Republished copy of Daniel Bourdeau’s Unsolved Historical Ciphers, released under CC BY 4.0. Text unchanged; hosted by JIC alongside its translations; not an official copy by the author · View the original ↗
OBKR UOXOGHULBSOLIFBBWFLRVQQPRNGKSSO
?????? · Linear A · Voynich · Z13
27 five-letter groups, one pigeon

A survey · September 2026

The famous ones, and why they resist

Kryptos, Voynich, Dorabella, Beale, Linear A, the Phaistos disc, the pigeon message and the Shanghai gold bars: famous texts with no accepted solution, sorted by the reason each has held out

Daniel Bourdeau · posted · updated · based on Elonka Dunin’s list

The short version. The ciphers on the famous lists resist for different reasons, and treating them as one kind of puzzle gets in the way of thinking about them. Sorted by cause, most of the list does not need a better cryptanalyst. Some are lost writing systems, a problem for linguistics. One is information-theoretically secure and cannot be deciphered without its pad. Several are too short for any proposed solution to be proved, so they can be guessed at but not confirmed. At least two were probably never enciphered. That leaves a handful that are open, and they tend to be the ones few people have heard of.

01 Five reasons a cipher stays unsolved

categorywhat it meanscan effort help?
not a cipherAn undeciphered script. Nothing is concealed; the language or the sign values are simply lost.Only more text, or a bilingual.
unbreakableA one-time pad or an unrecoverable codebook. The information is not present in the ciphertext.No. Not ever.
unprovableReal encipherment, but so short that many readings fit and none can be demonstrated.Rarely. A solution would need outside confirmation.
no messageConstructed to look like a cipher. There is nothing inside.Only to prove the negative.
openA genuine cipher, of workable length, where the method is plausibly recoverable.Yes.

02 Not ciphers at all

Four of the best-known entries are writing systems whose language or sound values are lost. A cipher hides a message from readers it was not meant for; a lost script was written to be read by everyone who knew it, and those readers are gone. The techniques do not transfer, and a cryptanalyst has no special advantage.

Linear A not a cipher

Crete · c.1800 BC · about 1,400 inscriptions

Michael Ventris deciphered Linear B in 1952, and the reason he could is instructive: the underlying language was Greek, a language already known in detail. Linear A uses a closely related script but records a different language, with no surviving relative and no bilingual text. The signs can be given probable sound values by carrying them over from Linear B, and the result still cannot be understood, because nobody knows what the words mean. That is the reverse of a cipher problem.

The Phaistos disc not a cipher

Crete · c.1800 BC · 241 signs, 45 distinct, one object

Stamped with movable type, which makes it remarkable, and unique, which makes it hopeless. A corpus of one object a few hundred signs long cannot support a decipherment: there is no way to test a proposed reading against anything. Claimed solutions appear regularly and none can be checked. Its best prospect was always that it might serve as a crib for Linear A, which has not happened.

The Indus script not a cipher

Indus valley · c.2600–1800 BC · thousands of objects, about 400 signs

There is plenty of material, but the inscriptions average around five signs and the longest known is seventeen. With no bilingual, no known descendant language and texts that short, the field cannot even settle whether the script encodes speech at all or functions as a system of marks. That question has to be answered before decipherment can start.

Rongorongo, and the Etruscan, Proto-Elamite and Meroitic corpora not a cipher

Easter Island and elsewhere · various

Meroitic is the clearest illustration of the distinction. Its script was deciphered over a century ago, so the texts can be read aloud with confidence, and still nobody knows what they say, because the language has no established relatives. Sound values without meaning is a condition no amount of cryptanalysis improves.

03 Unbreakable, in the strict sense

The Bletchingley pigeon message unbreakable

Surrey · found 2012, sent c.1942 · 27 five-letter groups

Found in a chimney attached to the leg bone of a carrier pigeon. GCHQ examined it and concluded it was almost certainly enciphered with a one-time pad. If that is right, the message cannot be deciphered at all: a one-time pad of the same length as the message makes every plaintext of that length equally consistent with the ciphertext, so the information is absent from the object rather than hidden in it. Only the pad itself, or the original plaintext, could recover it, and both are gone.

The Lüderitz consular telegram unbreakable

German South-West Africa · 1911 · 43 five-figure groups

It is little known, and it belongs here. It is a British Foreign Office message of 43 groups in a codebook. Without the codebook there is no attack, because the groups are arbitrary labels rather than transformations of letters. This is the ordinary fate of code, as distinct from cipher: it is defeated by archives, not by analysis.

04 Real ciphers, too short to prove

The Dorabella cipher unprovable

Edward Elgar to Dora Penny · 1897 · 87 symbols

Eighty-seven characters drawn from an alphabet of 24 squiggles. Elgar was fond of wordplay and the note was personal, so the plaintext may well be allusive, misspelled or private, which removes the statistical regularities a solution would be tested against. Many solutions have been proposed, and all of them are the kind of thing that fits 87 characters if you look hard enough. Barring a second document in the same system, the accurate status is "unprovable".

Kryptos, passage K4 unprovable

CIA headquarters, Langley · 1990 · 97 characters

The most attacked 97 characters in the world, worked on continuously since 1990 by a large and organised community, with three published cribs released by the sculptor himself. Short, and deliberately irregular: Jim Sanborn has confirmed the earlier passages contain intentional misspellings, so ordinary language statistics are unreliable. In 2025 Sanborn put the solution up for private sale, which ends it as a public challenge whatever happens to the ciphertext.

The D’Agapeyeff cipher unprovable

London · 1939 · 196 Polybius cells

The one on this list we have examined closely, and the results are worth stating. The structure is not in doubt: 392 usable digits form 196 pairs, the first digit of every pair from {6,7,8,9,0} and the second from {1,2,3,4,5}, which is the 5×5 Polybius square D’Agapeyeff teaches in his own book. His book also contains a worked Polybius example with the plaintext supplied: a control with the same author, the same method and a known answer.

Run identical tests on both and they separate sharply. The control matches English almost exactly: best-case chi-squared against English letter frequencies 4.2, and repeated digrams 3.6 standard deviations above a random shuffle of its own symbols, at the English level. The challenge fails both: chi-squared 34.1, and digram repetition slightly below random. Calibrated against 3,000 real English samples of the same length, none was as frequency-flat as the challenge and none used as few distinct cells. That test does not depend on the order of the text, so it holds whatever transposition might have been applied, and a substitution-invariant search for a transposition scores no better on the cipher than on random shuffles of its own letters.

So the ciphertext does not carry the signature of English enciphered by the method the book teaches. D’Agapeyeff later admitted he could no longer decipher it himself, and dropped it from subsequent editions. The simplest explanation is that he made errors in the encipherment.

05 Probably no message at all

The Chinese gold bar cryptograms no message — full write-up

Shanghai · 1933 · 16 strings, 263 letters

Settled. The 263 letters contain almost exactly ten of every letter of the alphabet: 21 of the 26 appear exactly ten times. Chi-squared against a uniform distribution is 1.25 on 25 degrees of freedom where random sampling predicts 25, a one-in-a-trillion level of over-uniformity, and none of 200,000 simulated random strings came close. No encryption does this: substitution and transposition preserve the plaintext’s skew, and a one-time pad is still random sampling and lands near 25. Somebody counted out ten of each letter and arranged them to look like cryptography.

The Beale papers no message

Virginia · published 1885 · three papers, one solved

Paper 2 genuinely decodes against the Declaration of Independence and describes a buried fortune. Papers 1 and 3 do not decode against anything. Testing paper 1 against the English-language Gutenberg corpus as a book cipher produced no key text, and its number choices do not behave like an encoding: its letter statistics through the Declaration are indistinguishable from random picks, where paper 2 stands 16 standard deviations clear, and it shows none of the repeated-number structure that a real encoding leaves. Add the anachronistic vocabulary in the pamphlet’s "1822" letters, long ago identified by Jean Nickell, and the sensible conclusion is that paper 2 was built as bait and the other two were filled in.

The Voynich manuscript no message?

c.1420, radiocarbon dated · about 240 pages

The most-studied text with no accepted reading, and the only one on this list where the category is genuinely contested. The manuscript is old and the parchment is real. But the script behaves oddly for a natural language: word structure is unusually rigid, words repeat adjacent to themselves far more than any known language allows, and the statistics differ measurably between sections. Six centuries of attention by linguists, cryptanalysts and computational methods have produced no key and no reading that survives scrutiny. A constructed language or a glossolalic text would look much like this, so meaninglessness is not proved; still, the weight of evidence has moved a long way from "cipher awaiting a cryptanalyst".

06 Genuinely open

Almost everything worth attacking on the famous list has been attacked to exhaustion. The items where effort still pays are elsewhere: archival ciphers of ordinary length, where a key survives in a collection nobody has connected to the ciphertext, or where the method is recoverable because the correspondents were not very good at this. Four entries on the working list were settled that way in this project. The key of a Richelieu letter was rebuilt from cribs beside its clear words; Avenel’s printed decipherment of 1858 was found afterwards and confirmed it. The codebook of John Armstrong’s coded postscript to Madison was rebuilt from a State Department clerk’s pencil decodes over other despatches. Of two Chinese telegrams of 1916, the one to Sun Yat-sen from Swatow was decoded after its condenser key was recovered from the ciphertext alone, and Huang Xing’s was decoded in part by aligning it with the decode the Japanese Foreign Ministry filed with it.

The famous list shows that fame is a poor guide to tractability. A cipher that resists usually does so for a structural reason, and the reason is usually visible in the statistics before any attempt at a solution.

07 Sources