Aristocrat cipher in 5-letter groups without word divisions", so the enciphering is identical to an Aristocrat's and only the presentation changes. That change deletes every word shape a solver would normally start from, which is why The Cryptogram usually supplies a crib with the ones it prints.
What can you still attack in a cryptogram with no word spaces?
Letter counts, letter pairs and a guessed word. The groups of five are arbitrary, so nothing marks where the real words begin and end, and every technique that starts from a one-letter word, a doubled letter in a known position, an apostrophe or a word pattern loses its anchor. What survives is statistical rather than structural, and it is slower: the frequency of each cipher letter, the frequency of each pair, and the hope of placing a probable word somewhere in the text.
Is letter frequency enough to solve a cryptogram?
Rarely on its own, and never reliably on a short one. Frequency tables describe long stretches of text, and a puzzle cryptogram of twenty or thirty words is far too short for its letter counts to settle into the expected shape. Frequency is also unstable below the first few places: E leads in every English count, but the order of the letters behind it shifts with the kind of text counted. Frequency narrows the field, and word structure closes it.
How short is too short for a cryptogram to have one answer?
About twenty letters. Claude Shannon's 1949 paper on secrecy systems places the unicity point for a simple substitution at roughly 27 letters, tested experimentally between 20 and 30, and reports that at 30 letters there is nearly always a unique solution while at 20 it is usually easy to find several. A message below that length can be turned into readable English by more than one alphabet, and nothing in the message itself can choose between them. That is a property of the text, not a limitation of any particular solver.
Sources
- Edgar Allan Poe, "Our Puzzles Once More", Alexander's Weekly Messenger, 26 February 1840, p. 4, cols. 3-5 and p. 2, col. 4, and "Enigmatical", 15 January 1840, p. 2, col. 4, transcribed by the Edgar Allan Poe Society of Baltimore - retrieved 13 August 2026
- Clarence S. Brigham, "Edgar Allan Poe's Contributions to Alexander's Weekly Messenger", Proceedings of the American Antiquarian Society, vol. 52, April 1942, pp. 45-125, which reprints the newspaper text quoted above. Reissued as a separate in 1943 with different pagination, which is why the same study is cited elsewhere with a 1943 date - retrieved 13 August 2026
- Edgar Allan Poe, "A Few Words on Secret Writing", Graham's Magazine, vol. 19, July 1841, pp. 33-38 - retrieved 13 August 2026
- American Cryptogram Association, Beginner's Guide to the American Cryptogram Association by Code Penguin, definitions of aristocrat, patristocrat and pattern words - retrieved 13 August 2026
- American Cryptogram Association, Tyro Tutorial by LIONEL, chapter 6 for the Aristocrat and chapter 10 for the Patristocrat and its Caesar-shifted crib - retrieved 13 August 2026
- American Cryptogram Association, sample issue of The Cryptogram, for the Aristocrat and Patristocrat departments as they are actually set, punctuation and cribs included - retrieved 13 August 2026
- American Cryptogram Association, published word lists, whose
dict list is split by word length and holds the 120 two-letter entries counted above - retrieved 13 August 2026
- American Cryptogram Association, letter-frequency orderings by corpus, covering the Brown corpus, the British National Corpus and six novels - retrieved 13 August 2026
- Parker Hitt, Manual for the Solution of Military Ciphers, Press of the Army Service Schools, Fort Leavenworth, 1916, chapter II for the grouping practice and pp. 95-96 for the note on word forms - retrieved 13 August 2026
- William F. Friedman, Elements of Cryptanalysis, Training Pamphlet No. 3, Office of the Chief Signal Officer, War Department, May 1923, footnote to p. 14 - retrieved 13 August 2026
- C. E. Shannon, "Communication Theory of Secrecy Systems", Bell System Technical Journal, vol. 28, no. 4, October 1949, pp. 656-715, unicity point for the simple substitution at p. 695 - retrieved 13 August 2026
- Peter Norvig, "English Letter Frequency Counts: Mayzner Revisited", and the 97,565-word list distilled from the Google Books Ngrams English 1-grams, version 20120701, which the structural figures above were counted from directly - retrieved 13 August 2026