The Zodiac 340 cipher was never one cipher. It was two, stacked, and the outer one contained no letters at all.
Underneath sat a homophonic substitution of roughly the difficulty of the one already broken in August 1969. On top of it sat a rearrangement of the reading order, and that is the layer that held. Fifty-one years of cryptanalysts were solving the right puzzle on the wrong text, because the text they were staring at was not in the order it had been written.
Key Takeaways
- The 340 symbols form a block 20 rows deep and 17 columns wide. Read straight across it is noise. Read down one row and right two columns, wrapping at the edges, and it is English.
- The block is not read as a single unit. It splits into four sections: the first nine rows, the second nine rows, then row 19 and row 20 on their own.
- The tell was statistical and slight. Pairs of symbols repeat more often at a spacing of 19 than at any other spacing: 37 repeats, against an average of 20 across random shuffles of the same symbols.
- Zodiac made two mistakes while writing it out, and both of them made the correct reading order look wrong to software.
- Claude Shannon's unicity distance is why this solution can be checked, and why two of the four ciphers may never be checkable at all.
Four cryptograms are attributed to Zodiac, and each is named for the number of symbols in it. Everything below uses those names.
| Cipher |
Mailed |
Length |
Status |
| Z408 |
31 July 1969, in three parts to three newspapers |
408 characters |
Read by 8 August 1969, except the final 18 characters |
| Z340 |
8 November 1969, to one newspaper |
340 characters |
Read in December 2020 |
| Z13 |
20 April 1970 |
13 characters |
Unread |
| Z32 |
26 June 1970, with a map |
32 characters |
Unread |
What was hiding inside the Zodiac 340 cipher?
Two operations, applied in that order, with the boring one on the bottom.
Write Z340's symbols out as they were mailed and you get a grid 20 rows deep and 17 columns wide. The recovery step, in the solvers' own paper (arXiv:2403.17350, later published in Cryptologia), is what they call a (1, 2)-decimation, and it is short enough to describe completely.
Start at the top left. Write down the symbol you are standing on, move down one row, move right two columns, and wrap around whenever you fall off an edge. Repeat until every cell has been visited. In chess terms it is a knight's move, performed identically 340 times.
The second surprise is that the grid is not walked as one block. It is cut into four sections and each is walked separately: rows 1 to 9, rows 10 to 18, then row 19 alone and row 20 alone. Nine, nine, one, one.
Only after that does the part everyone expected apply. A homophonic substitution replaces each letter with one of several interchangeable symbols, so that counting symbols tells you much less than counting letters would. Z340 draws on 63 distinct symbols to carry 340 characters. Z408 used 54 symbols across the 390 characters that were read.
That ratio is not a footnote. Solvers of this kind work by making small random changes to a candidate key and keeping whatever scores better as English, and the more key there is per character of text, the flatter and noisier that scoring landscape becomes. Counted over Z340's first nine rows alone the ratio is about 0.41, against 0.13 for Z408. That gap is a large part of why software that chewed through look-alike test ciphers could not touch this one.
What finally exposed the reading order?
Repeated pairs, at the wrong distance.
Take any two symbols a fixed number of positions apart and treat that as a pair. Adjacent symbols are pairs at spacing 1, and Z340 has 25 pairs that occur more than once at that spacing. Shuffle the same 340 symbols at random and you get about 20. Nothing there. But step the spacing outwards and something happens at 19: the count rises to 37, the highest of any spacing between 2 and 170.
A high repeat count at a fixed spacing is the fingerprint of a transposition. Symbols that were neighbours in the plaintext have been pushed a constant distance apart, and their pairings survive the move.
It is worth being honest about how thin that signal was. Thirty-four different spacings in that range meet or beat the adjacent-pair count, so 19 was a lead rather than a proof. The solvers' own comparison figures cut both ways too: random shuffles of Z340 average 20 repeats, but artificial ciphers built to imitate Z340's statistics average 34.5. Against the second yardstick, 37 is barely a bump.
The spike was first noted by a member of a Zodiac discussion forum and independently by the Belgian programmer Jarl Van Eycke. It is what drew in the Australian mathematician Sam Blake, who had watched a talk by David Oranchak titled "The Zodiac Ciphers: What do we know, and when do we stop trying to solve them?" Blake spotted that the spacing was not cleanly 19 at all: it wrapped at 18 vertically, which is exactly what a diagonal walk across a grid 17 wide produces.
On 17 May 2020 Van Eycke proposed a transposition that lifted the repeating-pair count from 25 to 42. It did not decode, for reasons that were nothing to do with him and everything to do with two mistakes in the original. The paper's verdict on that moment is blunt: he "had essentially found the needle in the haystack without realizing it."
Why did fifty years of experts miss it?
Because Z408 taught everybody the wrong lesson, and the near misses all pointed the same wrong way.
The FBI's own file shows the assumption at work within weeks. In a cryptanalysis report dated 18 December 1969, the Bureau recorded that Z408's key produced no message from Z340, and that roughly a fifth of the symbols were ones it had not seen before. It had also tried what it called a combination cryptosystem, pairing the substitution with linear and route transposition, along with reading the text backwards, in columns, and in a snake pattern alternating direction row by row. Negative result.
The near miss came forty years later. In 2009 Dan Olson, then chief of the FBI's Cryptanalysis and Racketeering Records Unit, set out a series of observations about the text. Some were sharp: lines 1 to 3 and 11 to 13 show markedly fewer repeated characters than the rest, which is what homophonic substitution does. One was decisive in the wrong direction. Randomness, he noted, was far greater across rows than down columns, which seemed to point away from columnar or diagonal transposition.
The transposition was diagonal.
That is the shape of the whole 51 years, and it was not a case of nobody trying transposition. A 2013 result argued Z340 could not be purely homophonic, since ciphers built to imitate its statistics were falling to software while this one would not, and academic attempts in 2014 and 2016 both assumed a substitution and transposition mix. Everyone was circling. But four sections walked on a knight's move is not a scheme in the standard repertoire, and it is not one that a search over ordinary columnar arrangements will stumble into.
What did the Zodiac 340 cipher's own author get wrong?
Two things, and both worked in his favour by accident.
The first is a dropped symbol on line 15, the sixth line of the second section. Van Eycke traced the garbling in that whole section to a single run of symbols on that line which had to be shifted around by one position before the section would read. The second is stranger: the words LIFE IS, sitting in the upper right of the second section, appear to have been left out of the transposition altogether, so they read straight through while everything around them had been moved.
The consequence is worth sitting with. Even with the reading order exactly right, section 2 came out visibly damaged. Any automated search that ranks candidates by how much English falls out will score the true answer below cleaner-looking nonsense produced by wrong keys. When the solvers first read section 2 they had lines like SOO HEN BE CURSEE OOW HAVE ENSUGH SLAVER TO WOR V FOV ME, correct in outline and wrong in a dozen places at once.
The scheme was not strong. Its author's sloppiness was.
How do we know this Zodiac 340 cipher solution is the right one?
Because the message is more than twice as long as the point beyond which a second sensible reading stops being expected.
Claude Shannon gave the quantity its name in 1949. Unicity distance is the amount of ciphertext beyond which a second sensible reading stops being expected, and below which several readings can be expected. His own rule of thumb, on page 698 of "Communication Theory of Secrecy Systems", is the standard every claimed solution should be held to. It sits in a section on whether an analyst has genuinely read a cryptogram or merely read a solution into it, and the two examples he reaches for are the Bacon and Shakespeare ciphers and the "Roger Bacon" manuscript, better known now as the Voynich:
"In general we may say that if a proposed system and key solves a cryptogram for a length of material considerably greater than the unicity distance the solution is trustworthy. If the material is of the same order or shorter than the unicity distance the solution is highly suspicious."
In 2021 Joachim von zur Gathen of the University of Bonn did the arithmetic for this particular system, accounting for the homophonic substitution, the sectioning, the transpositions and the irregular substitutions together, and put the unicity distance at 152 at most. Z340 is 340 characters. On his assumptions it clears the bar by more than double, which is exactly the condition Shannon called trustworthy: a second key producing a sensible message is not expected to exist.
Then there is the evidence that has nothing to do with information theory. Seventeen days before Z340 was posted, someone claiming to be Zodiac telephoned a live call-in television programme and said on air that he did not want to go to the gas chamber. The solvers' account lines that up against two lines of the decryption. One reads "THAT WASNT ME ON THE TV SHOW". The other says the writer is not afraid of the gas chamber. Neither was forced into place; both fell out of a key derived from elsewhere in the text.
The Bureau agreed, in writing. Its statement records that "On December 5, 2020, the FBI received the solution to a cipher popularly known as Z340 from a cryptologic researcher and independently verified the decryption".
Why might the two short ciphers never be solved?
Because they sit on the wrong side of Shannon's line, and no amount of cleverness moves them across it.
Put a number on it. Shannon worked out the unicity point for plain simple substitution, the easiest system there is, and reported it on page 695 as "about 27 letters", experimentally between 20 and 30. Z13 has thirteen symbols. It is under the bar for a cipher far weaker than the one Zodiac was by then demonstrably capable of building, so several different keys can each yield a sensible reading and nothing in the text can choose between them. Thousands of candidate readings of Z13 have been collected on that basis, and no test exists that would tell you which, if any, is correct.
Z32 is longer but worse off, because twenty-nine of its thirty-two symbols occur exactly once. With that many singletons you can construct a substitution key producing almost any short legible phrase you care to name, so a proposed answer cannot be tested, only preferred. Both cryptograms are in a different condition from unsolved. They are undecidable on the evidence available, short of Zodiac's own working papers turning up.
And "solved" is not binary even for Z408. The key recovered in 1969 reads the whole of it except the final eighteen characters, which come out as EBEORIETEMETHHPITI and mean nothing. One suggestion is that they are filler, symbols copied from the lines above to pad the third sheet out to match the other two. Another is that a second step applies to them alone. Fifty-seven years later they are still unread, sitting at the end of the one message everyone counts as broken.
If you want the mechanism in your hands rather than on a page, build a homophonic substitution, then a transposition, then stack one on the other in that order. That is Z340. Then see whether a cipher identifier can still pick the two layers apart, or try the rest of the cipher tools.
Frequently asked questions
Did the FBI ever formally confirm the Zodiac 340 cipher solution?
Yes, and it did so twice on one day. The solution reached the Bureau's Cryptanalysis and Racketeering Records Unit on 5 December 2020, and by the solvers' account they were held back from publishing until 11 December so that victim notifications could be made first. Two separate statements went out on 11 December. One came from the San Francisco field office, confirming that "a cipher attributed to the Zodiac Killer was recently solved by private citizens" and declining any further comment because the investigation remains open. The other came from the Bureau as a whole and is the more detailed of the two, describing the verification and noting that over the preceding 51 years the unit had "reviewed numerous proposed solutions from the public" without finding merit in any of them.
What is a knight's-move transposition, in plain terms?
A transposition hides a message by changing where the letters sit rather than what they are, and the rule for moving them is the key. The oldest version is the scytale, a strip of leather wound around a rod and written along its length, which turns into nonsense the moment you unwind it. What makes the family awkward for a codebreaker is that nothing is substituted at any point, so the letter frequencies of the plaintext survive intact and every tool built on counting symbols reports that nothing has happened. That is why a transposition layer can sit on top of a substitution for decades without announcing itself, and why the chess-move rule behind this one had to be guessed rather than measured.
Could software have solved it without any human guesswork?
Not as things stood. Even with the transposition applied correctly, the first automated pass at the first nine rows returned nothing usable, because the amount of key relative to the amount of text left the search too flat. What broke it was Oranchak feeding three suspected phrases back into the solver at the positions where they had already surfaced in a batch run: HOPE YOU ARE, TRYING TO CATCH ME, and THE GAS CHAMBER. Those three fixed about 43 percent of the symbol assignments, and the machine finished the rest. The solvers later found the section could be done without the hints if longer language statistics were used, but that was after the fact.
What does the solved message actually say?
It opens "I HOPE YOU ARE HAVING LOTS OF FUN IN TRYING TO CATCH ME", carries on into the denial about the television show and the line about not fearing the gas chamber, and ends with the writer claiming he has enough slaves to work for him in what he spells PARADICE, where everyone else will have nothing. The spelling in that last stretch is his own, and the misspellings are dense enough that the solvers publish the plaintext with corrections in brackets. The final two lines are odd in a different way: several words in them were written in reverse, so the raw output reads EFIL WILL EB NA EASY ENO NI ECIDARAP DEATH before it is turned back around into LIFE WILL BE AN EASY ONE IN PARADICE DEATH.
Why did Zodiac use a harder method the second time?
The solvers' own inference, offered as inference rather than fact, is that the speed of the first break provoked it: Z408 fell within days of publication, and the reply carried a transposition layer Z408 did not have. Combining rearrangement with substitution is a standard hardening move rather than an invention, so what it shows is a slightly deeper reading of classical cryptography, not a new idea. It also bought him nothing in content. Donald C. B. Marsh, the Colorado School of Mines mathematician and past president of the American Cryptogram Association whom police had asked to work the ciphers, told a Vallejo paper in January 1970 that he doubted Z340 held a name and expected its contents to be "as valueless as those of the first". When the cipher was finally read in 2020, that turned out to be right.
Sources
- David Oranchak, Sam Blake and Jarl Van Eycke, "The Solution of the Zodiac Killer's 340-Character Cipher", arXiv:2403.17350, 26 March 2024, later published in Cryptologia. Section 1 for the four ciphers, their mailing dates, their symbol counts and the unread tail of Z408; Section 2 for the 1969 FBI cryptanalysis report; Section 3 for the 2009 FBI observations; Section 5 for the repeating-pair evidence, the transposition, the cribbing, the two enciphering errors, the plaintext, the call-in programme 17 days before the mailing, the 11 December release and both FBI statements; Section 8 for Z13, Z32 and the contemporary assessments quoted here - retrieved 10 August 2026, arxiv.org/abs/2403.17350
- Joachim von zur Gathen, "Unicity distance of the Zodiac-340 cipher", IACR Cryptology ePrint Archive 2021/1620, 12 December 2021, published in Cryptologia 47(5), 2023. Source for the unicity distance of at most 152 - retrieved 10 August 2026, eprint.iacr.org/2021/1620
- Claude E. Shannon, "Communication Theory of Secrecy Systems", Bell System Technical Journal 28(4), October 1949, pp. 656 to 715. The quoted passage is in Section 16, "Validity of a Cryptogram Solution", p. 698; the simple-substitution unicity point of about 27 letters is on p. 695 - retrieved 10 August 2026, archive.org/details/bstj28-4-656
- Federal Bureau of Investigation, FBI Records: The Vault, "The Zodiac Killer", the Bureau's released case file in seven parts, which holds the 1969 cryptanalysis correspondence summarised above - retrieved 10 August 2026, vault.fbi.gov/The Zodiac Killer