Skip to content
clickidy
🎯 ALL GAMES
STORIES

TRUE STORIES
BEHIND THE CODE.

Every cipher on this site has a real history - codebreakers, spies, and the world's most famous unsolved and partially-solved codes. 17 true stories, verified against primary sources.

Codes & Ciphers History ◢

The codebreakers, spies and unsolved mysteries behind the ciphers · 17 stories

STORYBletchley Park

How Britain broke Enigma and Lorenz - Turing, the Bombe, Ultra, and the first electronic computer.

STORYNavajo Code Talkers

The unbroken WWII code built from a spoken language, plus a verified code-word reference table.

STORYDead Drops

How two spies trade secrets without ever meeting - the cache, the signal, and the nickel that gave it away.

STORYInvisible Ink

How secret writing actually works, from lemon juice to reagent inks, and the cases that ended it.

STORYDecoder Ring History

It was never a ring. The real story behind Little Orphan Annie's badge - and the cipher inside it.

STORYLeo Marks & the SOE

The 22-year-old cryptographer who replaced a fatal memorised poem with a key printed on silk.

STORYVoynich Manuscript

A 600-year-old illustrated book in a script nobody has ever translated.

STORYKryptos

A CIA-courtyard sculpture with four encrypted panels - three solved, one still standing.

STORYCicada 3301

The anonymous internet puzzle that sent solvers chasing posters on four continents.

STORYThe Somerton Man

DNA gave a likely name in 2022. The pencilled code in the book found with him is still unsolved.

STORYThe Beale Ciphers

One cipher describes a buried fortune nobody has found. The other two have never been broken.

STORYThe Zodiac Ciphers

A schoolteacher couple broke the first in a week. The second took 51 years. Two remain.

STORYRohonc Codex

A 448-page illustrated manuscript in an unknown script, unread for over 150 years.

STORYThe Dorabella Cipher

Elgar's 87-character note to a close friend - she never cracked it, and nor has anyone else.

STORYRicky McCormick's Encrypted Notes

The FBI's own codebreakers couldn't solve it, so in 2011 they asked the public instead.

STORYThe Olivier Levasseur Cryptogram

A real 18th-century pirate, a real execution, and 300 years of treasure legend.

STORYThe D'Agapeyeff Cipher

A 1939 textbook challenge cipher its own author later admitted he forgot how to solve.

Try the ciphers these stories are about →

THE SHORT ANSWER ◢

A ciphertext stays unread for one of four reasons, and they are not variations on a theme. It can be too short for any answer to be provably the right one. Its key can be lost, or can never have been written down. It can turn out to mean something without ever having been enciphered. Or there may be no message inside it at all.

Difficulty hardly figures. The famous unsolved cipher is almost never a puzzle that has beaten everybody by being clever. It is usually a puzzle that cannot be settled by anybody, because the evidence needed to settle it is not there.

The first of the four causes is the one that comes with a number attached, and Claude Shannon attached it in 1949. Everything that follows rests on that number, so it comes first here.

Key Takeaways

  • Shannon named the threshold unicity distance: the length at which a cryptogram stops supporting a family of plausible answers and starts supporting exactly one.
  • The threshold moves with the cipher system. For simple substitution he put it near 27 letters; for a mixed-alphabet Vigenere with d alphabets, about 53d.
  • A perfectly keyed message is not merely hard. Shannon proved that a random key as long as the message leaves the analyst exactly where they started.
  • Length is necessary and not sufficient: two of the three Beale ciphers run to hundreds of numbers and remain unread because nobody can name the key text.
  • A text with no message and a text whose system nobody has guessed produce identical evidence, which is why hoaxes are so hard to prove either way.

How much ciphertext a solution needs before anyone can trust it

Shannon published Communication Theory of Secrecy Systems in the Bell System Technical Journal in October 1949. Section 14 names the point at which a cryptogram acquires a single answer, the unicity distance, and sizes it for an idealised cipher in one line: "For the random cipher it is approximately H(K)/D."

H(K) measures the size of the key space, so more possible keys push the threshold up. D is the redundancy of the language, the statistical pattern that makes English English, and it works the other way: the more predictable the plaintext, the fewer characters are needed before only one key can produce something that looks like it. Redundancy is what a cryptanalyst spends, and below the threshold there is not enough of it to spend.

Applied to the classical systems, the answers spread widely.

Cipher system Ciphertext needed before a solution is unique Where Shannon gives it
Simple substitution, random key About 27 letters Section 15, p. 695
Transposition of period d, random key About 1.7d log(d/e) letters Section 15, p. 695
Vigenere of period d About 2d letters Section 15, p. 695
Mixed-alphabet Vigenere, d alphabets mixed independently About 53d letters Section 15, p. 698

For the simplest system in that table he also reports the experiment, and it is worth having in his own words: "With 30 letters there is nearly always a unique solution to a cryptogram of this type and with 20 it is usually easy to find a number of solutions." Ten letters is the whole span between the two regimes.

So there is no single length at which a cryptogram becomes solvable. The bar depends on the system you believe was used, and with an unread text nobody knows what that was. Shannon closed the argument in section 16, on whether an alleged solution is genuine: "If the material is of the same order or shorter than the unicity distance the solution is highly suspicious." His two examples were the Bacon-Shakespeare ciphers and the manuscript he called the Roger Bacon manuscript, better known now as the Voynich.

The threshold tested against a real cipher

Shannon's threshold is not confined to idealised ciphers. Joachim von zur Gathen modelled the actual scheme behind the Zodiac Killer's 340-character cryptogram, substitution and sectioning and transposition and deliberate misspellings together, and concluded that the "unicity distance of the Zodiac-340 cipher is at most 152". The cryptogram is 340 characters, so it clears its own bar by more than double. The same arithmetic condemns the killer's two short cryptograms, of which the team that broke the long one write that "there is no known test that can scientifically falsify or validate candidate solutions". Under the bar there is no test, which is a different condition from unsolved.

One caveat travels with the number. Shannon states the result for ciphers rather than codes, and a codebook, where whole words are replaced by arbitrary groups, does not obey it. A short message in an unrecovered code can be unreadable forever without being remotely difficult.

The lost key, and why length cannot rescue an unsolved cipher

The second cause is the one people underestimate, because it is not a difficulty at all. Some ciphertexts are not hard. They are empty.

Shannon defined perfect secrecy in section 10 as the condition that seeing the cryptogram leaves the analyst's probabilities exactly as they were: "intercepting the message has given the cryptanalyst no information." He then showed the condition is achievable and, on page 682, named the system that achieves it: "This type of perfect secrecy is realized by the Vernam system." He means a random key at least as long as the message. Against that, effort buys nothing: every plaintext of the right length stays exactly as likely as it was before the ciphertext arrived.

Real cases are messier and end in the same place. The Beale ciphers are the standing example, and the 1885 pamphlet that carries them says outright what went wrong. Beale's letter promises a key held by a third party: "Such a key I have left in the hands of a friend in this place, sealed, addressed to yourself, and endorsed not to be delivered until June, 1832." The pamphlet's anonymous author records the outcome in one clause: "the promised explanation has never been received".

Length did not help. Cipher No. 1 runs to 520 numbers and cipher No. 3 to 618, both far past any of Shannon's thresholds for a simple system, and both are unread. The middle cipher fell by accident, which is the pamphlet's own word for it: its author describes "the delight he experienced when accident revealed to him the explanation of the paper marked" number two, keyed as it turned out on the Declaration of Independence. His advice to readers is that "accident alone, without the promised key, will ever develop the mystery". That accident has never repeated, and the full account of the three Beale ciphers is a record of it not repeating. A book cipher's key space is the set of books in the world, and no quantity of ciphertext narrows it.

When an unsolved cipher is not a cipher at all

Shannon opens his paper by dividing the field into three and setting two of the three aside. There are concealment systems, which hide the existence of a message; privacy systems, which need special equipment; and true secrecy systems, where the message is plainly present and only its meaning is hidden. He confines himself to the third, remarking that concealment is "primarily a psychological problem".

That discarded category is where several famous unread texts may belong, and cryptanalysis is the wrong instrument for all of it. If the marks on a page are the initial letters of remembered words, no key exists, no system was applied, and there is nothing for frequency analysis to bite on. The text means something. It was simply never encrypted.

The Somerton Man's letters are the clearest candidate. Student teams at the University of Adelaide worked down a list of candidate schemes, striking off the classical ciphers they could eliminate, and the list itself carries two entries that are not ciphers at all: the initial letters of a sentence, and the initial letters of an unordered list. They then attacked it from the other end, comparing the letter frequencies against the initial letters of words in translations of the Universal Declaration of Human Rights, in the 266 languages for which a usable text could be assembled. Their 2013 report states the finding plainly: "The English Language statistically fits the best for the code assuming it is the initial letters of words in a sentence or list."

An initialism made by one person for their own use is not breakable, because there is nothing in it to break. No key was ever chosen, so none can be recovered, and the only route to the meaning runs through whoever held the words in their head.

The diagnostic problem underneath is easy to state and hard to solve. Statistics can show that a text is not a random scatter of letters, and can rule out particular systems one at a time. Neither of those is a demonstration that a system was ever used. Not random is not the same as enciphered.

Hoaxes, and why they are so hard to prove

The fourth cause shares a parent with the third rather than sitting beside it, because neither text was ever enciphered. What separates them is meaning: the Somerton Man's letters stand for words somebody had in mind, and a hoax stands for nothing. The trouble is that a hoax and a system nobody has guessed leave exactly the same trace, which is years of failure. Absence of a solution is not evidence of absence of a message, and the reverse inference is no better.

Shannon was interested in the mirror image of that error. Section 16 exists because analysts had repeatedly produced solutions to material too meagre to support one, and his rule of thumb is a test for reading a solution into a text rather than out of it. A hoaxer and an over-eager solver work the same seam from opposite ends.

Physical evidence constrains a hoax without closing the question. Radiocarbon dating of the Voynich parchment at the University of Arizona put the pages in the early fifteenth century, the laboratory narrowing the range to 1404 to 1438, and the same report notes the pigments were consistent with the palette available then. That kills one hoax hypothesis, since the manuscript cannot have been fabricated by its modern discoverer, and leaves another intact: a genuinely fifteenth-century object can still have been filled with meaningless script by a fifteenth-century hand.

Nor does meaninglessness settle the other question, which is the trap in this whole subject. Greg Hodgins, the physicist who dated the parchment, points out that a text can be mostly meaningless and enciphered at once: "There are types of ciphers that embed meaning within gibberish. So it is possible that most of it does mean nothing." He is describing a grille, a sheet with holes cut in it laid over the page so that only the letters showing through are read. Under a grille, filler is the design. So a finding that most of a text means nothing is no argument that the Voynich carries no cipher, and Yale's Beinecke Rare Book and Manuscript Library still catalogues Beinecke MS 408 as a "Scientific or magical text in an unidentified language, in cipher", while recording that "for the most part the text remains an unsolved puzzle".

That is the usual shape of a hoax test. It narrows the window and rarely shuts it, which is why the honest verdict on several of these texts is neither solved nor unsolved but undetermined.

What actually opens an unsolved cipher

Only a handful of things do, and cleverness on its own is not one of them: more ciphertext, a crib that pins some plaintext in place, the key, or the maker's working papers. Each of those adds evidence from outside the ciphertext. Nothing that stays inside it can help, because the shortage of evidence is the whole problem.

The Zodiac Killer's 340-character cryptogram fell because it was long enough for an outside party to check the answer, and the FBI did. His two short cryptograms sit under the bar and will stay there. The state of the Zodiac ciphers sets out both.

Then there is the case where the key exists and is simply withheld. The CIA's account of the Kryptos sculpture in its own courtyard records that the artist "designed the fourth section (now referred to as K4) to be very difficult to crack and as of yet, it has not been broken". Ninety-seven characters, and no released key. That is the lost-key case with the loss made deliberate, and it is the only version of any of this where the answer is known to exist.

Frequently asked questions

Why are some codes and ciphers still unsolved?

Usually for one of four reasons, none of which is the attacker's skill. The ciphertext can be too short for any candidate answer to be provably unique, which is Shannon's unicity distance. The key can be lost or was never recorded. The text may mean something without ever having been enciphered, so cryptanalysis is the wrong tool. Or it may carry no message at all.

What is unicity distance, in plain terms?

It is the amount of ciphertext at which a cryptogram stops having several sensible readings and starts having one. Claude Shannon defined it in 1949 as the size of the key space divided by the redundancy of the plaintext language. Below that length, different keys each produce plausible messages and the text cannot decide between them; above it, a plausible reading is very likely to be the only one.

Can a very short cipher ever be solved for certain?

Not from the ciphertext alone. Shannon's own test is that a solution to material shorter than the unicity distance is highly suspicious, and short cryptograms admit many sensible readings by construction. Certainty for a short cipher has to come from outside the text, such as a confirmed crib, the maker's working papers, or a documented key.

Are most unsolved ciphers hoaxes?

There is no way to establish that, which is the point. A text with no message and a text whose system nobody has guessed produce the same evidence, namely repeated failure, so the absence of a solution supports neither conclusion. Physical tests narrow the possibilities, as radiocarbon dating did for the Voynich manuscript, but they rarely settle whether the writing ever meant anything.

How can anyone tell whether an unread text is enciphered at all?

Only imperfectly. Statistical tests can show that letters are not randomly scattered and can rule out particular systems one by one, which is how the University of Adelaide teams worked through the Somerton Man's letters. What no test does is prove that a system was used. Not random is not the same as enciphered, and an initialism, a personal shorthand or a private mnemonic will pass many of the same checks.

Sources

  • Claude E. Shannon, Communication Theory of Secrecy Systems, Bell System Technical Journal 28(4), October 1949, pp. 656 to 715. Section 1 for the three types of secrecy system, p. 656; section 10 for perfect secrecy and the Vernam system, pp. 679 to 682; section 14 for the definition of unicity distance, p. 693; section 15 for the estimates in the table, pp. 695 and 698; section 16 for the test of an alleged solution, p. 698 - retrieved 13 August 2026, archive.org
  • Joachim von zur Gathen, Unicity distance of the Zodiac-340 cipher, IACR Cryptology ePrint Archive 2021/1620, 12 December 2021, later published in Cryptologia. Section 2 for the statement of Shannon's criterion, section 8 for the bound quoted here - retrieved 13 August 2026, eprint.iacr.org
  • David Oranchak, Sam Blake and Jarl Van Eycke, The Solution of the Zodiac Killer's 340-Character Cipher, arXiv:2403.17350, 26 March 2024, later in Cryptologia. Section 5 for the FBI's independent verification of the 2020 solution, section 6 for the unicity discussion, section 8.2.1 for the short cryptograms - retrieved 13 August 2026, arxiv.org
  • Barbara A. Shailor, Beinecke MS 408, in Medieval and Renaissance Manuscripts in the Beinecke Library, Yale University. The catalogue description and the note on claimed decipherments - retrieved 13 August 2026, pre1600ms.beinecke.library.yale.edu
  • Daniel Stolte, UA Experts Determine Age of Book Nobody Can Read, University of Arizona University Communications, 9 February 2011. Hodgins on grille ciphers and on the pigments; the dating range is in the article's own photograph caption - retrieved 13 August 2026 from the Internet Archive capture of 20 January 2013, the uanews.org domain having been retired, web.archive.org
  • University of Adelaide, School of Electrical and Electronic Engineering, Semester B Final Report 2013, cipher cracking, for the language comparison and the initial-letters conclusion, and its Cipher Cross-off List, for the candidate schemes including the two that are not ciphers - both retrieved 13 August 2026
  • The Beale Papers (Lynchburg, 1885), Wikisource transcription in full. Beale's letter of 9 May 1822 for the sealed key; the anonymous author's introduction for the accident and for the key's non-arrival; the printed ciphers, whose numbers were counted for this piece as 520 in No. 1 and 618 in No. 3 - retrieved 13 August 2026, en.wikisource.org
  • Central Intelligence Agency, Kryptos Sculpture, for the four sections and the unbroken fourth - retrieved 13 August 2026, cia.gov