721.7B+ configurations evaluated across recorded experiments

After 721.7B+ configurations tested

What we’ve learned

None of the standard single-layer classical ciphers fully tested so far has survived against K4 under the project’s direct-positional, additive-key test frame; a few, such as repeating-key ciphers with two different keyword-mixed alphabets, Gromark with keyed alphabets on both sides, and Trifid, have been only partly tested. Large bounded slices of two-layer and three-layer classical space are also saturated, and a 2026 program extended the negatives beyond the standard reading: scoring after undoing candidate rearrangements, and letting the known plaintext words land anywhere in the output, both closed cleanly at millions of configurations. The CT-perturbation idea (small transcription differences between Sanborn’s archived coding charts and the carved text) was tested at one-letter depth and closed negative in May 2026; follow-up searches in August and September 2026 (a missing or wrong letter under the KRYPTOS-alphabet cipher used for K1 and K2, and a single wrong, missing, extra or swapped letter combined with a grid rearrangement) also found nothing within their tested ranges. These results are narrower than they sound: no single-letter error in the carved text unlocked K4 under the cipher families, alphabets and keyword lists tested. It does not show that the carved text is correct, and two-character differences anchored to the archive were never run. The W-delimiter interpretation stays available only as one ingredient of a multi-step scheme, and several earlier “signals” were retired after stricter controls.

Status as of September 29, 2026: K4 remains unsolved: no verified plaintext has been published. (In September 2025 Jarett Kobek and Richard Byrne found scrambled plaintext strips in Sanborn’s papers at the Smithsonian’s Archives of American Art. Sanborn confirmed the find but said it does not reveal the coding method or key, and the files were sealed. Paradigm, which now holds Sanborn’s Kryptos archive, runs an online checker for K4 guesses without publishing the answer.) An end-to-end audit in June 2026 of every candidate answer this project had produced up to then (13,302 of them) confirmed zero survive verification, and the searches run since, through September 2026, have also come back empty. Computer searches continue, but the main open leads are physical and archival, such as newly documented circled letters on a tableau in the sculptor’s working papers (not yet analyzed; any use for K4 must be preregistered first) and planned measurements of the sculpture itself. A longer technical status report is in the research repository as docs/REAL_K4_CURRENT_POSITION.md; it is dated June 2026 and does not include the August and September 2026 corrections described below.

Hover or tap a letter to see its position. Positions on this page count from 0, as in the project’s code; most public sources count from 1, which puts EASTNORTHEAST at 22–34 and BERLINCLOCK at 64–74. Colors show known plaintext regions and the Stehle anomaly zone.

O B K R U O X O G H U L B S O L I F B B W F L R V Q Q P R N G K S S O T W T Q S J Q S S E K Z Z W A T J K L U D I A W I N F B N Y P V T T M Z F P K W G D K Z X T J C D I G K U H U A U E K C A R
Known plaintext (crib) Stehle anomaly region Ciphertext
Position:

What 721.7B+ configurations told us

The site has accumulated a large negative map of bounded classical search space. Under direct positional correspondence (where ciphertext position N maps to plaintext position N), the current repo state supports the following:

  • Repeating-key Vigenère, Beaufort and Variant Beaufort, on the standard or the KRYPTOS alphabet, at every key length 1–26: mathematically impossible within the direct-positional additive-key model. With one keyword-mixed alphabet used the way K1 and K2 used theirs (the same mixed alphabet for plaintext and ciphertext), key lengths 1–22, 24 and 25 are ruled out whatever the keyword. Versions with two different mixed alphabets are not fully ruled out.
  • Self-keying (autokey) ciphers (keyed by the plaintext or by the ciphertext; Vigenère, Beaufort or Variant Beaufort; standard or KRYPTOS alphabet), applied directly to the carved text: no starting key of up to 25 letters fits the known plaintext. Some starting keys of 27 letters or more can fit, so this result does not cover longer keys. With a letter-rearrangement layer added, self-keying is not ruled out either: an unrestricted rearrangement leaves too much freedom for the known letters to rule it out, which is not the same as evidence for it.
  • Standard fractionation ciphers (Bifid, Playfair, Two-Square and Four-Square on 5×5 squares; ADFGX and ADFGVX): ruled out in their standard forms by simple structural facts. A 5×5 square holds only 25 letters, and K4 uses all 26; ADFGX and ADFGVX always produce an even number of letters, and K4 has 97. Trifid (27 symbols) and Bifid on a 6×6 square (36 symbols) are not covered by this argument, and the project’s tests of them are not conclusive.
  • Many structured rearrangement + repeating-key combinations: negative within their tested families. An earlier shortcut proof that claimed to rule out repeating keys of most lengths under any rearrangement was withdrawn in August 2026 (it applied a key-consistency check in the wrong frame). The column-rearrangement cases (widths 4 to 9, standard A-to-Z alphabet, key applied before the rearrangement) were then searched again directly at key lengths 1 to 24, and none fits.
  • Running keys from 60,000+ public English texts (Project Gutenberg’s English-language texts), read straight across the carved text with no rearrangement, and across 73-letter versions with suspected filler letters removed: zero candidates across 106 billion position checks (best 10 of 24 known letters, a chance-level score). Running keys combined with rearrangements have been tested only for a limited set of source texts, such as the first volume of Howard Carter’s The Tomb of Tut-ankh-Amen under column and route rearrangements (no signal). An April 2026 claim that column rearrangements at widths 6, 8 and 9 block every running key, whatever the source text, was withdrawn in August 2026: it rested on a key-consistency check applied in the wrong frame. None of this rules out running keys from other texts, non-English texts, or with other rearrangements.
  • Two-layer and three-layer compositions: an April 2026 count gave 105,692 two-layer branches (additive × transposition, transposition × repeating-key substitution, 6 stateful families) and 838,350 non-columnar three-layer branches, with a best of 7 of 24 known letters on the three-layer set. Later campaigns (May to September 2026) added more than 100 million further multi-layer configurations, such as 17.5 million in May 2026 that combined two rearrangements with a keyword substitution. All noise within the families and keyword sets tested.
  • Many bespoke or historical systems (VIC, RS44, Wheatstone, interrupted-key, DRYAD): all noise within tested scope.

These eliminations describe the scope of what we have tested under specific assumptions. They do not claim that K4 cannot be solved by classical cryptanalysis; classical cipher space has infinite variation, and any bespoke procedure, non-standard transposition, or combination outside our tested scope remains open. We document concrete negatives so the community does not have to re-test approaches that are already known to fail, not to suggest the problem is closed.

These eliminations do not rule out the same families as one layer of a multi-layer construction; that includes self-keying, which is not ruled out once a letter-rearrangement layer is added. The repeating-key, self-keying and running-key results do not apply if K4 uses a non-additive cipher mechanism, and the results that read the carved text straight across assume that each carved letter decrypts to the plaintext letter in the same position (see “What remains unknown” below). See the elimination database for the full inventory, and the open questions for what remains.

The research code is public on GitHub, though the public copy can lag behind the working version. Most elimination records include a reproduction command.

1

The W-Delimiter Structural Lead

A live layout hypothesis, not a settled claim

structural

The short version

Delete the five carved Ws at positions 20, 36, 48, 58 and 74 and the old width-21 vertical-bigram anomaly disappears. That looked for a while like an explanation. A May 2026 audit showed it is not one: replace every W with any one other letter, keeping the text 97 characters long, and all eleven repeated bigrams survive intact. A September 2026 audit explained why: the count depends only on which positions hold the same letter, so replacing every W with one other letter cannot remove any of the eleven, while deleting a letter shifts every later position and breaks the pairs that straddle the deletion. Deleting other letters spread through the middle of the text weakens or removes the anomaly in the same way. What the anomaly responds to is where letters are deleted, not which letters they are. By April 2026, 80+ direct single-layer W-segmentation hypotheses had been tested, with no signal. W-segmentation is therefore no longer the primary anchor. It remains admissible inside multi-layer hypotheses, and the public reading is still “if K4 has a delimiter or row-end mechanism, the W positions are the cleanest bounded place to test it,” not “the Ws are proven delimiters.”

The 97 characters, broken at the five Ws
0–19 O B K R U O X O G H U L B S O L I F B B W 20
21–35 F L R V Q Q P R N G K S S O T W 15
37–47 T Q S J Q S S E K Z Z W 11
49–57 A T J K L U D I A W 9
59–73 I N F B N Y P V T T M Z F P K W 15
75–96 G D K Z X T J C D I G K U H U A U E K C A R 22
Six runs of 20, 15, 11, 9, 15, 22, totalling 92 once the five delimiters themselves are set aside. The tinted cells are the known plaintext. Note where they fall against the run ends: only 2 characters separate EASTNORTHEAST from the next W, and 4 separate a W from the start of BERLINCLOCK.

What we know and don’t know

We know the width-21 effect is not explained by W placement: it survives replacing every W, and deleting other letters from the middle of the text weakens or removes it too (deleting from the very start barely changes it). Removing all eight Ks leaves one repeated bigram; removing all five Ws leaves none. The Ws sit between positions 20 and 74, never more than 16 apart, so almost every stretch of 21 letters contains one, and deleting them breaks all eleven pairs. The anomaly therefore says nothing about the Ws. We also do not know whether the Ws are ciphertext, filler, row-end markers, or some other procedural feature. What the W positions give us, independently of the anomaly, is a finite structural test surface: six segments with fixed crib geometry, including only two characters after EASTNORTHEAST and four before BERLINCLOCK.

One reading that keeps coming up is a punctuation or marker convention: that after decryption some or all carved Ws would turn out to be plaintext letters such as X, Q or Z, used as separators the way K2 and K3 use X and Q. That reading splits in two, and neither half is a lead. If all five Ws stand for the same separator under a repeating-key cipher, the key must have the same value at all five W positions. With no repeated letters in the key, its length must divide every gap between the Ws (16, 12, 10 and 16 letters), which leaves a length of 1 or 2, and the cribs alone rule both out: the T at positions 24 and 28 would have to encipher to the same letter, but the carving shows V and R. A longer key that repeats a letter could also do it, but the cribs already rule out every Vigenère- or Beaufort-style repeating key up to 26 letters long, on either the standard or the KRYPTOS alphabet. Some longer keys (27 letters or more) do fit the cribs, and this argument does not rule them out. If only some Ws are separators, or the key never repeats, the reading makes no prediction we can test. The K2 precedent also points the other way: its X separators were ordinary plaintext letters that enciphered to whatever the key produced (A, S and T), not to one fixed carved letter. K3 has no key at all (it is a pure rearrangement), so its X and Q were carved as themselves, only moved, which says nothing either way about W. We keep the W positions as a bounded test surface for delimiter or row-end mechanisms. We do not carry the marker reading as a lead.

2

The Stehle Anomaly

A unique constant-difference pattern at positions 55–63

~1 in 205
Low confidence: a real pattern, but weak evidence and unexploited

The short version

In one region of K4 (positions 55–63), every pair of characters four apart differs by exactly 5 in the alphabet. This pattern appears nowhere else in the ciphertext. Counting the whole search that found it — any run this long, at any spacing — the odds of it happening by chance are about 1 in 205. That is a real pattern carrying weak evidence, not a discovery.

Technical detail

If you look at every 4th character in K4 starting from position 55, something unusual happens: each character is exactly 5 positions later in the alphabet than the one 4 spots before it. This holds for a run of 9 consecutive characters (positions 55–63).

We searched the entire ciphertext for this kind of pattern at every possible spacing and every possible difference value. This is the only one. Because both the spacing of 4 and the region were found by looking rather than chosen in advance, the honest question is how often a run this long appears at any spacing. Re-measured in August 2026 over 200,000 simulated ciphertexts, that happens about 1 in 205 times for spacings 1 to 30, or 1 in 234 for spacings 1 to 24. Had the spacing of 4 been named in advance the figure would be 1 in 5,714, but it was not, so that number is unavailable. An earlier version of this page cited 1 in 642, from a Bonferroni correction over 712 tests; that was roughly three times too generous and is superseded.

The Constant-Difference Pattern

Every 4th character in this region differs from its predecessor by exactly 5 (mod 26).

Position 55 56 57 58 59 60 61 62 63
Letter D I A W I N F B N
Value (A=0) 3 8 0 22 8 13 5 1 13
Δ4 (lag-4 diff) 5 5 5 5 5
Window length 9 characters
Constant difference Δ4 = 5 (mod 26)
Other occurrences in K4 Zero
Odds once the whole search is counted ~1 in 205

What we know and don’t know

The pattern is real, and it stays unusual (about 1 in 205) even after counting the whole search that found it. However, we have not been able to exploit it: no cipher mechanism we’ve tested produces this pattern as a consequence of its key schedule. It may be a local coincidence in the cipher structure, not a clue to the method. It remains a live local anomaly, but it is no longer the site’s sole or dominant public lead.

✗

Retired Claims

Promising leads that did not survive matched controls, and errors we found in our own methods

Science progresses by testing and discarding hypotheses. Several observations initially appeared statistically significant but were retired after more rigorous controls. We document them here because intellectual honesty matters more than looking right.

The Filler-Letter (“Null”) Palette (retired April 2026)

The project previously presented, as its strongest signal, a claim that 17 suspected filler letters in K4 (the “null palette”) used only seven distinct letters. That claim did not survive a control that repeated the same search on shuffled text, and it is now retired. The underlying lesson is methodological rather than cryptographic: picking out anomalies after the fact can manufacture persuasive-looking structure unless the chance baseline is spelled out and deliberately challenged. Full report.

Follow-up audit (2026-04-08): An adversarial internal review reclassified 19 additional “interesting” results as eliminated once their dependence on the retired palette or on structural disqualifiers (the self-keying family, the VIC family, key lengths too long for the clues to test; the self-keying reason has since proved too broad, see below) was identified. We also ran a pre-registered checklist. Its non-columnar three-layer enumeration of 838,350 compositions returned zero candidates under pre-committed conjunctive thresholds. Its other two items, Carter Vol 1 and Kahn Codebreakers as running-key sources against columnar widths 6/8/9, turned out in August 2026 to have tested nothing: the faulty key-consistency check described below discarded every arrangement before either text was read. Carter’s volume was also tested in other searches under column and route rearrangements, with no signal; Kahn’s book has not been re-run. Full records are in the internal status audit (docs/exhaustion_audit_2026_04_08.md in the research repository), which is deliberately adversarial about our own claims.

Our own errors, corrected (August and September 2026)

In August 2026 we found that a key-consistency check used across the project (the Bean constraints) had been applied in the wrong frame in tests that also rearranged the letters, so the failures it reported in those tests could not be trusted. That withdrew an earlier proof that claimed to rule out repeating keys of most lengths under any rearrangement, together with the list of “surviving” key lengths it produced, and reopened 18 records we had marked exhausted. The column-rearrangement cases (widths 4 to 9, key lengths 1 to 24, standard alphabet) were then searched again without that check, and nothing fits. In September 2026 we found that most of the same check (all but its one equality and the pairs Bean himself published) only works on the standard A-to-Z alphabet and gives false failures on the KRYPTOS alphabet used for K1 and K2. No recorded elimination is overturned by that, but one search had skipped half its cases because of it; that half has since been run, with nothing found, though the search’s detection tests later proved weak and its result is now marked provisional. The same month, an audit found that 57 older experiment scripts carried copies of the K1 to K3 texts that match the real texts only for a stretch (often the first 20 to 60 letters) and then diverge, often into invented text. Results computed from those copies did not test the real texts beyond that point. The main conclusion, that the K1 to K3 texts do not work as a running key for K4 read straight across, was re-checked on the verified texts and still fails (best 8 of 24 known letters, a chance-level score); that re-check is not yet in the repository. Also in September 2026, we found that an older claim, that self-keying (autokey) ciphers cannot fit the known letters even when combined with any letter rearrangement, was wrong: an explicit rearrangement of the 97 carved letters followed by ciphertext-keyed self-keying decryption reproduces all 24 known letters. Self-keying applied directly to the carved text is still ruled out for starting keys of up to 25 letters; with a rearrangement it is not ruled out, though that is not a lead.

Summary

What we established

  • 721.7B+ configurations evaluated across recorded experiments, with no solution-grade signal in the bounded classical slices tested so far
  • Most standard single-layer classical ciphers are ruled out within the project’s direct-positional additive-key frame; a few are only partly tested
  • A few anomaly surfaces remain live: the Stehle local regularity and the W-delimiter interpretation as a multi-layer-only component after its single-layer construction saturated. The CT-perturbation hypothesis is demoted, not closed: the May 2026 search tested every one-letter substitution in the carved text and found nothing, and later single-error searches (August and September 2026) were also empty, which leaves two-character and archive-anchored differences untested
  • Multiple earlier signals were retired when controls failed, and in August and September 2026 we found and corrected errors in some of our own earlier methods (see Retired Claims above)

What remains unknown

  • The cipher type and key. The site cannot claim to have exhausted non-standard or bespoke space.
  • Whether each carved letter decrypts to the plaintext letter in the same position. Sanborn’s clues fix where the words sit in the plaintext, and the usual reading lines them up with the carved letters, but that rests on newspaper narration and remarks relayed from conversations, not on his own quoted words
  • Whether the carved Ws are ciphertext or delimiters, and whether any physical or procedural segmentation rule is real
  • Whether K4 contains filler characters under any independently justified rule; the old statistical filler-letter (“null”) palette is retired
  • Running keys combined with rearrangements (only a limited set of source texts has been tested that way), running keys from non-public or non-English sources, or running keys combined with monoalphabetic substitution + non-standard transposition
  • Bespoke procedural mechanisms using Sanborn’s encoding charts or physical installation features
  • Whether K5, archive photographs, or other primary-source evidence would reveal new constraints
  • Anything we haven’t thought of. If you have an idea we haven’t tested, tell us — that is exactly why this site exists.