OBKR UOXOGHULBSOLIFBBWFLRVQQPRNGKSSO
?????? · Linear A · Voynich · Z13
27 five-letter groups, one pigeon

A survey · September 2026

The famous ones, and why they resist

Kryptos, Voynich, Dorabella, Beale, Linear A, the Phaistos disc, the pigeon message, the Shanghai gold bars — the celebrated unsolved ciphers, sorted by the actual reason each has held out

Daniel Bourdeau · based on Elonka Dunin’s list

The short version. The famous unsolved ciphers are famous for very different reasons, and lumping them together as one kind of puzzle is the main obstacle to thinking clearly about them. Sorted honestly, most of the list is not waiting for a cleverer cryptanalyst at all. Some are undeciphered writing systems, which is a problem for linguistics. One is information-theoretically secure and will never be read. Several are too short for any proposed answer to be provable, so they can be guessed but not solved. At least two were probably never enciphered in the first place. That leaves a handful genuinely open — and they tend to be the ones nobody has heard of.

01 Five reasons a cipher stays unsolved

categorywhat it meanscan effort help?
not a cipherAn undeciphered script. Nothing is concealed; the language or the sign values are simply lost.Only more text, or a bilingual.
unbreakableA one-time pad or an unrecoverable codebook. The information is not present in the ciphertext.No. Not ever.
unprovableReal encipherment, but so short that many readings fit and none can be demonstrated.Rarely. A solution would need outside confirmation.
no messageConstructed to look like a cipher. There is nothing inside.Only to prove the negative.
openA genuine cipher, of workable length, where the method is plausibly recoverable.Yes.

02 Not ciphers at all

Four of the best-known entries are undeciphered writing systems. A cipher hides a message someone intended you not to read; a lost script is a message someone very much wanted read, whose readers have all died. The techniques do not transfer, and a cryptanalyst has no special advantage.

Linear A not a cipher

Crete · c.1800 BC · about 1,400 inscriptions

Michael Ventris broke Linear B in 1952, and the reason he could is instructive: the underlying language turned out to be Greek, a language already known in detail. Linear A uses a closely related script but records a different language, with no surviving relative and no bilingual text. The signs can even be given probable sound values by carrying them over from Linear B — and the result is still unreadable, because nobody knows what the words mean. That is the exact opposite of a cipher problem.

The Phaistos disc not a cipher

Crete · c.1800 BC · 241 signs, 45 distinct, one object

Stamped with movable type, which makes it remarkable, and unique, which makes it hopeless. A corpus of one object a few hundred signs long cannot support a decipherment: there is no way to test a proposed reading against anything. Claimed solutions appear regularly and none can be checked. Its best prospect was always that it might serve as a crib for Linear A, which has not happened.

The Indus script not a cipher

Indus valley · c.2600–1800 BC · thousands of objects, about 400 signs

There is plenty of material, but the inscriptions average around five signs and the longest known is seventeen. With no bilingual, no known descendant language and texts that short, the field cannot even settle whether the script encodes speech at all or functions as a system of marks. That question has to be answered before decipherment can start.

Rongorongo, and the Etruscan, Proto-Elamite and Meroitic corpora not a cipher

Easter Island and elsewhere · various

Meroitic is the clearest illustration of the distinction. Its script was deciphered over a century ago, so the texts can be read aloud with confidence — and still nobody knows what they say, because the language has no established relatives. Sound values without meaning is a condition no amount of cryptanalysis improves.

03 Unbreakable, in the strict sense

The Bletchingley pigeon message unbreakable

Surrey · found 2012, sent c.1942 · 27 five-letter groups

Found in a chimney attached to the leg bone of a carrier pigeon. GCHQ examined it and concluded it was almost certainly enciphered with a one-time pad. If that is right the message is not hard to read, it is impossible: a one-time pad of the same length as the message makes every plaintext of that length equally consistent with the ciphertext, so the information is absent from the object rather than hidden in it. Only the pad itself, or the original plaintext, could recover it, and both are gone.

The Lüderitz consular telegram unbreakable

German South-West Africa · 1911 · 43 five-figure groups

Not famous, but it belongs here. A British Foreign Office codebook cipher of 43 groups. Without the codebook there is no attack, because the groups are arbitrary labels rather than transformations of letters. This is the ordinary fate of code, as distinct from cipher: it is defeated by archives, not by analysis.

04 Real ciphers, too short to prove

The Dorabella cipher unprovable

Edward Elgar to Dora Penny · 1897 · 87 symbols

Eighty-seven characters drawn from an alphabet of 24 squiggles. Elgar was fond of wordplay and the note was personal, so the plaintext may well be allusive, misspelled or private — which removes the statistical regularities a solution would be tested against. Many readings have been proposed and all of them are the kind of thing that fits 87 characters if you look hard enough. Barring a second document in the same system, the honest status is not "unsolved" but "unprovable".

Kryptos, passage K4 unprovable

CIA headquarters, Langley · 1990 · 97 characters

The most attacked 97 characters in the world, worked on continuously since 1990 by a large and organised community, with three published cribs released by the sculptor himself. Short, and deliberately irregular: Jim Sanborn has confirmed the earlier passages contain intentional misspellings, so ordinary language statistics are unreliable. In 2025 Sanborn put the solution up for private sale, which ends it as a public challenge whatever happens to the ciphertext.

The D’Agapeyeff cipher unprovable

London · 1939 · 196 Polybius cells

The one on this list we have examined closely, and the results are worth stating. The structure is not in doubt: 392 usable digits form 196 pairs, the first digit of every pair from {6,7,8,9,0} and the second from {1,2,3,4,5}, which is the 5×5 Polybius square D’Agapeyeff teaches in his own book. His book also contains a worked Polybius example with the plaintext supplied — a perfect control, same author, same method, known answer.

Run identical tests on both and they separate sharply. The control matches English almost exactly: best-case chi-squared against English letter frequencies 4.2, and repeated digrams 3.6 standard deviations above a random shuffle of its own symbols, dead on the English level. The challenge fails both: chi-squared 34.1, and digram repetition slightly below random. Calibrated against 3,000 real English samples of the same length, none was as frequency-flat as the challenge and none used as few distinct cells. That test does not depend on the order of the text, so it holds whatever transposition might have been applied — and a substitution-invariant search for a transposition scores no better on the cipher than on random shuffles of its own letters.

So the ciphertext does not carry the signature of English enciphered by the method the book teaches. D’Agapeyeff later admitted he could no longer decipher it himself, and dropped it from subsequent editions. The most economical reading is that he botched the encipherment.

05 Probably no message at all

The Chinese gold bar cryptograms no messagefull write-up

Shanghai · 1933 · 16 strings, 263 letters

Settled, and cleanly. The 263 letters contain almost exactly ten of every letter of the alphabet — 21 of the 26 appear exactly ten times. Chi-squared against a uniform distribution is 1.25 on 25 degrees of freedom where random sampling predicts 25, a one-in-a-trillion level of over-uniformity, and none of 200,000 simulated random strings came close. No encryption does this: substitution and transposition preserve the plaintext’s skew, and a one-time pad is still random sampling and lands near 25. Somebody counted out ten of each letter and arranged them to look like cryptography.

The Beale papers no message

Virginia · published 1885 · three papers, one solved

Paper 2 genuinely decodes against the Declaration of Independence and describes a buried fortune. Papers 1 and 3 do not decode against anything. Testing paper 1 against the English-language Gutenberg corpus as a book cipher produced no key text, and its number choices do not behave like an encoding: its letter statistics through the Declaration are indistinguishable from random picks, where paper 2 stands 16 standard deviations clear, and it shows none of the repeated-number structure that a real encoding leaves. Add the anachronistic vocabulary in the pamphlet’s "1822" letters, long ago identified by Jean Nickell, and the sensible conclusion is that paper 2 was built as bait and the other two were filled in.

The Voynich manuscript no message?

c.1420, radiocarbon dated · about 240 pages

The most-studied unsolved text in existence, and the only one on this list where the category is genuinely contested. The manuscript is old and the parchment is real. But the script behaves oddly for a natural language: word structure is unusually rigid, words repeat adjacent to themselves far more than any known language allows, and the statistics differ measurably between sections. Six centuries of attention by linguists, cryptanalysts and computational methods have produced no key and no reading that survives scrutiny. That is not proof of meaninglessness — a constructed language or a glossolalic text would look much like this — but the weight of evidence has moved a long way from "cipher awaiting a cryptanalyst".

06 Genuinely open

Almost everything worth attacking on the famous list has been attacked to exhaustion. The items where effort still pays are elsewhere: archival ciphers of ordinary length, where a key survives in a collection nobody has connected to the ciphertext, or where the method is recoverable because the correspondents were not very good at this. Four entries on the working list have fallen that way in this project — a Richelieu letter whose decipherment had sat in print since 1858, a Madison-era diplomatic postscript readable once the State Department’s own code was rebuilt from its pencil annotations, and two Chinese telegrams of 1916.

The lesson the famous list teaches, read properly, is that fame is a poor guide to tractability. An unsolved cipher is usually unsolved for a structural reason, and the reason is usually visible in the statistics before any attempt at a solution.

07 Sources