21/09/2026

Bishop of Worcester's Latin Cipher with Superscripts Reconstructed from Decipherment in Print

I was told by Andrew Aymeloglu that plaintext of two of the Bishop of Worcester's letters in cipher is printed in publications. When I put them in my list of unsolved ciphers, I thought there was not much to be done to complete the decryption. As it turned out, however, many of the unidentified symbols represent whole words. It would have been hard to identify them from scratch. See "Bishop of Worcester's Latin Cipher with Superscripts (1526, 1529)".

One anonymous letter seems to employ the same cipher but has many yet unidentified symbols, many of which would be nulls or words. I re-marked this as yet unsolved.

20/09/2026

Two Diplomatic Ciphers of Marquis de Villars (1669, 1671)


Some letters from Louis XIV to Pierre Villars, Marquis de Villars, are put on auction at Spink (I thank Patrick Hayes for the information). They are interesting in the study of codes and ciphers early in the reign of Louis XIV.

One (1669) seems to use "Colbert-Croissy Cipher (1668-1674) (DE=68) but there still remain many unidentified symbols.

I reconstructed the cipher used in another (1671). As far as I know, it is the only French cipher that had no regularity in arrangement before Louvois' in 1676.

See "Two Diplomatic Ciphers of Marquis de Villars (1669, 1671)".


PS. Patrick Hayes also discovered a letter part of which is in "Cipher with Prince Rupert, Digby, and Ormonde (1644-1645)" ("King Charles I's Ciphers"). The letter is Digby to Prince Rupert, dated 12 July 1644. He provided additional elements:

83=.

87=:

h3=now

Many thanks for the info!

19/09/2026

Louvois' Petit Chiffre (1690-1691) Solved

Daniel Bourdeau solved "French Cipher Despatch received by General Catinat (1691)" in my list of "Unsolved Historical Ciphers".

He has been solving so many items in the past few days (he told me he solved 26, with avg 1-2 hours per problem) that I cannot catch up in updating my list. So I put a notice in my list that people about to start working should first check his website. As far as I have seen, his solution and analysis are of very high quality.

For this particular case, automatic codebreaking by AI failed. He found another ciphertext in the same cipher with a paraphrased translation, in which matching ciphertext-plaintext portions could be found from recurring symbols.

See "Solution of Louvois's Petit Chiffre (1690-1691)" and his github quoted therein.

18/09/2026

Two Chinese Cipher Telegrams (1916) Solved

Two Chinese cipher telegrams from 1916 presented in "Chinese Cryptography: 1871-1945" are now solved by Daniel Bourdeau.

The one is a telegram to Sun Yat-sen, for which he identified the code condenser (kind of superencryption) by brute force attack after cleverly narrowing down the search scope.

The second was not technically "unsolved" because the decryption is attached, but the encryption scheme has not been known. Bourdeau found it is a three-kana code. It still remains to be found out how the three-kana code groups are mapped to character numbers in a codebook.

See "Solution of Two Chinese Cipher Telegrams Archived in Japan (1916)" and Bourdeau's github pages quoted therein.


 

17/09/2026

Solution of a Syllabic Cipher (Le Tellier-Castelnau Cipher, 1657)


An undeciphered letter from Le Tellier to Marquis de Castelnau, dated 12 May 1657, is presented in "Ciphers Early in the Reign of Louis XIV". From other letters in Le Tellier's correspondence at the time, it is considered to be in a syllabic cipher. The ciphertext spanning a little over half a page seemed too short for a conventional solver for general syllable assignment.

To my pleasant surprise, it was solved by Robert Pitt. I guess the regularity of the assignment was given as a constraint or training data. The solution is described in a new short article, "Solution of Le Tellier-Castelnau Cipher (1657)".


12/09/2026

Protecting Authenticity of Documents against Breaking of Encryption Scheme by Quantum Computing

IonQ published a blueprint for breaking 256-bit elliptic curve signatures used in blockchain technology including Bitcoin (press release). Unlike prior work, they "compiled every operation down to the actual error-correction primitives our architecture runs. Today's paper proved - rather than assumed - a lower bound on the probability that the full computation succeeds." They estimated that solution of 256-bit ECDLP (elliptic curve discrete logarithm problem, the classically intractable mathematical problem underlying elliptic curve cryptography) on secp256k1 (parameters specifying a specific elliptic curve on which mathematical operations are done) takes 25.7 days per attempt, by using 19397 physical qubits (quantum bits) implementing 1457 logical qubits and 39 million Toffoli gates (means for operating on qubits). (Use of quantum states necessitates complicated error correction schemes, which inflates the number of physical qubits required to implement logical qubits.)


I was reminded of an issue of potentially compromising authenticity of documents by their remark, "The cryptographic exposure this work describes relates to authentication and integrity rather than to confidentiality.... Unlike an attack on encrypted data, a signature compromise is exploitable going forward rather than retroactively against traffic recorded today. "

The threat to confidentiality is already quietly underway through a strategy known as "Harvest Now, Decrypt Later" (my blogpost). On the other hand, breaking of the signature scheme does not allow tampering with a document already signed with the scheme. Instead, it allows an attacker to derive a private key from a public key, which means that the attacker can put an authentic digital signature to a forged document. Suppose there is a digitally signed document stating "The President is very unpopular." Even with the knowledge of the private signature key, the attacker cannot falsify it to read "The President is very popular." Instead, however, it will be possible to create a new document stating "The President is very popular." and put a digital sign to authenticate it.

The same applies for digital timestamping because digital timestamping works by putting a digital signature to a combination of a hash of a document and a timestamp by a trusted timestamping authority to prove that the document was present at the time indicated by the timestamp. If the signature scheme is broken as of 2030, the attacker can create a document stating "The President is very popular." and add to it a valid timestamp of 2026.

Experts are aware of the issue and one (cenceptually) simple solution is timestamp renewal, whereby a document with a timestamp as a whole is wrapped in another layer of digital timestamping with a new (e.g., quantum-resistant) signature scheme. But this renewal need to be done before the original signature scheme is broken.

08/09/2026

Wellington's Code/Cipher during the Peninsular War

Some months ago, I wrote about a British book cipher during the American Revolutionary War. This time, I uploaded a new article about Wellington's dictionary code: "Wellington's Polyalphabetic Cipher with a Dictionary Code". For words/names not found in the dictionary, a polyalphabetic cipher with heavy nulls was used.

My observations are based on Wellington's despatch to General Maitland dated 2 September 1812. I thank George Lasry for the information of the auction of the letter at Spink.

06/09/2026

Route Transposition Ciphers during the US Civil War Solved by using AI

Two undecoded telegrams to Union General Milroy were solved by Richard Bean, who had Claude Opus 5 solve them. While there are many papers about codebreaking with AI (see my blogpost for some), this is the first case that I see commonly available generic AI solve a real historical cryptogram.

I note the transposition route is the same as that of Stager Cipher No.7 albeit with a different number of lines. I uploaded a new article "Stager Cipher No.7 Continued in Use after Abandonment" about this.

16/08/2026

US Codebreaking Activities in Tokyo during the Korean War

I updated my recent article "Korean Cryptography" with additional specimens from John Milmore (2002), #1 Code Break Boy. The book, written like an unedited memorandum of an eyewitness, is interesting in recording US codebreaking activities on North Korean traffic during the Korean War, in which the author was "the principle cryptanalyst" (p.3).

It is more interesting to me because the codebreaking unit was headquartered in Tokyo (Japan was still under occupation after WWII). The photo below is a recent view of the building used as the headquarter (from Wikipedia). 

 


 

10/08/2026

How Long Does It Take to Decipher a Despatch?

How long did it take for a secretary to decipher a despatch? Sometimes we see a reply to a ciphered despatch received the night before, in which case we know that the deciphering of the original letter and the enciphering of the reply were done in a day. It is desired to find such an instance for which the original letter in cipher is available. If the letter is a long one, a better upper bound estimate can be made.

An informal experiment I recently read about this (I thought it was in Desenclos and Clinet (2025) (BDN) but apparently I misremembered it) induced me to try it myself. It took me twenty minutes to decipher a page.

But of course, this depends on many factors.

(i) The page is almost entirely in cipher but the number of symbols on the page (about 340) is modest. (One instance of a letter of Mary, Queen of Scots, has more than 4000 symbols on a page.)

(ii) Of these, almost 80% are single letters, with only about 20% being symbols for syllables and names. While the cipher has three or four homophones for each letter of the alphabet, after getting familiar with the cipher, one can work with this much (as well the most frequent syllables and code numbers such as "re", "de", "se", "que", "luy", "dit") from memory. If the cipher used syllables and codes more extensively, it would have taken more time in consulting the cipher table.

(iii) I was familiar with the cipher because I had been working with it for two weeks before the experiment. When one works with a new cipher, much longer time is necessary.

(iv) The deciphering work may be delayed if symbol shapes are hard to identify. In this regard, this particular case posed difficulty because of ink bleed-through. For this experiment, however, its influence was negligible beause I simply skipped the hardest cases for the experiment.

(v) There is interlinear decryption, but I did not refer to it for the experiment. (Actually, I had worked on this particular page before but I'm sure I did not remember the content.)

(vi) I worked on a pdf file, which is not very convenient as far as writing deciphered text is concerned. If I had worked on paper, it would have taken much less time.

26/07/2026

Mirabeau's Cipher

Mirabeau's undecoded letter (1787) (see my blogpost) reminded me of the famous cipher devised by him, which is now described in a new article, "Mirabeau's Cipher".

It includes several open questions. If someone have any ideas, please let me know.


 

24/07/2026

A "Coded" Message from a Tang General to a Korean General

In Western history, there are many prominent historical figures who used code/cipher. But in China, Korea, or Japan, use of code/cipher was not common before the modern era. So an episode from the Tang period as an introduction for a narrative of Korean patriot codes in the Japanese colonial period on a Korean website I cited recently caught my attention. As expected, it is more like a riddle than code/cipher.

The episode is recorded in Memorabilia of the Three Kingdoms (三國遺事) (Wikipedia):

又古記云。總章元年戊辰〈若總章戊辰則李勣之事而下文蘇定方誤矣。若定方則年號當龍朔二年壬戌來圍平壤之時也〉國人之所請唐兵屯于平壤郊而通書曰。急輸軍資。會群臣問曰。入於敵國至唐兵屯所。其勢危矣。所請王師糧匱而不輪其料。亦不宜也。如何。庾信奏曰。臣等能輸其軍資。請大王無慮。於是庾信仁問等率數萬人入句麗境。輸料二萬斛乃還。大喜。又欲興師會唐兵。庾信先遣然起兵川等一人問其會期。唐帥蘇定方紙畫鸞犢二物迴之。國人未解其意。使問於元曉法師。解之曰。速還其兵。謂畫犢畫鸞二切也。於是庾信迴軍。欲渡浿江。今日後渡者斬之。軍士爭先半渡。句麗兵來掠。殺其未渡者。翌日信返追句麗兵。捕殺數萬級。(text from Database of East Asian World History Research Center (東アジア世界史研究センター))

Korea was divided into three major kingdoms: Goguryeo (高句麗), Paekche (百済), and Silla (新羅) for several centuries. Silla, allied with Tang (China), conquered Paeckche in 660 and then Goguryeo in 668. Kim Yu-sin (金庾信) (Wikipedia) was a leading figure in the unification of the Korean Peninsula under Silla.

In 668, when a Tang army under General Su Dingfang (蘇定方) (Wikipedia) (so goes the record, but either the year or the name of the general must be wrong because Su died in 667) was camped near Pyongyang, capital of Goguryeo deep behind the border, Silla was to join the Tang army. General Kim Yu-sin sent forward a small detachment to ask for a schedule. General Su Dingfang replied by drawing a young phoenix (鸞) and a calf (犢). When Kim's staff was puzzled by this mysterious letter from the ally, an eminent scholar-monk Wonhyo (元曉) (Wikipedia) figured out that the riddle can be solved by fanqie (反切), a technique whereby the pronuciation of a character is indicated by the initial consonant of a first character and the ending of a second character.

With this technique, the drawing of a calf (畫犢) (hwa-dok) reads hok, and the drawing of a young pohenix (hwa-ran) (畫鸞) reads hwan. That is, the two drawings refer to hok-hwan, which is somehow understood to be sok-hwan (速還), meaning "Retrun quickly". (I relied on the Hangul rendering of the characters in the transliterations here. Maybe we need to check the old pronunciation of these characters.)

This saved General Kim Yu-sin's army from annihilation.

Similar stories, if not fanqie, may abound in the world. In the Warring States Period in Japan, when warlord Oda Nobunaga was attacking the Asakura clan in 1570, his back was threatened by the Azai clan, supposed to be an ally. Nobunaga is said to have been warned of the imminent danger by his sister Oichi, wedded to Azai Nagamasa. She sent a pack of beans with both ends tied, which revealed the pincer movement by his enemies. While one might deplore such crucial information not being conveyed in a more straightforward message, this episode is considered apocryphal (Wikipedia).

23/07/2026

Update on Korean Ciphers

I have been wondering how Hangul script can be enciphered. While mentioning some possibilities in "Substitution Cipher for Hangul", I have not seen historical instances. Then, Torbjörn Andersson from Sweden, who saw my first blogpost, told me of actual examples, in which a straighforward solution of separately representing consonants and vowels forming Hangul characters was actually used. This first clue allowed me to do some search and I now uploaded a new article, Korean Cryptography.

14/07/2026

Mirabeau's Undecoded Letter (1787)

In addition to the Spanish decryption of a French cipher mentioned yesterday, Desenclos and Clinet (2025) presents their own decryption of a letter of Francis I to Christophe Richer, mbassador to Denmark (21 January 1547). The feat was achieved in February 2025 by Ioana Ionescu under the supervision of Paul Zimmermann and was completed and verified by Camille Desenclos with the key found in the archives (BnF NAF 8431, f.182). By comparing the ciphertext and plaintext, it can be seen that the cipher has homophones, double letters, nulls, and symbols for short words or titles ("que", "je", "faict", "et", "le roy de Danemarck", "Escossois", "le roy d'Angleterre", etc.).

They also present an undecoded letter of Mirabeau (the last image of the article). They give a date of 12 April 1787, but the cleartext seems to be "X. en reponse au no 3. le 12 aout". Anyway, if this is 1787, it is shortly after he came back in January 1587 from a stay in the Prussian court, where he had been sent on a mission by the Foreign Minister Vergennes. (His trip is recorded in Histoire secrete de la cour de Berlin (Internet Archive; translation: The Secret History of the Court of Berlin (Internet Archive).)

The ciphertext is transcribed below:

549 1450 623 506 71 611 1296 61 57 1146 713 884 1017 878 556 655 846 703 991 984 791 806 1023 511 723 482 814 467 1090 1030 687 705 1151 426 934 1059 1002 99 1231 882 738 1199 1071

Mirabeau is said to have devised, during imprisonment when young, a cipher for representing a letter with two figures (LANAKI), but it would have been for personal use.

The short specimen above seems to be a full-fledged diplomatic code and has a number as high as 1450, which is higher than the size of typical French codes at the time (see my blogpost). It is wondered whether the code really had about 1500 entries (rather than using high numbers as nulls). If the above is all we've got, cryptanalysis would be impossible. But code numbers from the following page are faintly visible. If more pages (actually, it has to be many more pages) are available, it may be an interesting challenge for codebreakers.

13/07/2026

Spanich Decryption of Claude Blatier's letter (1582)

One of many interesting pieces described in Desenclos and Clinet (2025) mentioned the other day is the Spanish decryption of a letter of Claude Blatier in Tournai to Henry III (23 October 1582). The arrangement of the decrypted key with borders is very similar to that in the decryption of the Duke of Anjou's cipher I quoted from BNE in "French ciphers during the Reigns of Charles IX and Henry III". Probably Blatier's cipher was also decrypted by the same Spanish codebreaker, Luis de la Cerda.

My article mentions a short ciphertext of a Claude Blatier du Belloy, a French agent in the Low Countries, with what seems to be the plaintext in the margin. I was hoping to establish the mapping between the cipher symbols and the plaintext, but the Spanish key does not seem to match. So this short specimen remains a riddle. (Some letters of Sr Blatier in the Low Countries (1584) in BnF fr.16127 (f.196 ff.) do not include cipher.)

12/07/2026

Ciphers in the Archives of French Foreign Ministry

Desenclos and Clinet (2025) I mentioned yesterday not only provides many images but also the authors take care to cite primary sources to support their statements. Especially, materials from the archives of the Foreign Ministry are new to me.

Among others, I was excited to see the image of the original cipher for the French plenipotentiaries for the Treaty of Ryswick in 1697. It is the same as the cipher used by them in a first talk in Ryswick in 1694, of which I posted a reconstruction in "French Ciphers during the Reign of Louis XIV". (It will be seen that the reconstruction on my page needs some correction: the inflectional endings "ais" and "ait" should be "ois" and "oit" according to the convention at the time.)

Conversely, I posted the original cipher between Henry IV and the Landgrave of Hesse-Cassel in "French Ciphers during the Reign of Henry IV of France" but the specimen from BnF fr.15920, f.162 (Gallica) was not in my list.

These are only two of the many materials included in this article. It is a treasure trove for students of French historical ciphers.

11/07/2026

Earliest French Ciphers (1507, 1513, 1521)

Introduction of ciphers in France was later than in Italy or Spain.

While absence of extant ciphertext does not mean there was no cipher, the pursuit of the earliest specimen is not without merit. As of 2018, the oldest specimen was from 1526. In 2023, I thought specimens from ca.1520-1521 might be the oldest (blog post; identified as Antoine Duprat's reports (1521) in Camille Desenclos and George Lasry, "Cryptanalytic and historical challenges with unidentified encrypted documents from the early modern era" (HistoCrypt 2025), 2.2).

But I now see a specimen from 1513 had already been reported in Camille Desenclos (2021), "Le premier essor de la cryptographie en France (1510-1630)" (HAL). It is a letter in cipher from Louis de Solliès to Florimond Robertet, dated 8 July 1513 (BnF Dupuy 261, f.121).

And now, an even earlier instance is given in Camille Desenclos and Sarah Clinet (2025), "Diplomatie et gestion du secret" (Bibliothèque diplomatique numérique (BDN)). It is Robert de Gramont to Georges d'Amboise (ca. 1507) (BnF fr.2930, f.189 (catalogue info)).

09/07/2026

Heavy-Null Cipher Challenge

Inspired by Henry of Navarre's cipher posted the other day, I created a challenge cryptogram.

It is a monoalphabetic substitution cipher and the plaintext is English. The catch is that it includes a large number of nulls. I know once nulls are removed, modern computers would solve it in an instant. But I suppose trying every possible combination of 26 significant symbol numbers is not computationally feasible.

If someone succeeds in solving this, please let me know how this can be broken.

79 41 80 68 50 26 82 76 61 80 92 66 13 18 52 56 17 46 71 25 64 79 98 74 18 93 18 51 26 81 67 75 35 37 71 73 46 74 52 29 52 26 16 95 85 65 30 14 31 24 26 35 82 78 66 37 95 28 85 69 25 39 26 36 15 51 52 35 64 41 19 41 69 50 82 14 28 31 32 26 85 78 95 65 55 40 64 46 27 44 90 11 27 64 26 37 37 26 47 35 37 55 41 92 61 38 36 15 13 59 73 41 99 80 69 46 83 79 35 39 24 91 44 26 68 59 79 37 69 73 93 79 68 49 82 49 87 18 94 36 45 59 90 16 66 66 83 33 28 26 44 49 18 26 18 68 29 35 73 81 85 33 90 16 28 95 69 26 91 97 35 91 57 43 56 20 30 23 58 52 26 44 73 80 66 55 10 37 55 44 89 55 83 92 32 22 91 91 44 40 13 79 16 79 29 98 62 99 87 27 17 24 28 53 63 58 35 46 82 55 48 25 85 74 45 52 18 68 96 11 16 15 45 42 44 74 35 19 44 39 47 37 68 35 56 66 73 55 22 42 80 34 84 25 90 44 14 32 89 13 98 92 37 46 68 49 43 24 15 34 35 39 65 44 47 66 71 64 26 40 35 76 99 96 96 92 53 25 26 37 46 15 69 15 40 92 35 46 11 26 31 86 94 75 84 85 84 52 31 66 92 55 77 49 26 87 79 82 74 37 70 19 69 55 34 83 23 73 93 28 44 29 34 91 90 28 90 87 35 56 87 40 49 81 67 15 34 46 25 93 64 63 34 33 46 51 87 26 25 67 49 48 96 61 59 64 66 80 66 73 23 64 52 91 93 26 31 62 11 97 28 44 34 45 56 46 20 65 27 67 34 32 37 83 22 46 68 14 52 40 49 10 43 38 18 35 66 43 70 26 34 46 60 32 36 68 90 76 68 80 38 82 96 22 94 11 67 41 96 55 67 67 61 37 48 71 47 71 10 55 92 27 24 18 67 40 24 92 93 66 28 87 23 23 26 58 94 94 83 84 15 65 61 49 65 27 98 45 46 99 30 92 14 80 98 52 18 67 47 82 31 66 41 22 85 48 25 55 81 17 27 42 82 41 50 71 26 44 15 13 60 30 71 46 51 81 26 30 26 34 44 37 47 26 25 22 53 75 66 90 69 26 34 91 36 42 49 84 34 55 35 46 84 36 36 55 68 90 44 73 13 98 25

(To insert the null symbols, I used a Perl script generated by AI. Of course, I verified that the above can be decrypted correctly. Randomness based on the rand() function may not be ideal but I believe it served the purpose. On the other hand, when I first asked AI to create a random sequence, it failed my expectation.)

06/07/2026

Heavy Use of Nulls in Henry of Navarre's Cipher (1586)

More than half of the symbols are nulls in a letter (1586) from Henry of Navarre, later Henry IV of France. I have observed several French cipher letters employing many nulls, but this is by far the heaviest use of nulls.

I uploaded a new article, "Heavy Use of Nulls in Henry of Navarre's Cipher (1586)" to report this. 


 

03/07/2026

Ciphering Errors of Elizabeth Stuart, Queen of Bohemia

Elizabeth Stuart, Queen of Bohemia, tried a polyalphabetic cipher in her correspondence with Thomas Roe, as described in "Ciphers in Early Stuart England before the Civil War". It switches Caesar substitution tables between words or word fragments. The key in Arabic figure placed before the word (fragment) indicates the shift in the Caesar cipher (counting from the plaintext itself). Thus, when the key is 4, "a" is enciphered as "d".

This cipher is called "Key 1 Roe" in Nadine Akkerman (ed.), The Correspondence of Elizabeth Stuart, Queen of Bohemia, Volume II (2011), p.1062, according to which only the keys 4, 5, 6, and 7 were used (obviously because larger shifts would make the counting too cumbersome).

Nadine Akkerman and Pete Langman (2024), Spycraft: Tricks and Tools of the Dangerous Trade from Elizabeth I to the Restoration provides specific examples (p.388, n.134). A typical ciphertext is:

I have had newes from K.[Arundell] 50.[Emperor] 6nfzn.[hath] 4kmyhq4.[giuen-] 4lmp.[him] 5mnw[hir] last 4dkwzhu[agswer]

("K" and "50" are nomenclature elements.) 

This short specimen includes two enciphering errors: "hir" should be "his" and "agswer" should be "answer". The first error is a simple counting error, while the latter error arose because counting was in the opposite direction. That is, for the plaintext letter N, the fourth letter afterward, Q, should be the ciphertext letter, instead of which the ciphertext actually includes K, the fourth letter forward.

Similar errors due to opposite shifting were made when "electorat" was enciphered as "4bobz5yswey" (p.387, n.132). Here, E is incorrectly enciphered as B (instead of H) and C is incorrectly rendered Z (instead of F).

Akkerman and Lagman considers this kind of errors suggests use of a cipher wheel. That is, this can be readily explained as "reading the plaintext on the inner wheel and the ciphertext on the outer, that is, the 'wrong' way around". (You can see this by switching the plaintext and ciphertext lines in the above image.)

I think, however, counting in the opposite direction is more likely. The fact that only four shifts (4, 5, 6, 7) were used seems to show that Elizabeth did not have a table or a wheel at hand when working on the cipher. She was counting for enciphering each letter.