Generated by Codex with GPT 5.6 Sol XHigh

Four Messages in Copper

For 35 years, the sculpture Kryptos stood outside CIA headquarters with one of its four encrypted passages still unsolved. Cryptographers cracked the first three sections in the 1990s, but the final 97-character message, known as K4, resisted every public effort. Then in September 2025 two journalists found its plaintext in the Smithsonian archives. They had not broken the cipher at all; they had discovered the answer in the artist’s papers.

That anticlimax carries the article’s central lesson. Cryptography is a contest between increasingly sophisticated mathematical locks and the people searching for weaknesses around them. The history of Kryptos shows both sides of that contest: ingenious ciphers can conceal a message, but any system remains vulnerable to clues, implementation mistakes and human behavior.

Encryption begins with plaintext, transforms it into unreadable ciphertext and relies on a secret key to reverse the transformation. The basic idea protects everyday financial transactions and online communication as well as spy messages. Its strength, however, depends on more than the number of possible keys.

How Old Ciphers Gave Way

The Caesar cipher shifts every letter by a fixed amount. Because the alphabet permits only 25 nontrivial shifts, an attacker can simply try them all. A substitution cipher seems far stronger: it scrambles the entire alphabet, creating 26 factorial possible keys, or more than 403 septillion arrangements. Yet it preserves the statistical patterns of language. In English, E appears far more often than Z, one-letter words are usually A or I, and common short words provide further clues. Frequency analysis can therefore defeat a key space too large for brute force.

Artist Jim Sanborn encrypted the first two Kryptos passages with the Vigenère cipher, which applies a repeating sequence of Caesar shifts. Its different shifts blur ordinary letter frequencies: two instances of E need not become the same ciphertext letter. But if a code breaker determines the key’s length, the message can be divided into groups encrypted by the same shift. Each group then becomes an ordinary Caesar cipher that frequency analysis can attack. Sanborn used the keys “PALIMPSEST” and “ABSCISSA,” along with a modified alphabet etched into the sculpture.

For K3, Sanborn used a transposition cipher. Instead of replacing letters, it rearranges them according to a rule. Because the original letter frequencies remain unchanged, the ciphertext itself hints at the method. At least three groups independently solved K1 through K3: an NSA team in 1992, CIA analyst David Stein by hand in 1998, and computer scientist Jim Gillogly with computer assistance in 1999. Their staggered disclosures also show that solving a code and publicly establishing priority are separate problems.

K4 and the Human Side Door

K4 appeared to promise a harder mathematical challenge. Modern encryption often protects data with problems, such as factoring enormous numbers, that are believed to require impractical amounts of computation. A fast general solution would not merely crack one puzzle; it would overturn a foundational assumption behind widely used security.

Journalists Jarett Kobek and Richard Byrne took another route. An announcement for Sanborn’s planned auction of the K4 solution mentioned original coding charts held by the Smithsonian Institution. They requested the documents and found scraps containing the plaintext, then e-mailed Sanborn the answer on September 3, 2025. The episode resembles a thief finding a password on a sticky note rather than defeating the lock it protects.

That is also how many real data breaches occur. Correctly implemented modern encryption generally holds, while attackers phish users, exploit software bugs or take advantage of misplaced secrets. Security is therefore a property of an entire system, not just its mathematics.

The discovery did not end the puzzle. Kobek and Byrne agreed not to reveal the plaintext, the public still does not know how K4 was encrypted, and the meanings of the first three passages remain obscure. Sanborn has also confirmed a fifth message. Kryptos endures because its deepest theme is not whether one cipher can be solved. It is the continuing race between mathematical protection and the fallible humans who create, store and use secrets.