Skip to content
clickidy
🎯 ALL GAMES

READING · 17 MIN

THE SCULPTURE
STILL KEEPING A SECRET.

It sits in a courtyard the public can't normally reach, at the headquarters of the agency whose entire job is breaking other people's codes. Three of its four messages have been solved. The people who work there still can't read the fourth.

An artist, a cryptographer, and 1,735 letters of copper 

Kryptos is a copper, granite and wood sculpture installed in 1990 in a courtyard at CIA headquarters in Langley, Virginia, created by American artist Jim Sanborn with cryptographic help from Ed Scheidt, then chairman of the CIA's own Cryptographic Center. The main copper screen is cut into an S-curve and carries exactly 1,735 letters, but only one side of it is a message: 869 characters, split into four numbered passages the puzzle community calls K1 through K4. The other side is a keyword alphabet table rather than ciphertext - alongside a compass, a Morse-code-like sequence, and other decorative cryptographic flourishes scattered around the courtyard.

Three panels, cracked years apart 

K1 and K2 both use a keyed substitution - closer to a Vigenère cipher than a simple Caesar shift, since each uses its own keyword layered over the alphabet. CIA physicist David Stein solved three of the four sections by hand and told the agency in early 1998, though the CIA didn't make that public at the time; California computer scientist Jim Gillogly independently solved K1 through K3 in 1999 using a program, and published it first. K1 decodes to a sentence about “the nuance of iqlusion” - Sanborn's deliberate misspelling of “illusion,” one of several intentional quirks he's confirmed over the years. K3 uses a completely different method, a columnar transposition that scrambles letter order rather than substituting them, and decodes to a paraphrase of Howard Carter's own diary account of opening Tutankhamun's tomb in 1922.

K4: 97 characters, three decades, no key 

The fourth passage, just 97 characters long, remains unsolved. Sanborn has released a handful of plaintext clues over the years to keep the puzzle honest and fund independent verification of any future solution - in 2010 confirming that six letters decode to “BERLIN,” in 2014 confirming the next five spell “CLOCK” (widely read as a reference to Berlin's public Weltzeituhr or Bahnhof Zoo clock), and in 2020 confirming a further stretch spells “NORTHEAST.” None of the clues has been enough for anyone to reconstruct the underlying key. Puzzle researcher Elonka Dunin has tracked the sculpture and its clues in detail since the 1990s, and her public FAQ remains one of the most cited references for anyone attempting K4. Sanborn, born in 1945, has said publicly he intends to have the full solution authenticated and preserved - likely through an auction house - so the answer survives him even if K4 never falls to a solver first.

Thousands of submitted answers. None confirmed. 

Sanborn has said he's received thousands of proposed solutions since 1990, and rejected every one. That's the part that makes Kryptos different from most famous unsolved ciphers: the person who can confirm a correct answer is alive, reachable, and still checking his email.

Play the ciphers in this story

More Codes & Ciphers history →

WHAT THE RECORDS SHOW 

The first people to read three of the four Kryptos passages were not named in any newspaper. They were cryptanalysts inside the National Security Agency, and they finished in late 1992, more than five years before the first public solution was announced. The NSA released its own paperwork on the episode under the Freedom of Information Act, in May 2013 and again in September 2014, so this is a matter of record rather than folklore.

That file is also the most candid account of the sculpture in existence, because it was never written to be read outside the building. It records a study group that met on its own time, a lucky guess that worked for the wrong reason, a decision to walk away from the fourth passage after a single day, and a mistake that three separate sets of professionals copied for fourteen years.

Key Takeaways

  • An NSA memo dated 9 June 1993 reports that "three of the four cipher systems used to encrypt the sculpture's plain text had been diagnosed and completely exploited", giving "a readability of approximately 89%".
  • A later NSA account puts the in-house work "seven years before these other individuals".
  • The team spent one day on the final passage and stopped, calling it "too short to solve without diverting a great deal of effort from operational problems".
  • The entry point for K3, the transposition passage, was physical: three letters on the copper stand about 1 cm proud of the rest.
  • K2's accepted ending, "ID BY ROWS", was wrong. Restoring one omitted letter turns those eight letters into nine: "X LAYER TWO".

Who solved Kryptos first, according to the NSA's own paperwork

The earliest document in the release is a set of meeting notes dated 18 December 1991. They record the first analytic meeting of a self-assembled "CIA Sculpture Study Group" five days earlier, in a conference room, running "about an hour with all present contributing ideas". The convener is disarming about the branding: "Yes, the group name is arbitrary. If you have a better suggestion please let us know." The notes end with a line that tells you what kind of effort this was. "NOTE: these notes were prepared at NO expense to the US Government."

How the ciphertext got out of Langley at all is in a chronology the NSA compiled in 1998. In 1991, "while on a trip to the CIA headquarters, an informal group comprised mainly of Cryptanalysis interns, handwrites the cipher onto sheets of paper, and distributes it to any and all interested cryptanalysts back at NSA". The following year the work acquired official standing: "Official challenge for solution is relayed through DCI at a Gold Bug award ceremony."

Three analysts then solved the three readable passages, and the chronology gives the order, which is not the order the passages appear in. Going first was the second passage, K2, a polyalphabetic substitution using eight alphabets. K3 followed, "337 characters and employing a transposition system using a matrix with dimensions 4 X 86". The opening 63 characters, K1, went last, another polyalphabetic substitution, this one using ten alphabets. All three names are redacted, and the chronology dates all three solves to 1992.

Set out side by side, the solution sheets attached to the 1993 memo and the chronology compiled in 1998 give this:

Passage Cipher Structure Key Characters Solved at NSA
K1 Periodic polyalphabetic substitution 10 alphabets PALIMPSEST 63 Third
K2 Periodic polyalphabetic substitution 8 alphabets ABSCISSA 373 First
K3 Keyed columnar transposition Grid of 4 rows by 86 columns, read bottom to top KRYPTOS, numbered and repeated 13 times 337 Second
K4 Not established Not established Not established 97 Never

Ciphers, alphabet counts, keys and the grid come from the 1993 solution sheets; the character counts and the solving order come from the 1998 chronology. Those counts are the chronology's own and sum to 870, while the copper carries 869, which is taken up further down.

Structure, not solution, produces the most interesting line in the chronology. The first solver's decryption of K2 "accounts for the last 373 characters from the first section of 436, but the initial 63 characters resist decryption. Because of this, analysts concede that four distinct sections are likely, with this being the second section." Nobody handed them a passage count. The four-part shape everyone now takes for granted was a deduction made from a stretch of letters that would not break.

What the Kryptos memo to the Director actually claimed

The formal write-up went up the chain on 9 June 1993, under the title "CIA KRYPTOS Sculpture - Challenge and Resolution". It reports that "in November, a cadre of cryptanalysts assigned to Z Group enthusiastically responded to the challenge. Within one month, three of the four cipher systems used to encrypt the sculpture's plain text had been diagnosed and completely exploited." A measure of success is attached, and it is a modest one: "The exploitation of the sculpture's first three parts constitutes a readability of approximately 89%. The final 97 characters continue to elude solution."

That November is November 1992. The challenge reached the analysts at the Gold Bug ceremony in 1992, the chronology places all three solves in the same year, and it closes 1992 with "an informal document is produced detailing the solution of the three sections".

The 1998 staff processing form that reopened the file tells the same story with the clock running much faster. "Parts 1-3 were solved within two days of receiving the information", it says, adding that "subsequent analysis and solution, however, did not require any compute power". The two documents do not agree on whether the work took a month or two days, and the file never reconciles them.

Then comes the sentence that explains why the fourth passage is still standing. "Another day was spent on the final section and a decision was made to stop any further work. Given the suspected cryptography, the last section is too short to solve without diverting a great deal of effort from operational problems." The agency with the deepest bench in the world gave K4 one day and reallocated the staff.

The clue was three letters standing proud of the copper

K3 did not fall to statistics. It fell to a defect you can only see standing in the courtyard.

"The 15th line of the cipher begins with the letters END, and of the letters YAHR which follow it, the Y, A, and R are raised up about 1 cm. (about 1/2 inch)", the NSA account notes. "This made analysts at NSA wonder [if] the END was perhaps the end of a certain portion of cipher." The document reads "wonder is" there. The hunch was right. Working backwards from the recovered plaintext, END turned out to be the column nearest the right-hand side of the transposition grid, and YAHR the second column pulled from it, seven columns to its left. That spacing held: "this 'seven columns to the left' property continues throughout the entire process."

END is also worth a second look, because three letters is one short of a full column. Four rows across 86 columns has room for 344 characters and K3 supplies 337, so seven cells sit empty and a handful of columns run three deep instead of four. END is one of the short ones.

Elsewhere in the same document sits the most human admission in the file. The attack was seeded by finding the section's only Q and assuming a U would follow it, which is the standard move. It worked, and then it turned out not to have been true. "Remember how the solution to this portion of the cipher began by placing a U next to the Q? Well, in the solution the Q is not followed by a U. Good luck never hurts when doing cryptanalysis."

That is the awkward thing about a columnar transposition. It hides a message without changing a single letter of it, so the letter frequencies that give away a substitution cipher look perfectly ordinary. Telling one family of cipher from another is the first move in any cipher identification, and on Kryptos more than one family sits on a single sheet of copper.

The eight letters three sets of professionals read wrong

K2 ends with a latitude and longitude, and then, in every solution of it produced for fourteen years, with the phrase "ID BY ROWS". The 1993 memo attaches a note, and the note is an admission of defeat in miniature: "W.W. is presumed to be William Webster. The coordinates refer to the location of or a location within the Central Intelligence Agency. The significance of I.D. BY ROWS remains undetermined."

It remained undetermined because it was not there. On 19 April 2006, Jim Sanborn confirmed to the Kryptos Group that a letter had been left out of the encoding. His verdict on the accepted answer, per the group's announcement, was four words: "No, that last part is wrong." Putting a single cipher letter S back into its place near the end turns those final eight letters into nine, and "ID BY ROWS" becomes "X LAYER TWO". The coordinates are now followed by something that sounds like an instruction.

Everyone sat with the wrong version for a long time, and the NSA write-up is blunt about it. Sanborn's admission "came after seven years of hearing the phrase 'I D BY ROWS,' and assuming all along it was some sort of 'cryppie talk' used by solvers to explain what they had done to reach this point. He never intended the cipher to say that, figuring by omitting a letter, it would merely cause the cipher to decrypt to random letters and not really say anything with meaning." Seven years is the count from the public solutions of 1999; from the NSA's own 1992 solve it is fourteen. As for whether the omission was a slip, the author records the artist's position without endorsing it: "Mr. Sanborn claims that the omitted letter was for 'aesthetic reasons,' refusing to claim any oversight."

A smaller version of the same blindness sits on the face of the 1993 memo. Its letter-by-letter decryption of K1 prints IQLUSION, exactly as the copper gives it. Directly beneath, the "respaced and punctuated" reading prints ILLUSION. Sanborn's oddity was smoothed away in the document that went to the Director. NSA's own later account lists three planted misspellings, one per solved passage: IQLUSION, UNDERGRUUND and DESPARATLY. On this sculpture the errors are load-bearing, and the professional instinct to tidy them is exactly the wrong one.

What the file says about the last 97 characters

A status report on K4 closes the 2014 release, and nobody outside the building would have written it. "For those of us at NSA who've worked on this, and that numbers in the dozens, no one has ever gotten that last part."

What follows is a short list of properties and no solution. Letter frequencies across the 97 characters are described as fairly flat, with one bump: eight of them are K. There are no long repeats. The single structural hint the writer found is a faint tendency for something to recur every seventh character, described as "a slight interval 7 property", and chasing it came to nothing: "I have tried a number of things which might cause an interval 7 property to appear, including Plaintext Autokey and Ciphertext Autokey, but I've yet to stumble upon something that gives either readable plaintext, or hints at the presence of a second encipherment layer." Anyone who has stared at a partly solved cipher will recognise the shape of that paragraph.

One of the better outsider observations is preserved in the file, and then set aside. Between them, the two keywords that drive K1 and K2, ABSCISSA and PALIMPSEST, use eighteen letters, and those letters rearrange exactly into "P.S. It's as simple as ABC", with nothing left over on either side. NSA's response is a shrug: "While that's nice to know, I don't know how it would figure into the actual solution of the fourth part."

The closing line of the document is the honest one, and it is still the state of play. "Work continues in spits and spurts, depending upon time, motivation, and ideas." No solution to those 97 characters has ever been confirmed by the artist.

How much of the Kryptos screen is a message at all

The counts in the record are worth knowing, because the sculpture looks like far more ciphertext than it holds.

The message occupies one side of the curved screen only. "There are 869 characters appearing on this side of the sculpture", the NSA account states. "That count includes the four question marks which are scattered throughout." The other side is not a message. It is a reference table, 28 lines of it, a keyword-mixed alphabet built on the word KRYPTOS with a plain A to Z running along the top and bottom, which is why the CIA can say "the copperplate screen has exactly 1,735 alphabetic letters cut into it" while the encrypted portion is roughly half that.

The record does not quite agree with itself even here. The 1998 chronology states that the three solved passages "comprise the first 773 characters out of 870 total, leaving the last 97 characters unresolved", which is one character more than the 869 counted on the copper. The file offers no explanation for the extra character, and neither will we.

Frequently asked questions

Who solved Kryptos first?

An in-house group of NSA cryptanalysts read the first three passages in late 1992. A memo dated 9 June 1993 reports the result internally, and a later NSA account puts the work "seven years before these other individuals", meaning the two publicly credited solvers. The CIA's own account of the sculpture records that "in early 1998, a CIA physicist announced to the Agency that he had cracked the code for three of the four sections", followed "a year later by a public announcement from a California computer scientist"; the NSA write-up dates the first of those announcements to February 1999 instead. The individual NSA analysts' names are redacted in the released documents.

Did the NSA ever solve K4?

No. A 1998 NSA form records that after the first three passages fell, "another day was spent on the final section and a decision was made to stop any further work", on the grounds that the last section is "too short to solve without diverting a great deal of effort from operational problems". A later internal write-up says that of the dozens of NSA staff who have worked on it, "no one has ever gotten that last part".

What was wrong with the original solution to K2?

One letter was missing from the copper. Every solution of that passage from 1992 until 2006, inside the agencies and outside them, ended with the eight letters "ID BY ROWS", which the NSA's 1993 memo flagged as meaningless: "The significance of I.D. BY ROWS remains undetermined." On 19 April 2006 Jim Sanborn confirmed that a cipher letter S had been left out; restoring it turns those eight letters into the nine of "X LAYER TWO", so the coordinates are followed by a phrase rather than by nonsense.

What ciphers do the solved Kryptos passages use?

K1 and K2 are both periodic polyalphabetic substitutions built on a keyword-mixed alphabet based on the word KRYPTOS, which is also the table cut into the reverse of the screen. The NSA solution sheets give K1 ten alphabets with the repeating key PALIMPSEST, and K2 eight alphabets with the repeating key ABSCISSA. K3 abandons substitution entirely for an incompletely filled transposition grid of four rows and 86 columns, keyed on KRYPTOS and read bottom to top. What K4 uses is not established.

Are the misspellings in Kryptos deliberate?

The NSA write-up treats them as part of the design and lists three, one from each solved passage: IQLUSION, UNDERGRUUND and DESPARATLY. What it does not do is claim to know their function, and the file is careful to keep the three deliberate misspellings separate from the omitted letter in K2, which the artist has said was left out for "aesthetic reasons" rather than by mistake.

If the keyword tables and repeating keys in that file are new to you, the rest of the codes covers the families the sculpture draws on, including the keyed polyalphabetic systems behind K1 and K2, and the other unread ciphers are the company K4 keeps.

Sources