Frequently Asked Questions
The basics
Is Kryptos K4 solved?
No. As of September 2026, K4 remains unsolved after more than 35 years: no one has published its plaintext or its encryption method. In September 2025 two writers, Jarett Kobek and Richard Byrne, found scrambled strips of the plaintext among Sanborn’s papers at the Smithsonian’s Archives of American Art. Sanborn confirmed the find but stressed that “K4 has not been solved or decrypted”, because the coding method and key were not found. The finders have pledged not to release the text.
Why can’t computers just solve K4?
K4 has only 97 characters, too short for most statistical attacks to distinguish signal from noise. Repeating-key ciphers on the standard or KRYPTOS alphabet are ruled out at every key length from 1 to 26 when each carved letter decrypts to the plaintext letter in the same position. Pure transposition is independently impossible (the ciphertext has 2 E’s but the 24 known plaintext letters contain 3), so K4 must involve at least some substitution. The exact multi-step structure is unknown. There are an astronomically large number of possible methods that could produce the 24 known letters, far too many to test one by one. Solving K4 requires identifying the specific method, not just trying all keys — and the public evidence currently available is not specific enough to identify that method. (At the 1990 dedication Sanborn said there are “two systems of enciphering the bottom text”. The bottom half of the panel holds both K3 and K4, so how that applies to K4 alone is an interpretation, and this project treats such remarks as context, not as a specification of the method.)
What has been tried
What has already been tried?
597 recorded experiments covering 721.7B+ configurations have been run, testing every major classical cipher family: Vigenère, Beaufort, columnar transposition, Playfair, Bifid, running keys, and more. The standard single-layer classical ciphers have been eliminated under direct positional correspondence (where ciphertext position N maps directly to plaintext position N), with some gaps still open in our published record, including running keys taken from texts we have not tested; repeating-key ciphers that use two different keyword-mixed alphabets; a Gromark cipher with keyed alphabets on both sides; keys longer than our checks cover (for example, repeating keys of 27 to 29 letters, or 53 or more); and Trifid and Bifid on a 6×6 square, whose tests were not conclusive. These eliminations do not rule out the same families as one layer of a multi-layer construction. Browse the full database to see what has been tested.
Did you try scrambling the letters AND using a keyed substitution?
Yes. It is one of the most common suggestions we get, and it has been tested extensively: many letter-rearrangement methods (columnar, rail fence, route, serpentine, spiral, Myszkowski and others) combined with keyed substitution (Vigenère, Beaufort and Variant Beaufort with repeating keys). None produced a solution. Some of these searches used a consistency check that turned out to be invalid once letters are rearranged; see below for what was withdrawn and what was re-run.
Every one of these starts from ABCDEFGHIJKL.
Rail fence
write in a zigzag across three rails, read each rail
reads out AEIBDFHJLCGK
Columnar
write in rows, read the columns in key order
reads out BFJDHLAEICGK
Serpentine
write in rows, read alternating left to right and back
reads out ABCDHGFEIJKL
Spiral
write in rows, read inward from the top-left corner
reads out ABCDHLKJIEFG
An earlier version of this page said we had mathematically proved that 17 of 25 key lengths fail for every possible rearrangement. That proof was withdrawn in August 2026: it relied on a consistency check that is only valid when the letters stay in place, and a counterexample showed it was false. We re-ran the columnar searches without that check. For every grid width from 4 to 9 and every column order (substitution first, then rearrangement), no repeating key of length 1 to 24 on the standard alphabet fits the 24 known letters; at lengths 25 and 26 there are too few known letters to tell a real key from chance. Other rearrangement searches that relied on the withdrawn check have been reopened, so a repeating key combined with a rearrangement we have not re-searched is not ruled out.
However, some combinations remain open: if the substitution uses a non-repeating key (like a passage from a book, or a self-keying cipher), the rearrangement + substitution model is still possible. This is still an open residual family, though the April 2026 audit no longer treats it as the project’s leading hypothesis. See the multi-layer category for full details.
Why can’t you just try every possible letter rearrangement?
K4 has 97 characters. The number of possible rearrangements of 97 characters is 97! (97 factorial), which equals approximately 10152. For comparison, there are roughly 1080 atoms in the observable universe. Even if every atom in the universe were a computer testing one billion rearrangements per second, running for the entire age of the universe, you’d barely scratch the surface.
This is why we test structured rearrangement methods — methods a human could describe with a rule (like “write into 8 columns, read them in this order”). We assume that a human encryptor like Sanborn used a describable method, not a random shuffling.
What about [specific keyword] as the key?
We’ve tested hundreds of thematic keywords including KRYPTOS, PALIMPSEST, ABSCISSA, BERLIN, TUTANKHAMUN, SANBORN, SCHEIDT, COMPASS, SHADOW, SPHINX, and many more. But more importantly: the specific keyword doesn’t matter for most cipher types we’ve tested, because for repeating-key ciphers on the standard or KRYPTOS alphabet we ruled out every possible key of every length from 1 to 26 letters (when each carved letter decrypts to the plaintext letter in the same position), which covers any keyword of that length you could name.
The exception is running keys (where a long passage of text is the key). For those, the specific source text matters, and we’ve only tested texts that are publicly available. If Sanborn used a private or unpublished text, we wouldn’t have tested it.
What approaches remain open?
Most standard single-layer cipher families have been eliminated under direct positional correspondence and additive-key assumptions, including repeating-key ciphers on the standard or KRYPTOS alphabet (impossible at every key length from 1 to 26), self-keying ciphers with a starting key of up to 25 letters, and running keys from 60,000+ publicly available English texts (about 53 billion position-checks in this reading). Some ciphers built on keyword-mixed alphabets are not yet ruled out in our published record: repeating-key ciphers that use two different mixed alphabets, and a Gromark cipher with keyed alphabets on both sides. By April 2026 we had also enumerated 105,692 two-layer compositions and 838,350 non-columnar three-layer compositions within our registered layer families with no signal above noise. Classical cipher space has infinite variation, so this does not rule out everything; it describes what we have tested.
Open directions we are interested in:
- W-delimiter or other finite segmentation procedures. The narrower idea that the
carved
Ws decrypt to separator letters such asXorQis not on this list; see Finding 1 for why. - Running keys from non-public or non-English source texts
- Monoalphabetic + transposition + running-key compositions. In June 2026 tests at K4’s 97-letter length, the strongest detector we built for this family scored real and shuffled text alike (0 of 6 planted test cases detected). It stays open as a limit on what we can detect rather than as a lead.
- Bespoke procedural ciphers using Sanborn’s encoding charts or other physically motivated rules
- Non-standard transpositions, homophonic or digraphic outer layers, and anything else not yet in our layer registry
- A genuinely novel mechanism we have not thought of
If you have an idea we have not tested, the Submit a Theory page is the fastest way to route it into our classifier. See also the Research Questions page.
Contributing
Can I submit my own theory?
Yes. Use the Submit a Theory page. Describe your idea in plain English and an automated classifier, which can be wrong, will check whether it matches anything in the elimination database. If it looks new, specific and practical to test, it is queued for a person to review.
About this project
How do I know your results are correct?
Most elimination pages include a reproduction command you can run yourself. The code is public on GitHub, though the public copy can lag behind the working version, and most of the stored result files these pages are built from are not in it, so rerunning a command is the way to check a result. We also classify results by confidence tier and list explicit scope limitations for each elimination. If you find an error, report it and we will investigate.
Who built this?
kryptosbot.com is built by Colin Patrick (human lead) and Claude (AI computational partner, by Anthropic). The project began as a systematic attempt to solve K4 using computational cryptanalysis and evolved into a public elimination database so the community can build on our work rather than re-testing approaches that have already come up empty. This site does not know the solution and is not affiliated with Paradigm Operations LP or any other rights holder or verifier of the official solution.