1394 · 1116 · 1273 · 250 · 1165 · 1405
11 16 19 ~25 29 10
972 · 148 · 1459 · 1482

Working notes · September 2026

Unsolved Historical Ciphers

Progress on the items in S. Tomokiyo's Unsolved Historical Ciphers list — reading the archives, reconstructing the keys, and correcting the catalogues where a solution already existed in print.

Daniel Bourdeau · updated 15 September 2026

★ Famous case closed · September 2026

The Chinese gold bar cryptograms are unsolved — because there is nothing in them

Seven bars said to have been issued in Shanghai in 1933 and to certify a deposit of $300,000,000, stamped with sixteen strings of Latin letters. Published by the IACR in 1996, carried on Elonka Dunin’s list of famous unsolved codes ever since, and never read.

They were never read because they are not an encryption. The 263 letters contain almost exactly ten of every letter of the alphabet — twenty-one of the twenty-six appear exactly ten times. That is flatter than randomness itself permits, and no cipher can do it: substitution and transposition both preserve the plaintext’s frequency skew, and even a one-time pad is still random sampling. Somebody counted out ten of each letter and arranged them to look like cryptography.

1.25chi-squared vs uniform
(chance predicts 25)
1 in 1012likelihood if random
0 / 200,000simulated strings
this uniform
30 yrson the unsolved lists
Read the full case →
72catalogue entries
8solved / explained
1partial
7blocked on access
8queued to attack

solved new decipherment   found solved already in print; catalogue wrong   partial   stuck   blocked key or manuscript located but not reachable online   queued   infeasible

01 Write-ups

United States · 1808solved

Armstrong to Madison — the coded postscript

Forty-nine groups of the 1,600-element "THE = 972" diplomatic code, read in full after reconstructing 580 groups from the State Department's own pencil decodes on NARA microfilm M34 roll 13.

"Russel ought to be the consul: he is an American by birth … Next to him in fitness is O'Mealy, but he is, like Warden, an Irishman."

read →
France · 1629solved

Richelieu to M. de Rancé — BnF Français 3829

Ciphertext-only recovery of a homophonic alphabet with a doubling mark and nomenclature; then found to agree word for word with the decipherment Avenel printed in 1858, which the catalogues had missed.

"Castor voudroit bien que la [duchesse de Chevreuse] peust estre attrapée près de la frontière…"

read →
Ireland / England · 1634–35alphabet recovered

Maltravers to Ormonde — a regular block cipher

Doubled letters written with consecutive figures betray a regular key (consonants three figures each from 7, vowels from 64, nulls 91–111). Every spelled word reads and the nomenclator falls into place from the 1634 Irish Parliament.

"he was angry [with the Lord Deputy] … brought no letters … upon his motion [Ormonde] is to be a councellor"

read →
Brussels · 1659–60explained

Hyde's ciphered superscriptions — not a cipher at all

The four "undeciphered addresses" on Hyde's letters to Barwick decode to nothing under the full Hyde–Barwick key printed in 1721 — because, as the 1724 editor states, they were numbers "signifying nothing … only to puzzle the Enemy".

"some Persons … have wondered what was the meaning of them" — Life of Barwick, 1724

read →
Shanghai · 1933no message

The Chinese gold bar cryptograms — ten of everything

Sixteen strings on seven bars said to certify $300,000,000, unread for ninety years. They contain almost exactly ten of every letter of the alphabet: chi-squared 1.25 against uniform where chance predicts 25, about a trillion to one. No cipher can flatten a distribution past what randomness allows, so nobody has read them because there is nothing to read.

MQOLCSJTLGAJOKBSSBOMUPCE · ZUQUPNZN · FEWGDRHDDEEUMFFTEEMJXZR

read →
Surveythe famous ones

Why the famous ciphers resist

Kryptos, Voynich, Dorabella, Beale, Linear A, Phaistos, the pigeon message. Sorted by the actual reason each has held out: undeciphered writing systems, one that is information-theoretically secure, several too short for any answer to be provable, and at least two that were probably never enciphered. Includes our D’Agapeyeff results against the author’s own control.

Fame is a poor guide to tractability.

read →
China / Japan · 1916scheme found

Huang Xing to Lin Hu and Li Genyuan — a kana condenser

Listed as “solved but specific scheme unknown”: the Japanese Foreign Ministry filed a decode nobody could read, and an encipherment nobody could name. Both recovered here. Three kana carry one character, each kana holding a digit in its gojūon consonant row while the vowel is free — five spellings per digit, so the surface text barely repeats. Consonant rows collide seven times against 1.03 expected; vowels at exactly chance.

護國軍能速入湘贛甚好。章行嚴何日東渡?速令出發,並望預電。興 徑

read →
Swatow → Tokyo · 1916solved

The Swatow telegram to Sun Yat-sen — a systematic code condenser

Twenty consonants, five vowels, ten-letter words: the letters of a code condenser over the standard Chinese telegraph code. The family of systematic tables is small enough to brute-force, and one key reads 41 characters: Mo Qingyu's independence at Chaozhou and Sun's men ordered out of the Swatow garrison headquarters, 3 April 1916.

潮城由莫擎宇獨立。我軍亦光復汕頭。後莫率大隊來,令我退出鎮守府…

read →

02 Priority queue

Everything still open, from both source lists, in one ranking. Odds is the estimated chance of a full reading; effort is the work needed to find out. Cheap decisive tests outrank expensive long shots, so a coin-flip that resolves in ten minutes sits above a one-in-four that costs a day. Entries marked famous come from Elonka Dunin’s list of famous unsolved codes; most of them rank low here for a reason given in the last column.

#TargetDateOddsEffortWhy it sits here
Attack now
1Charles I in the Isle of Wight — the two unread letters1648evenminutesTwo of the four were solved by Biermann and Brown in 2021 and their key is published. Either it opens the other two immediately or it does not. The cheapest decisive test on the list.
2Berthier to Napoleon1812evenlowNapoleon’s correspondence is printed complete and online, so the plaintext of a staff letter may simply be in the edition. Checking the printed edition first has already turned four items on these lists from unsolved into solved.
3Encoded letter to Marshal Marmont1807evenlowSame petit chiffre family and the same printed-edition route as the Berthier letter; worth doing in one pass.
4William Perwich to Lord Arlington, Paris1670evenlowProbably a transposition, possibly one of Morland’s. The despatches were printed by the Camden Society in 1903 and sit on the Internet Archive, so both the text and any contemporary reading are free to check.
5Telegrams found in the sunken Zhongshanc.1938evenlowChinese telegraph code again, so the machinery built for the two 1916 telegrams applies unchanged. The risk is a commercial codebook with an additive rather than a systematic condenser, which would end it quickly.
6Chinese gold bar ciphers, Shanghai famous1933lowmediumThe one item on the famous list that plays to this project’s strengths: mixed Chinese and Latin script on seven bars, in a banking context, where Chinese telegraph code and a reader of the language are exactly what is needed. Against it, the inscriptions are short, the photographs poor, and the provenance disputed.
7Telegram from Switzerland, “BLUME SALAMANCA”1937lowlowNever attempted here and cheap to try. Salamanca was Franco’s headquarters, so the Spanish Civil War supplies cribs, and the coincidence index points at transposition rather than a code. Only two short messages, which caps the odds.
8Japanese telegram decoded by Yardleyc.1920partiallowYardley printed the plaintext, so the scheme is attackable, but Japanese diplomatic traffic of 1920 ran on codebooks. One message can only recover the entries it happens to use, so a complete answer is ruled out by construction.
Long shots, already diagnosed
9Vatican Challenge, Part 5 (Farnese to Poggio)15421 in 4hoursThe most prestigious item left. Meister’s three printed keys are rejected by likelihood, and a trigram partition search that recovers synthetic keys of this design fails on the real text in both Italian and Spanish, so the digits must carry multi-digit syllable codes. The remaining edge is that every key in Argenti’s collection is systematic, which makes the family small enough to enumerate.
10D’Agapeyeff cipher famous1939lowmedium196 digit pairs, and the author admitted he had forgotten his own method, so a real cipher certainly exists. Probably a Polybius square with transposition, which suits the annealing solvers here. Heavily attacked for eighty years, and short enough that a unique solution may not be provable.
11Maltravers to Ormonde, the last nine codes1634–35lowlowThe alphabet is recovered and every spelled word reads. The nine nomenclator codes still resting on context need either the real key or more ciphertext, and neither is online.
12Colbert passages (Mélanges Colbert)1665–74lowlowThree passages too short to break, with all twelve reconstructed Colbert keys already failing. The only route left is paging Gallica for a deciphered sibling letter.
13Thurloe intercepts (Dutch, French, English)1653–56lowlowFour pieces of sixteen to one hundred and thirty-six groups. Every period key on the catalogue fails and hill-climbing yields fragments only. The Rawlinson originals are not digitised.
14D’Estaing to Gérard1779lowlowTwo hundred and seventeen numbers of a six-hundred element code with no key material. Doniol and Meng print only the neighbouring letters; the deciphered copy sits in the French foreign ministry archives.
15Le Tellier to Castelnau1657lowlowTwo hundred and two tokens. Le Tellier’s 1650 tables do not fit, and an exhaustive search of alphabetical syllabary offsets against a French model returned nothing. Too short to solve unconstrained.
Famous, and famous because they resist — or because they are not ciphers at all
16Dorabella cipher famous1897very lowlowEighty-seven symbols from Elgar to a friend. Short enough that many readings fit and none can be proved, which is why a century of proposed solutions has convinced nobody.
17Kryptos, passage K4 famous1990very lowhighThe most worked-over ninety-seven characters in the world, with published cribs and three decades of organised attack. Sanborn also sold the solution privately in 2025, so the prize is gone even if the passage falls.
18WWII pigeon cipher, Bletchingley famous1942?noneTwenty-seven five-letter groups that GCHQ assesses as one-time pad. If that is right the message is information-theoretically secure and no amount of work recovers it.
19Enigma message of 10 January 19451945very lowhighA single message against a bombe-scale search that others have already run. Nothing here that specialist projects do not do better.
20Voynich manuscript famousc.1420not a cipher?Six hundred years, an entire academic field, and radiocarbon dating have produced no key. The weight of evidence now points at a constructed or glossolalic text rather than an encipherment, in which case there is nothing to solve.
21Phaistos disc famousc.1800 BCnot a cipher241 stamped signs on one object. An undeciphered script with a corpus of a single artifact cannot be read by cryptanalysis; it needs more text or a bilingual.
22Linear A famousc.1800 BCnot a cipherAn unknown language in a partly known script. Ventris broke Linear B because the language turned out to be Greek; Linear A has no such handle, so this is a problem for linguistics, not codebreaking.
23Indus script famousc.2600 BCnot a cipherAbout four hundred signs, but the inscriptions average five characters and there is no bilingual. It is disputed whether it encodes language at all.
24Rongorongo, and the Etruscan, Proto-Elamite and Meroitic corpora famousvariousnot ciphersUndeciphered writing systems rather than concealed messages. Meroitic can even be read aloud without being understood, which is the opposite of a cipher problem.
25Lüderitz consular telegram1911noneForty-three five-figure groups from a Foreign Office codebook. Without the book there is no attack, only guesswork.

03 Blocked on access, not on cryptanalysis

These are the highest-value items left, and none needs a new idea. Each waits on a reader’s account, a copy order, or a server coming back. Odds shown are for after the material is in hand.

TargetDateOdds once openWhat unblocks it
Charles II to the Duke of Hamilton1650highThe key survives and is catalogued open: National Records of Scotland GD406/1/2197, “Keys for ciphers used in the correspondence of the Duke of Hamilton”. A copy order to Edinburgh should settle four letters at once.
Royalist intercepts, BL Add MS 72438 ff. 9–101646highThe same volume holds Weckherlin’s forty-nine captured Digby keys, so this becomes key matching rather than cryptanalysis. Needs British Library images, offline since the cyber-attack, or a DECODE account.
Prince Maurice to Prince Rupert1645evenSame volumes, same blockage. The two known Rupert keys of 1644–45 do not fit, so it depends on an unpublished key being among the Digby set.
Ferdinand III and the Cardinal-Infante1634–40evenAll three DECODE records are marked “authentication required” for images and transcriptions alike. A research account is granted on request.
1520s superscript-digit ciphers1526–29evenOne of the four Worcester letters is already deciphered and would seed the syllable table. Blocked the same way: DECODE login, and the British Library viewer is down.
Stepney to the Earl of Manchester1702evenManuscript already transcribed from Yale. The key is Stepney’s own office cipher, asked for in August 1701, in TNA SP 105/106 or BL Add MSS 7058–78.
Henry III to Ségur1583–86evenFour folios of BnF 500 de Colbert 401. Gallica refuses this client entirely and a retry job is running. The volume’s other Henry III cipher is a plain alphabetical syllabary, a strong prior for these.

04 Closed

TargetDateStatusOutcome
Richelieu to M. de Rancé1629solvedHomophonic alphabet, doubling mark and nomenclature recovered ciphertext-only; agrees word for word with Avenel (1858), missed by DECODE R9461–R9462.
Armstrong to Madison, coded postscript1808solvedAll forty-nine groups, from a code table of 580 groups rebuilt off the State Department’s own pencil decodes. The separate code of the 20 February 1808 letter is still open.
Telegram to Sun Yat-sen, Swatow1916solvedStandard telegraph code through a systematic twenty by five condenser; forty-one characters read.
Telegram from Huang Xing to Lin Hu and Li Genyuan1916scheme foundListed as “solved but specific scheme unknown”. Three kana per character, each kana carrying one digit in its gojuon consonant row while the vowel is a free homophone, so every digit has five spellings and the surface text barely repeats. Consonant-row triples collide seven times against 1.03 expected (p = 0.006); vowels collide at exactly chance (p = 0.70). The Foreign Ministry’s filed decode and its annotated Japanese reading recovered from JACAR.
Hyde’s ciphered superscriptions1659–60explainedNot a cipher. Dummy numbers, as the 1724 editor of the Life of Barwick states outright.
Union cipher telegrams to General Milroy1861–62found solvedStager cipher no. 7, solved by Richard Bean in 2026. The catalogue has since caught up.
Confederate Navy dictionary code1863found solvedSolved by others in August 2026 with Webster’s Primary School Dictionary of 1850. Still listed as unsolved.
Feynman ciphers 2 and 31987found solvedSolved by David Vierra in 2023, verified here by decrypting both from ciphertext alone.
Beale Paper no. 11885fabricationNo key text found across the English Gutenberg corpus; the number choices and letter statistics point to a hoax rather than a lost key. No further work planned.

05 The rest of the catalogue

The list carries roughly sixty unsolved entries; the sections above cover those worth ranking. The remainder are short passages, key-dependent fragments or archive-bound manuscripts, held here so that nothing is silently dropped.

GroupEntries
English, 16th centuryThrockmorton (1559) and Wool (1568) · Moray and Wood (1568) · SP53/16 no. 78 and no. 79 · SP53/22 f. 52 · ciphers related to Walsingham
Spanishpostscript to Ferdinand’s letter (1498) · Charles V letter (1521?) · Simancas EST,LEG,1381,180 and 1381,143
French to 1610Catherine de Medici to du Croc (1567) · Birago to Nevers (1571) · Blancmesnil to Nevers · Marie de Medici (1610)
Italian and VenetianVenetian letter in Spanish archives (c.1589) · Cocquet (1616) · Fra Guglielmo Vizani (1637)
GermanKing of Hungary and Bohemia (1634) · further ciphers of Ferdinand III · variable-length figure codes, Austrian archives (1627, 1644) · Starhemberg (1758)
French, 17th centuryPrince of Condé (1654)
English Civil WarOrmond and Arran (1678) · Charles I and Boswell (1643) · Richard Forster (1644) · the private cipher of Charles I and Henrietta Maria (1645) · a letter to Prince Rupert (1648) · an intercepted letter of Hyde (1659) · one further intercepted letter
French, 1690–1710ambassador in Rome (1690) · Catinat (1691 and 1702) · Geertruidenberg (1710) · Villars and Polignac (1710)
AmericanArmstrong to Madison, 20 February 1808, a different code from the postscript solved here, with a disputed 2025 contest solution

Corrections and pointers to existing decipherments are welcome — a catalogue entry marked "unsolved" is often a literature search away from "solved in 1858".