Skip to content
clickidy
🎯 ALL GAMES

READING · 14 MIN

ITS OWN AUTHOR
REPORTEDLY FORGOT IT.

Most unsolved ciphers stay unsolved because the person who made them died, disappeared, or never explained the rules. This one comes with a stranger story: that its own author forgot how he'd built it. That story is repeated everywhere, and it traces back to a single second-hand report.

A textbook, and a challenge for the reader ◢

In 1939, Alexander D'Agapeyeff published Codes and Ciphers with Oxford University Press, an introductory guide to the subject aimed at general readers. The cartographer label often attached to him comes from a book on maps he co-wrote three years after this one. In the first edition, he included a cipher of his own devising - a block of 395 digits, apparently built from a mix of substitution and transposition, similar in spirit to layering a substitution shift with a reordering step - as a challenge, deliberately withholding the solution.

Nobody solved it. Then, reportedly, neither could he. ◢

No solution to the cipher was ever published, and it resisted attempts by both amateur puzzlers and professional cryptanalysts. The twist came later, and second hand: an interview in which D'Agapeyeff is said to have admitted he could no longer remember the method or key he'd used, reported in a cryptography journal in the 1950s and repeated ever since. Nobody has produced a line of his own saying it. The puzzle did leave Oxford University Press - the 1949 edition was revised and reset at 149 pages, and the challenge did not survive the rebuild - but it never left the shelves, because two American publishers reissued the 1939 text in 1971 and 1974.

Unsolvable, technically, by design accident ◢

That makes the D'Agapeyeff cipher a genuinely unusual case among famous unsolved codes: not a message someone is deliberately hiding, and not a mystery tied to a death or a disappearance - just a puzzle whose answer key, if the story is right, evaporated from the one mind that ever held it.

Play the ciphers in this story

More Codes & Ciphers history →

WHAT THE RECORDS SHOW ◢

Alexander D'Agapeyeff is famous for one page of one book, and almost nothing else about him is widely repeated. The public record is small but real: two books under his name in library catalogues, and two National Archives entries that bear on his own life, a naturalisation certificate and a wartime personnel file. Read alongside the D'Agapeyeff cipher itself, those records pin down most of the familiar story and mark the several places where it stops being documented, including the best-known claim of all, which rests on a single second-hand report.

Key Takeaways

  • Library catalogues record the 1939 Oxford University Press book as plain Codes and Ciphers. The subtitle often quoted with it belongs to a much later reprint.
  • A Special Operations Executive personnel file exists under the name, but nothing openly readable ties it to the author rather than to a namesake.
  • The second edition of 1949 was not a quiet single-page deletion. It was revised and reset at 149 pages.
  • The puzzle stayed in print anyway, because two American publishers reissued the 1939 text in the 1970s.
  • The claim that the author forgot his own method traces back, in the accessible record, only to a 1994 second-hand report of a 1950s journal article, not to anything he is recorded as saying.

Who was Alexander D'Agapeyeff, according to the public record?

Two books appear under the name in the Open Library and Library of Congress records. Codes and Ciphers came from Oxford University Press in London and New York in 1939. Maps, written with E. C. R. Hadfield, followed from the same publisher in 1942.

That order matters, because Gillogly's explanation for how the book came to be written has it the other way around. In a 1994 discussion thread preserved by the American Cryptogram Association, the cryptologist Jim Gillogly wrote that D'Agapeyeff "wrote a cartography book in a series for Oxford University Press, so I assume he was later tapped for this one in the same series". The catalogue dates reverse that sequence. The cipher book came first, and the maps book three years after it.

None of the records consulted here gives him an occupation or a death date. The cartographer label attached to him elsewhere rests on the maps book, which the catalogue dates three years after the cipher book rather than before it.

Every Open Library and Library of Congress record for the 1939, 1971 and 1974 printings gives the title as simply Codes and Ciphers. The longer form, with a subtitle promising a history of cryptography, belongs to a 2006 reprint.

What do the National Archives hold under his name?

Searching the UK National Archives Discovery catalogue for the surname returns a short list. Two entries bear directly on the author's life.

The first is a naturalisation certificate issued on 28 February 1947 to Alexander d'Agapeyeff, recorded as being from Russia and resident in Campden, Gloucestershire. The catalogue spells the surname with a lower-case d. If that is the author, he was still a Russian national when his cipher book appeared, and became a British subject eight years later.

The second is more striking and needs more care. The catalogue lists a file in series HS 9, the personnel files of the Special Operations Executive, for "Alexander D'AGAPEYEFF, born 20.05.1902", covering 1939 to 1946. That is the same organisation whose wartime cipher work is a story in its own right. The series description sets the limit on what the entry proves. Some files in HS 9, it warns, "only contain a very brief note indicating that an individual was considered for service in SOE, but rejected".

No openly readable authority record gives the author's date of birth. So the entry establishes that a man of his name was of interest to SOE. It does not establish that the man who set the cipher worked for it.

The same caution applies to the rest of the list. Discovery also indexes an A. d'Agapeyeff active in British computing from the mid-1960s, a namesake question the catalogue leaves open and the FAQ below returns to.

Where in the 1939 book does the D'Agapeyeff cipher sit?

Robert A. J. Matthews, who has published on the cipher and worked from a first edition, places it on page 158, "the final page of the final chapter, which covers methods of decipherment". He records the whole of the author's framing as one sentence: "Here is a cryptogram upon which the reader is invited to test his skill."

The catalogue record agrees from the other direction: the 1939 printing runs to 160 pages with the bibliography beginning at page 159, so page 158 is the last page of text.

The cipher was therefore not buried in an exercise section. It was the closing gesture of an introductory textbook, offered without a hint about method, key or subject matter.

Did the D'Agapeyeff cipher really vanish from print?

From Oxford University Press, yes. From bookshops, no.

Printing Publisher Extent Bibliography Challenge present
1939, first Oxford University Press 160 pages pages 159 to 160 yes
1949, revised and reset Oxford University Press 149 pages pages 145 to 146, plus an index no
1960 Oxford University Press 149 pages as 1949 no
1971 reissue Gryphon Books, Ann Arbor 160 pages pages 159 to 160 yes
1974 reissue Gale Research, Detroit 160 pages pages 159 to 160 yes

The extents and bibliography ranges come from the catalogue records. The last column does not: no record says whether the challenge is present. For the 1939, 1971 and 1974 printings it follows from the identical 160-page setting, and for 1949 and 1960 from Gillogly's report that the cipher was removed from later editions.

The 1949 record describes the book as "Rev. and reset", with bibliographical references at pages 145 to 146 and an index the 1939 record does not list. That is not a page pulled from an otherwise unchanged book. It is a different setting of a shorter text, and the challenge did not survive the rebuild. Meanwhile the original kept circulating, in two American reissues carrying the 160-page fingerprint of the first edition.

Where does the claim that D'Agapeyeff forgot his method come from?

This is where the trail thins, and it is worth saying so plainly rather than filling the gap.

The earliest accessible statement of it is second hand. In that 1994 thread, Gillogly wrote: "This challenge cipher was removed from later editions; when interviewed he said he no longer remembered how he had done it, according to an article in The Cryptogram." The Cryptogram is the American Cryptogram Association's members' journal, and Matthews' account of the literature dates the relevant pieces to 1952 and 1959. Neither is freely readable online.

Matthews adds a nearby recollection from a different direction. He reports tracking down the author's son, also called Alexander and a past president of the British Computer Society, who remembered amateurs writing to his father with failed attempts, and his father's embarrassment at the fuss. The son could offer nothing about how the cipher was built, and did not think it a hoax.

Both accounts are consistent. Neither is a quotation from Alexander D'Agapeyeff.

What can be read off the ciphertext without solving it?

Quite a lot, and none of it needs a key. Here is the challenge as Matthews reproduces it in his appendix, in the same form as the block circulated in that 1994 thread:

75628 28591 62916 48164 91748 58464 74748 28483 81638 18174
74826 26475 83828 49175 74658 37575 75936 36565 81638 17585
75756 46282 92857 46382 75748 38165 81848 56485 64858 56382
72628 36281 81728 16463 75828 16483 63828 58163 63630 47481
91918 46385 84656 48565 62946 26285 91859 17491 72756 46575
71658 36264 74818 28462 82649 18193 65626 48484 91838 57491
81657 27483 83858 28364 62726 26562 83759 27263 82827 27283
82858 47582 81837 28462 82837 58164 75748 58162 92000

The counts below were recomputed from those groups rather than copied, so every figure can be checked against the block above.

There are 79 groups of five digits, 395 digits in all, ending in a group whose last three digits are zeros. Treat those three as filler and 392 digits remain, which divide into 196 pairs. That is exactly 14 by 14, which is why, Matthews reports, a square transposition has been the standing assumption since Wayne Barker's 1978 article in Cryptologia.

The pairs are also strikingly regular. The first digit of every pair is 6, 7, 8, 9 or 0, with 0 standing in for a tenth digit and appearing just once outside the trailing filler, and the second digit is always 1 to 5. That describes the row and column co-ordinates of a Polybius square, the classical grid that squeezes 26 letters into 25 cells by sharing one of them. Of the 25 co-ordinates such a grid allows, only 18 ever appear. The families it belongs to are laid out in the rest of the codes.

The frequencies fit that reading too. The commonest pair turns up 20 times, about one in ten, and the nine commonest together account for 74 per cent of the text. Matthews gives roughly 70 per cent for the nine commonest letters in English, and treats that closeness as evidence that each pair stands for one letter. He notes separately that the spread of the individual digits stays relatively flat, which he suggests may point to unusual vocabulary or even the deliberate avoidance of the letter E.

That is the difficulty in one line. The counts look like a substitution of English, but if a transposition sits over them, the letter order that would confirm it has already been destroyed.

Frequently asked questions

Has the D'Agapeyeff cipher ever been solved?

No published solution has ever been accepted. Matthews, writing after decades of attempts, called it "arguably the single most famous unbroken public-domain cipher not considered to be a hoax". He sets out possible lines of attack, including brute force across the combined transposition and substitution keyspace and search algorithms scored on letter-pair frequencies, but a keyspace estimate is not a solution, and none of the approaches he describes has produced readable English.

Is the D'Agapeyeff cipher a hoax?

The only family testimony on record says no. The author's son, tracked down by Matthews, did not believe his father had faked it, and Matthews places the cipher among unsolved ciphers "not considered to be a hoax", a category he sets against the ciphers that are, such as the Beale ciphers. The competing suspicion is not fraud but error: Gillogly's view was that the author "was trying to execute a Mirabeau cipher, like a checkerboard with nulls, but botched the encryption in some unknown way". That remains a hypothesis, not a finding.

Which edition of the book do I need to see the cipher?

The 1939 Oxford University Press first edition, or one of the two reissues of it: Gryphon Books in 1971 or Gale Research in 1974. The challenge is documented in the 1939 first edition, and the two reissues reproduce its 160-page setting; the 149-page revision is a different, shorter text, so check the extent in the catalogue record before ordering.

Why has so little been written about the cipher?

Because for most of its life the specialist literature was tiny and hard to reach. Matthews counts very few articles on it, and the ones usually named are two in The Cryptogram in 1952 and 1959 and one by Wayne Barker in Cryptologia in 1978, none of them freely readable. That is why the line about the author forgetting his method is repeated far more often than it is sourced.

Was the author related to the computing pioneer of the same name?

Almost certainly as father and son rather than as one man, though no record consulted says so outright. Matthews reports that the son of the cipher's author was also called Alexander and was a past president of the British Computer Society. The Discovery catalogue separately indexes papers recording an A. d'Agapeyeff active in British computing from the mid-1960s, speaking at that society and writing on its code of conduct. Treat the family link as reported by Matthews rather than as documented by the archive.

Sources