The Chinese gold bar cryptograms are unsolved — because there is nothing in them
Seven bars said to have been issued in Shanghai in 1933 and to certify a deposit of $300,000,000, stamped with sixteen strings of Latin letters. Published by the IACR in 1996, carried on Elonka Dunin’s list of famous unsolved codes ever since, and never read.
They were never read because they are not an encryption. The 263 letters contain almost exactly ten of every letter of the alphabet — twenty-one of the twenty-six appear exactly ten times. That is flatter than randomness itself permits, and no cipher can do it: substitution and transposition both preserve the plaintext’s frequency skew, and even a one-time pad is still random sampling. Somebody counted out ten of each letter and arranged them to look like cryptography.
(chance predicts 25)
this uniform
solved new decipherment found solved already in print; catalogue wrong partial stuck blocked key or manuscript located but not reachable online queued infeasible
01 Write-ups
Armstrong to Madison — the coded postscript
Forty-nine groups of the 1,600-element "THE = 972" diplomatic code, read in full after reconstructing 580 groups from the State Department's own pencil decodes on NARA microfilm M34 roll 13.
"Russel ought to be the consul: he is an American by birth … Next to him in fitness is O'Mealy, but he is, like Warden, an Irishman."
read →Richelieu to M. de Rancé — BnF Français 3829
Ciphertext-only recovery of a homophonic alphabet with a doubling mark and nomenclature; then found to agree word for word with the decipherment Avenel printed in 1858, which the catalogues had missed.
"Castor voudroit bien que la [duchesse de Chevreuse] peust estre attrapée près de la frontière…"
read →Maltravers to Ormonde — a regular block cipher
Doubled letters written with consecutive figures betray a regular key (consonants three figures each from 7, vowels from 64, nulls 91–111). Every spelled word reads and the nomenclator falls into place from the 1634 Irish Parliament.
"he was angry [with the Lord Deputy] … brought no letters … upon his motion [Ormonde] is to be a councellor"
read →Hyde's ciphered superscriptions — not a cipher at all
The four "undeciphered addresses" on Hyde's letters to Barwick decode to nothing under the full Hyde–Barwick key printed in 1721 — because, as the 1724 editor states, they were numbers "signifying nothing … only to puzzle the Enemy".
"some Persons … have wondered what was the meaning of them" — Life of Barwick, 1724
read →The Chinese gold bar cryptograms — ten of everything
Sixteen strings on seven bars said to certify $300,000,000, unread for ninety years. They contain almost exactly ten of every letter of the alphabet: chi-squared 1.25 against uniform where chance predicts 25, about a trillion to one. No cipher can flatten a distribution past what randomness allows, so nobody has read them because there is nothing to read.
MQOLCSJTLGAJOKBSSBOMUPCE · ZUQUPNZN · FEWGDRHDDEEUMFFTEEMJXZR
read →Why the famous ciphers resist
Kryptos, Voynich, Dorabella, Beale, Linear A, Phaistos, the pigeon message. Sorted by the actual reason each has held out: undeciphered writing systems, one that is information-theoretically secure, several too short for any answer to be provable, and at least two that were probably never enciphered. Includes our D’Agapeyeff results against the author’s own control.
Fame is a poor guide to tractability.
read →Huang Xing to Lin Hu and Li Genyuan — a kana condenser
Listed as “solved but specific scheme unknown”: the Japanese Foreign Ministry filed a decode nobody could read, and an encipherment nobody could name. Both recovered here. Three kana carry one character, each kana holding a digit in its gojūon consonant row while the vowel is free — five spellings per digit, so the surface text barely repeats. Consonant rows collide seven times against 1.03 expected; vowels at exactly chance.
護國軍能速入湘贛甚好。章行嚴何日東渡?速令出發,並望預電。興 徑
read →The Swatow telegram to Sun Yat-sen — a systematic code condenser
Twenty consonants, five vowels, ten-letter words: the letters of a code condenser over the standard Chinese telegraph code. The family of systematic tables is small enough to brute-force, and one key reads 41 characters: Mo Qingyu's independence at Chaozhou and Sun's men ordered out of the Swatow garrison headquarters, 3 April 1916.
潮城由莫擎宇獨立。我軍亦光復汕頭。後莫率大隊來,令我退出鎮守府…
read →02 Priority queue
Everything still open, from both source lists, in one ranking. Odds is the estimated chance of a full reading; effort is the work needed to find out. Cheap decisive tests outrank expensive long shots, so a coin-flip that resolves in ten minutes sits above a one-in-four that costs a day. Entries marked famous come from Elonka Dunin’s list of famous unsolved codes; most of them rank low here for a reason given in the last column.
| # | Target | Date | Odds | Effort | Why it sits here |
|---|---|---|---|---|---|
| Attack now | |||||
| 1 | Charles I in the Isle of Wight — the two unread letters | 1648 | even | minutes | Two of the four were solved by Biermann and Brown in 2021 and their key is published. Either it opens the other two immediately or it does not. The cheapest decisive test on the list. |
| 2 | Berthier to Napoleon | 1812 | even | low | Napoleon’s correspondence is printed complete and online, so the plaintext of a staff letter may simply be in the edition. Checking the printed edition first has already turned four items on these lists from unsolved into solved. |
| 3 | Encoded letter to Marshal Marmont | 1807 | even | low | Same petit chiffre family and the same printed-edition route as the Berthier letter; worth doing in one pass. |
| 4 | William Perwich to Lord Arlington, Paris | 1670 | even | low | Probably a transposition, possibly one of Morland’s. The despatches were printed by the Camden Society in 1903 and sit on the Internet Archive, so both the text and any contemporary reading are free to check. |
| 5 | Telegrams found in the sunken Zhongshan | c.1938 | even | low | Chinese telegraph code again, so the machinery built for the two 1916 telegrams applies unchanged. The risk is a commercial codebook with an additive rather than a systematic condenser, which would end it quickly. |
| 6 | Chinese gold bar ciphers, Shanghai famous | 1933 | low | medium | The one item on the famous list that plays to this project’s strengths: mixed Chinese and Latin script on seven bars, in a banking context, where Chinese telegraph code and a reader of the language are exactly what is needed. Against it, the inscriptions are short, the photographs poor, and the provenance disputed. |
| 7 | Telegram from Switzerland, “BLUME SALAMANCA” | 1937 | low | low | Never attempted here and cheap to try. Salamanca was Franco’s headquarters, so the Spanish Civil War supplies cribs, and the coincidence index points at transposition rather than a code. Only two short messages, which caps the odds. |
| 8 | Japanese telegram decoded by Yardley | c.1920 | partial | low | Yardley printed the plaintext, so the scheme is attackable, but Japanese diplomatic traffic of 1920 ran on codebooks. One message can only recover the entries it happens to use, so a complete answer is ruled out by construction. |
| Long shots, already diagnosed | |||||
| 9 | Vatican Challenge, Part 5 (Farnese to Poggio) | 1542 | 1 in 4 | hours | The most prestigious item left. Meister’s three printed keys are rejected by likelihood, and a trigram partition search that recovers synthetic keys of this design fails on the real text in both Italian and Spanish, so the digits must carry multi-digit syllable codes. The remaining edge is that every key in Argenti’s collection is systematic, which makes the family small enough to enumerate. |
| 10 | D’Agapeyeff cipher famous | 1939 | low | medium | 196 digit pairs, and the author admitted he had forgotten his own method, so a real cipher certainly exists. Probably a Polybius square with transposition, which suits the annealing solvers here. Heavily attacked for eighty years, and short enough that a unique solution may not be provable. |
| 11 | Maltravers to Ormonde, the last nine codes | 1634–35 | low | low | The alphabet is recovered and every spelled word reads. The nine nomenclator codes still resting on context need either the real key or more ciphertext, and neither is online. |
| 12 | Colbert passages (Mélanges Colbert) | 1665–74 | low | low | Three passages too short to break, with all twelve reconstructed Colbert keys already failing. The only route left is paging Gallica for a deciphered sibling letter. |
| 13 | Thurloe intercepts (Dutch, French, English) | 1653–56 | low | low | Four pieces of sixteen to one hundred and thirty-six groups. Every period key on the catalogue fails and hill-climbing yields fragments only. The Rawlinson originals are not digitised. |
| 14 | D’Estaing to Gérard | 1779 | low | low | Two hundred and seventeen numbers of a six-hundred element code with no key material. Doniol and Meng print only the neighbouring letters; the deciphered copy sits in the French foreign ministry archives. |
| 15 | Le Tellier to Castelnau | 1657 | low | low | Two hundred and two tokens. Le Tellier’s 1650 tables do not fit, and an exhaustive search of alphabetical syllabary offsets against a French model returned nothing. Too short to solve unconstrained. |
| Famous, and famous because they resist — or because they are not ciphers at all | |||||
| 16 | Dorabella cipher famous | 1897 | very low | low | Eighty-seven symbols from Elgar to a friend. Short enough that many readings fit and none can be proved, which is why a century of proposed solutions has convinced nobody. |
| 17 | Kryptos, passage K4 famous | 1990 | very low | high | The most worked-over ninety-seven characters in the world, with published cribs and three decades of organised attack. Sanborn also sold the solution privately in 2025, so the prize is gone even if the passage falls. |
| 18 | WWII pigeon cipher, Bletchingley famous | 1942? | none | — | Twenty-seven five-letter groups that GCHQ assesses as one-time pad. If that is right the message is information-theoretically secure and no amount of work recovers it. |
| 19 | Enigma message of 10 January 1945 | 1945 | very low | high | A single message against a bombe-scale search that others have already run. Nothing here that specialist projects do not do better. |
| 20 | Voynich manuscript famous | c.1420 | not a cipher? | — | Six hundred years, an entire academic field, and radiocarbon dating have produced no key. The weight of evidence now points at a constructed or glossolalic text rather than an encipherment, in which case there is nothing to solve. |
| 21 | Phaistos disc famous | c.1800 BC | not a cipher | — | 241 stamped signs on one object. An undeciphered script with a corpus of a single artifact cannot be read by cryptanalysis; it needs more text or a bilingual. |
| 22 | Linear A famous | c.1800 BC | not a cipher | — | An unknown language in a partly known script. Ventris broke Linear B because the language turned out to be Greek; Linear A has no such handle, so this is a problem for linguistics, not codebreaking. |
| 23 | Indus script famous | c.2600 BC | not a cipher | — | About four hundred signs, but the inscriptions average five characters and there is no bilingual. It is disputed whether it encodes language at all. |
| 24 | Rongorongo, and the Etruscan, Proto-Elamite and Meroitic corpora famous | various | not ciphers | — | Undeciphered writing systems rather than concealed messages. Meroitic can even be read aloud without being understood, which is the opposite of a cipher problem. |
| 25 | Lüderitz consular telegram | 1911 | none | — | Forty-three five-figure groups from a Foreign Office codebook. Without the book there is no attack, only guesswork. |
03 Blocked on access, not on cryptanalysis
These are the highest-value items left, and none needs a new idea. Each waits on a reader’s account, a copy order, or a server coming back. Odds shown are for after the material is in hand.
| Target | Date | Odds once open | What unblocks it |
|---|---|---|---|
| Charles II to the Duke of Hamilton | 1650 | high | The key survives and is catalogued open: National Records of Scotland GD406/1/2197, “Keys for ciphers used in the correspondence of the Duke of Hamilton”. A copy order to Edinburgh should settle four letters at once. |
| Royalist intercepts, BL Add MS 72438 ff. 9–10 | 1646 | high | The same volume holds Weckherlin’s forty-nine captured Digby keys, so this becomes key matching rather than cryptanalysis. Needs British Library images, offline since the cyber-attack, or a DECODE account. |
| Prince Maurice to Prince Rupert | 1645 | even | Same volumes, same blockage. The two known Rupert keys of 1644–45 do not fit, so it depends on an unpublished key being among the Digby set. |
| Ferdinand III and the Cardinal-Infante | 1634–40 | even | All three DECODE records are marked “authentication required” for images and transcriptions alike. A research account is granted on request. |
| 1520s superscript-digit ciphers | 1526–29 | even | One of the four Worcester letters is already deciphered and would seed the syllable table. Blocked the same way: DECODE login, and the British Library viewer is down. |
| Stepney to the Earl of Manchester | 1702 | even | Manuscript already transcribed from Yale. The key is Stepney’s own office cipher, asked for in August 1701, in TNA SP 105/106 or BL Add MSS 7058–78. |
| Henry III to Ségur | 1583–86 | even | Four folios of BnF 500 de Colbert 401. Gallica refuses this client entirely and a retry job is running. The volume’s other Henry III cipher is a plain alphabetical syllabary, a strong prior for these. |
04 Closed
| Target | Date | Status | Outcome |
|---|---|---|---|
| Richelieu to M. de Rancé | 1629 | solved | Homophonic alphabet, doubling mark and nomenclature recovered ciphertext-only; agrees word for word with Avenel (1858), missed by DECODE R9461–R9462. |
| Armstrong to Madison, coded postscript | 1808 | solved | All forty-nine groups, from a code table of 580 groups rebuilt off the State Department’s own pencil decodes. The separate code of the 20 February 1808 letter is still open. |
| Telegram to Sun Yat-sen, Swatow | 1916 | solved | Standard telegraph code through a systematic twenty by five condenser; forty-one characters read. |
| Telegram from Huang Xing to Lin Hu and Li Genyuan | 1916 | scheme found | Listed as “solved but specific scheme unknown”. Three kana per character, each kana carrying one digit in its gojuon consonant row while the vowel is a free homophone, so every digit has five spellings and the surface text barely repeats. Consonant-row triples collide seven times against 1.03 expected (p = 0.006); vowels collide at exactly chance (p = 0.70). The Foreign Ministry’s filed decode and its annotated Japanese reading recovered from JACAR. |
| Hyde’s ciphered superscriptions | 1659–60 | explained | Not a cipher. Dummy numbers, as the 1724 editor of the Life of Barwick states outright. |
| Union cipher telegrams to General Milroy | 1861–62 | found solved | Stager cipher no. 7, solved by Richard Bean in 2026. The catalogue has since caught up. |
| Confederate Navy dictionary code | 1863 | found solved | Solved by others in August 2026 with Webster’s Primary School Dictionary of 1850. Still listed as unsolved. |
| Feynman ciphers 2 and 3 | 1987 | found solved | Solved by David Vierra in 2023, verified here by decrypting both from ciphertext alone. |
| Beale Paper no. 1 | 1885 | fabrication | No key text found across the English Gutenberg corpus; the number choices and letter statistics point to a hoax rather than a lost key. No further work planned. |
05 The rest of the catalogue
The list carries roughly sixty unsolved entries; the sections above cover those worth ranking. The remainder are short passages, key-dependent fragments or archive-bound manuscripts, held here so that nothing is silently dropped.
| Group | Entries |
|---|---|
| English, 16th century | Throckmorton (1559) and Wool (1568) · Moray and Wood (1568) · SP53/16 no. 78 and no. 79 · SP53/22 f. 52 · ciphers related to Walsingham |
| Spanish | postscript to Ferdinand’s letter (1498) · Charles V letter (1521?) · Simancas EST,LEG,1381,180 and 1381,143 |
| French to 1610 | Catherine de Medici to du Croc (1567) · Birago to Nevers (1571) · Blancmesnil to Nevers · Marie de Medici (1610) |
| Italian and Venetian | Venetian letter in Spanish archives (c.1589) · Cocquet (1616) · Fra Guglielmo Vizani (1637) |
| German | King of Hungary and Bohemia (1634) · further ciphers of Ferdinand III · variable-length figure codes, Austrian archives (1627, 1644) · Starhemberg (1758) |
| French, 17th century | Prince of Condé (1654) |
| English Civil War | Ormond and Arran (1678) · Charles I and Boswell (1643) · Richard Forster (1644) · the private cipher of Charles I and Henrietta Maria (1645) · a letter to Prince Rupert (1648) · an intercepted letter of Hyde (1659) · one further intercepted letter |
| French, 1690–1710 | ambassador in Rome (1690) · Catinat (1691 and 1702) · Geertruidenberg (1710) · Villars and Polignac (1710) |
| American | Armstrong to Madison, 20 February 1808, a different code from the postscript solved here, with a disputed 2025 contest solution |
Corrections and pointers to existing decipherments are welcome — a catalogue entry marked "unsolved" is often a literature search away from "solved in 1858".