01 Five reasons a cipher stays unsolved
| category | what it means | can effort help? |
|---|---|---|
| not a cipher | An undeciphered script. Nothing is concealed; the language or the sign values are simply lost. | Only more text, or a bilingual. |
| unbreakable | A one-time pad or an unrecoverable codebook. The information is not present in the ciphertext. | No. Not ever. |
| unprovable | Real encipherment, but so short that many readings fit and none can be demonstrated. | Rarely. A solution would need outside confirmation. |
| no message | Constructed to look like a cipher. There is nothing inside. | Only to prove the negative. |
| open | A genuine cipher, of workable length, where the method is plausibly recoverable. | Yes. |
02 Not ciphers at all
Four of the best-known entries are undeciphered writing systems. A cipher hides a message someone intended you not to read; a lost script is a message someone very much wanted read, whose readers have all died. The techniques do not transfer, and a cryptanalyst has no special advantage.
Linear A not a cipher
Michael Ventris broke Linear B in 1952, and the reason he could is instructive: the underlying language turned out to be Greek, a language already known in detail. Linear A uses a closely related script but records a different language, with no surviving relative and no bilingual text. The signs can even be given probable sound values by carrying them over from Linear B — and the result is still unreadable, because nobody knows what the words mean. That is the exact opposite of a cipher problem.
The Phaistos disc not a cipher
Stamped with movable type, which makes it remarkable, and unique, which makes it hopeless. A corpus of one object a few hundred signs long cannot support a decipherment: there is no way to test a proposed reading against anything. Claimed solutions appear regularly and none can be checked. Its best prospect was always that it might serve as a crib for Linear A, which has not happened.
The Indus script not a cipher
There is plenty of material, but the inscriptions average around five signs and the longest known is seventeen. With no bilingual, no known descendant language and texts that short, the field cannot even settle whether the script encodes speech at all or functions as a system of marks. That question has to be answered before decipherment can start.
Rongorongo, and the Etruscan, Proto-Elamite and Meroitic corpora not a cipher
Meroitic is the clearest illustration of the distinction. Its script was deciphered over a century ago, so the texts can be read aloud with confidence — and still nobody knows what they say, because the language has no established relatives. Sound values without meaning is a condition no amount of cryptanalysis improves.
03 Unbreakable, in the strict sense
The Bletchingley pigeon message unbreakable
Found in a chimney attached to the leg bone of a carrier pigeon. GCHQ examined it and concluded it was almost certainly enciphered with a one-time pad. If that is right the message is not hard to read, it is impossible: a one-time pad of the same length as the message makes every plaintext of that length equally consistent with the ciphertext, so the information is absent from the object rather than hidden in it. Only the pad itself, or the original plaintext, could recover it, and both are gone.
The Lüderitz consular telegram unbreakable
Not famous, but it belongs here. A British Foreign Office codebook cipher of 43 groups. Without the codebook there is no attack, because the groups are arbitrary labels rather than transformations of letters. This is the ordinary fate of code, as distinct from cipher: it is defeated by archives, not by analysis.
04 Real ciphers, too short to prove
The Dorabella cipher unprovable
Eighty-seven characters drawn from an alphabet of 24 squiggles. Elgar was fond of wordplay and the note was personal, so the plaintext may well be allusive, misspelled or private — which removes the statistical regularities a solution would be tested against. Many readings have been proposed and all of them are the kind of thing that fits 87 characters if you look hard enough. Barring a second document in the same system, the honest status is not "unsolved" but "unprovable".
Kryptos, passage K4 unprovable
The most attacked 97 characters in the world, worked on continuously since 1990 by a large and organised community, with three published cribs released by the sculptor himself. Short, and deliberately irregular: Jim Sanborn has confirmed the earlier passages contain intentional misspellings, so ordinary language statistics are unreliable. In 2025 Sanborn put the solution up for private sale, which ends it as a public challenge whatever happens to the ciphertext.
The D’Agapeyeff cipher unprovable
The one on this list we have examined closely, and the results are worth stating. The structure is not in doubt: 392 usable digits form 196 pairs, the first digit of every pair from {6,7,8,9,0} and the second from {1,2,3,4,5}, which is the 5×5 Polybius square D’Agapeyeff teaches in his own book. His book also contains a worked Polybius example with the plaintext supplied — a perfect control, same author, same method, known answer.
Run identical tests on both and they separate sharply. The control matches English almost exactly: best-case chi-squared against English letter frequencies 4.2, and repeated digrams 3.6 standard deviations above a random shuffle of its own symbols, dead on the English level. The challenge fails both: chi-squared 34.1, and digram repetition slightly below random. Calibrated against 3,000 real English samples of the same length, none was as frequency-flat as the challenge and none used as few distinct cells. That test does not depend on the order of the text, so it holds whatever transposition might have been applied — and a substitution-invariant search for a transposition scores no better on the cipher than on random shuffles of its own letters.
So the ciphertext does not carry the signature of English enciphered by the method the book teaches. D’Agapeyeff later admitted he could no longer decipher it himself, and dropped it from subsequent editions. The most economical reading is that he botched the encipherment.
05 Probably no message at all
The Chinese gold bar cryptograms no message — full write-up
Settled, and cleanly. The 263 letters contain almost exactly ten of every letter of the alphabet — 21 of the 26 appear exactly ten times. Chi-squared against a uniform distribution is 1.25 on 25 degrees of freedom where random sampling predicts 25, a one-in-a-trillion level of over-uniformity, and none of 200,000 simulated random strings came close. No encryption does this: substitution and transposition preserve the plaintext’s skew, and a one-time pad is still random sampling and lands near 25. Somebody counted out ten of each letter and arranged them to look like cryptography.
The Beale papers no message
Paper 2 genuinely decodes against the Declaration of Independence and describes a buried fortune. Papers 1 and 3 do not decode against anything. Testing paper 1 against the English-language Gutenberg corpus as a book cipher produced no key text, and its number choices do not behave like an encoding: its letter statistics through the Declaration are indistinguishable from random picks, where paper 2 stands 16 standard deviations clear, and it shows none of the repeated-number structure that a real encoding leaves. Add the anachronistic vocabulary in the pamphlet’s "1822" letters, long ago identified by Jean Nickell, and the sensible conclusion is that paper 2 was built as bait and the other two were filled in.
The Voynich manuscript no message?
The most-studied unsolved text in existence, and the only one on this list where the category is genuinely contested. The manuscript is old and the parchment is real. But the script behaves oddly for a natural language: word structure is unusually rigid, words repeat adjacent to themselves far more than any known language allows, and the statistics differ measurably between sections. Six centuries of attention by linguists, cryptanalysts and computational methods have produced no key and no reading that survives scrutiny. That is not proof of meaninglessness — a constructed language or a glossolalic text would look much like this — but the weight of evidence has moved a long way from "cipher awaiting a cryptanalyst".
06 Genuinely open
Almost everything worth attacking on the famous list has been attacked to exhaustion. The items where effort still pays are elsewhere: archival ciphers of ordinary length, where a key survives in a collection nobody has connected to the ciphertext, or where the method is recoverable because the correspondents were not very good at this. Four entries on the working list have fallen that way in this project — a Richelieu letter whose decipherment had sat in print since 1858, a Madison-era diplomatic postscript readable once the State Department’s own code was rebuilt from its pencil annotations, and two Chinese telegrams of 1916.
The lesson the famous list teaches, read properly, is that fame is a poor guide to tractability. An unsolved cipher is usually unsolved for a structural reason, and the reason is usually visible in the statistics before any attempt at a solution.
07 Sources
- Elonka Dunin, list of famous unsolved codes and ciphers, the reference list for this survey.
- Klaus Schmeh, Klausis Krypto Kolumne, for the top-50 series and the gold bar discussion.
- Working notes and reproducible code for the items examined here:
goldbar/,dagapeyeff/andbeale/in the repository.