After 721.7B+ configurations tested
What we’ve learned
None of the standard single-layer classical ciphers fully tested so far has survived
against K4 under the project’s direct-positional, additive-key test frame; a few,
such as repeating-key ciphers with two different keyword-mixed alphabets, Gromark with
keyed alphabets on both sides, and Trifid, have been only partly tested. Large bounded slices of
two-layer and three-layer classical space are also saturated, and a 2026
program extended the negatives beyond the standard reading: scoring after
undoing candidate rearrangements, and letting the known plaintext words land
anywhere in the output, both closed cleanly at millions of configurations.
The CT-perturbation idea (small transcription differences between
Sanborn’s archived coding charts and the carved text) was tested at
one-letter depth and closed negative in May 2026; follow-up searches in
August and September 2026 (a missing or wrong letter under the
KRYPTOS-alphabet cipher used for K1 and K2, and a single wrong, missing,
extra or swapped letter combined with a grid rearrangement) also found
nothing within their tested ranges. These results are narrower than they
sound: no single-letter error in the carved text unlocked K4 under the
cipher families, alphabets and keyword lists tested. It does not
show that the carved text is correct, and two-character differences
anchored to the archive were never run. The W-delimiter
interpretation stays available only as one ingredient of a multi-step scheme,
and several earlier “signals” were retired after stricter controls.
Status as of September 29, 2026: K4 remains unsolved: no
verified plaintext has been published. (In September 2025 Jarett Kobek and
Richard Byrne found scrambled plaintext strips in Sanborn’s papers at the
Smithsonian’s Archives of American Art. Sanborn confirmed the find but said
it does not reveal the coding method or key, and the files were sealed.
Paradigm, which now holds Sanborn’s Kryptos archive, runs an online
checker for K4 guesses without publishing the answer.) An end-to-end audit in
June 2026 of every candidate answer this project had produced up to then
(13,302 of them) confirmed zero survive verification, and the searches run
since, through September 2026, have also come back empty. Computer searches
continue, but the main open leads are physical and archival, such as newly
documented circled letters on a tableau in the sculptor’s working papers
(not yet analyzed; any use for K4 must be preregistered first) and planned
measurements of the sculpture itself. A longer technical status report is in the
research repository as docs/REAL_K4_CURRENT_POSITION.md; it is dated
June 2026 and does not include the August and September 2026 corrections described below.
The K4 Ciphertext (97 Characters)
Hover or tap a letter to see its position. Positions on this page count from 0, as in the project’s code; most public sources count from 1, which puts EASTNORTHEAST at 22–34 and BERLINCLOCK at 64–74. Colors show known plaintext regions and the Stehle anomaly zone.
What 721.7B+ configurations told us
The site has accumulated a large negative map of bounded classical search space. Under direct positional correspondence (where ciphertext position N maps to plaintext position N), the current repo state supports the following:
- Repeating-key Vigenère, Beaufort and Variant Beaufort, on the standard or the KRYPTOS alphabet, at every key length 1–26: mathematically impossible within the direct-positional additive-key model. With one keyword-mixed alphabet used the way K1 and K2 used theirs (the same mixed alphabet for plaintext and ciphertext), key lengths 1–22, 24 and 25 are ruled out whatever the keyword. Versions with two different mixed alphabets are not fully ruled out.
- Self-keying (autokey) ciphers (keyed by the plaintext or by the ciphertext; Vigenère, Beaufort or Variant Beaufort; standard or KRYPTOS alphabet), applied directly to the carved text: no starting key of up to 25 letters fits the known plaintext. Some starting keys of 27 letters or more can fit, so this result does not cover longer keys. With a letter-rearrangement layer added, self-keying is not ruled out either: an unrestricted rearrangement leaves too much freedom for the known letters to rule it out, which is not the same as evidence for it.
- Standard fractionation ciphers (Bifid, Playfair, Two-Square and Four-Square on 5×5 squares; ADFGX and ADFGVX): ruled out in their standard forms by simple structural facts. A 5×5 square holds only 25 letters, and K4 uses all 26; ADFGX and ADFGVX always produce an even number of letters, and K4 has 97. Trifid (27 symbols) and Bifid on a 6×6 square (36 symbols) are not covered by this argument, and the project’s tests of them are not conclusive.
- Many structured rearrangement + repeating-key combinations: negative within their tested families. An earlier shortcut proof that claimed to rule out repeating keys of most lengths under any rearrangement was withdrawn in August 2026 (it applied a key-consistency check in the wrong frame). The column-rearrangement cases (widths 4 to 9, standard A-to-Z alphabet, key applied before the rearrangement) were then searched again directly at key lengths 1 to 24, and none fits.
- Running keys from 60,000+ public English texts (Project Gutenberg’s English-language texts), read straight across the carved text with no rearrangement, and across 73-letter versions with suspected filler letters removed: zero candidates across 106 billion position checks (best 10 of 24 known letters, a chance-level score). Running keys combined with rearrangements have been tested only for a limited set of source texts, such as the first volume of Howard Carter’s The Tomb of Tut-ankh-Amen under column and route rearrangements (no signal). An April 2026 claim that column rearrangements at widths 6, 8 and 9 block every running key, whatever the source text, was withdrawn in August 2026: it rested on a key-consistency check applied in the wrong frame. None of this rules out running keys from other texts, non-English texts, or with other rearrangements.
- Two-layer and three-layer compositions: an April 2026 count gave 105,692 two-layer branches (additive × transposition, transposition × repeating-key substitution, 6 stateful families) and 838,350 non-columnar three-layer branches, with a best of 7 of 24 known letters on the three-layer set. Later campaigns (May to September 2026) added more than 100 million further multi-layer configurations, such as 17.5 million in May 2026 that combined two rearrangements with a keyword substitution. All noise within the families and keyword sets tested.
- Many bespoke or historical systems (VIC, RS44, Wheatstone, interrupted-key, DRYAD): all noise within tested scope.
These eliminations describe the scope of what we have tested under specific assumptions. They do not claim that K4 cannot be solved by classical cryptanalysis; classical cipher space has infinite variation, and any bespoke procedure, non-standard transposition, or combination outside our tested scope remains open. We document concrete negatives so the community does not have to re-test approaches that are already known to fail, not to suggest the problem is closed.
These eliminations do not rule out the same families as one layer of a multi-layer construction; that includes self-keying, which is not ruled out once a letter-rearrangement layer is added. The repeating-key, self-keying and running-key results do not apply if K4 uses a non-additive cipher mechanism, and the results that read the carved text straight across assume that each carved letter decrypts to the plaintext letter in the same position (see “What remains unknown” below). See the elimination database for the full inventory, and the open questions for what remains.
The research code is public on GitHub, though the public copy can lag behind the working version. Most elimination records include a reproduction command.
The W-Delimiter Structural Lead
A live layout hypothesis, not a settled claim
The short version
Delete the five carved Ws at positions 20, 36, 48, 58 and 74 and the old
width-21 vertical-bigram anomaly disappears. That looked for a while like an explanation.
A May 2026 audit showed it is not one: replace every W with any one other
letter, keeping the text 97 characters long, and all eleven repeated bigrams survive intact.
A September 2026 audit explained why: the count depends only on which positions hold the
same letter, so replacing every W with one other letter cannot remove any of
the eleven, while deleting a letter shifts every later position and breaks the pairs that
straddle the deletion. Deleting other letters spread through the middle of the text weakens
or removes the anomaly in the same way. What the anomaly responds to is where letters are
deleted, not which letters they are.
By April 2026, 80+ direct single-layer W-segmentation hypotheses had been tested, with no
signal. W-segmentation is therefore no longer the primary anchor.
It remains admissible inside multi-layer hypotheses, and the public reading is still
“if K4 has a delimiter or row-end mechanism, the W positions are the cleanest
bounded place to test it,” not “the Ws are proven delimiters.”
What we know and don’t know
We know the width-21 effect is not explained by W placement:
it survives replacing every W, and deleting other letters from the middle of the
text weakens or removes it too (deleting from the very start barely changes it). Removing all
eight Ks leaves one repeated bigram; removing all five Ws leaves
none. The Ws sit between positions 20 and 74, never more than 16 apart, so
almost every stretch of 21 letters contains one, and deleting them breaks all eleven pairs. The anomaly therefore says
nothing about the Ws. We also do not know whether the
Ws are ciphertext, filler, row-end markers, or some other procedural feature.
What the W positions give us, independently of the anomaly, is a finite
structural test surface: six segments with fixed crib geometry, including only two
characters after EASTNORTHEAST and four before BERLINCLOCK.
One reading that keeps coming up is a punctuation or marker convention:
that after decryption some or all carved Ws would turn out to be plaintext
letters such as X, Q or Z, used as separators the way
K2 and K3 use X and Q. That reading splits in two, and neither half
is a lead. If all five Ws stand for the same separator under a repeating-key
cipher, the key must have the same value at all five W positions. With no
repeated letters in the key, its length must divide every gap between the Ws
(16, 12, 10 and 16 letters), which leaves a length of 1 or 2, and the cribs alone rule both
out: the T at positions 24 and 28 would have to encipher to the same letter,
but the carving shows V and R. A longer key that repeats a letter
could also do it, but the cribs already rule out every Vigenère- or Beaufort-style
repeating key up to 26 letters long, on either the standard or the KRYPTOS alphabet. Some
longer keys (27 letters or more) do fit the cribs, and this argument does not rule them out.
If only some Ws are separators,
or the key never repeats, the reading makes no prediction we can test. The K2 precedent
also points the other way: its X separators were ordinary plaintext letters
that enciphered to whatever the key produced (A, S and
T), not to one fixed carved letter. K3 has no key at all (it is a pure
rearrangement), so its X and Q were carved as themselves, only
moved, which says nothing either way about W. We keep the
W positions as a bounded test surface for delimiter or row-end mechanisms. We
do not carry the marker reading as a lead.
The Stehle Anomaly
A unique constant-difference pattern at positions 55–63
The short version
In one region of K4 (positions 55–63), every pair of characters four apart differs by exactly 5 in the alphabet. This pattern appears nowhere else in the ciphertext. Counting the whole search that found it — any run this long, at any spacing — the odds of it happening by chance are about 1 in 205. That is a real pattern carrying weak evidence, not a discovery.
Technical detail
If you look at every 4th character in K4 starting from position 55, something unusual happens: each character is exactly 5 positions later in the alphabet than the one 4 spots before it. This holds for a run of 9 consecutive characters (positions 55–63).
We searched the entire ciphertext for this kind of pattern at every possible spacing and every possible difference value. This is the only one. Because both the spacing of 4 and the region were found by looking rather than chosen in advance, the honest question is how often a run this long appears at any spacing. Re-measured in August 2026 over 200,000 simulated ciphertexts, that happens about 1 in 205 times for spacings 1 to 30, or 1 in 234 for spacings 1 to 24. Had the spacing of 4 been named in advance the figure would be 1 in 5,714, but it was not, so that number is unavailable. An earlier version of this page cited 1 in 642, from a Bonferroni correction over 712 tests; that was roughly three times too generous and is superseded.
The Constant-Difference Pattern
Every 4th character in this region differs from its predecessor by exactly 5 (mod 26).
What we know and don’t know
The pattern is real, and it stays unusual (about 1 in 205) even after counting the whole search that found it. However, we have not been able to exploit it: no cipher mechanism we’ve tested produces this pattern as a consequence of its key schedule. It may be a local coincidence in the cipher structure, not a clue to the method. It remains a live local anomaly, but it is no longer the site’s sole or dominant public lead.
Retired Claims
Promising leads that did not survive matched controls, and errors we found in our own methods
Science progresses by testing and discarding hypotheses. Several observations initially appeared statistically significant but were retired after more rigorous controls. We document them here because intellectual honesty matters more than looking right.
The Filler-Letter (“Null”) Palette (retired April 2026)
The project previously presented, as its strongest signal, a claim that 17 suspected filler letters in K4 (the “null palette”) used only seven distinct letters. That claim did not survive a control that repeated the same search on shuffled text, and it is now retired. The underlying lesson is methodological rather than cryptographic: picking out anomalies after the fact can manufacture persuasive-looking structure unless the chance baseline is spelled out and deliberately challenged. Full report.
Follow-up audit (2026-04-08): An adversarial internal review
reclassified 19 additional “interesting” results as eliminated once
their dependence on the retired palette or on structural disqualifiers (the
self-keying family, the VIC family, key lengths too long for the clues to test; the
self-keying reason has since proved too broad, see below) was identified. We also ran a pre-registered checklist. Its non-columnar three-layer
enumeration of 838,350 compositions returned zero candidates under pre-committed
conjunctive thresholds. Its other two items, Carter Vol 1 and Kahn Codebreakers
as running-key sources against columnar widths 6/8/9, turned out in August 2026 to
have tested nothing: the faulty key-consistency check described below discarded every
arrangement before either text was read. Carter’s volume was also tested in other
searches under column and route rearrangements, with no signal; Kahn’s book has
not been re-run. Full records are in the
internal status audit (docs/exhaustion_audit_2026_04_08.md in the
research repository), which is deliberately adversarial about our own claims.
Our own errors, corrected (August and September 2026)
In August 2026 we found that a key-consistency check used across the project (the Bean constraints) had been applied in the wrong frame in tests that also rearranged the letters, so the failures it reported in those tests could not be trusted. That withdrew an earlier proof that claimed to rule out repeating keys of most lengths under any rearrangement, together with the list of “surviving” key lengths it produced, and reopened 18 records we had marked exhausted. The column-rearrangement cases (widths 4 to 9, key lengths 1 to 24, standard alphabet) were then searched again without that check, and nothing fits. In September 2026 we found that most of the same check (all but its one equality and the pairs Bean himself published) only works on the standard A-to-Z alphabet and gives false failures on the KRYPTOS alphabet used for K1 and K2. No recorded elimination is overturned by that, but one search had skipped half its cases because of it; that half has since been run, with nothing found, though the search’s detection tests later proved weak and its result is now marked provisional. The same month, an audit found that 57 older experiment scripts carried copies of the K1 to K3 texts that match the real texts only for a stretch (often the first 20 to 60 letters) and then diverge, often into invented text. Results computed from those copies did not test the real texts beyond that point. The main conclusion, that the K1 to K3 texts do not work as a running key for K4 read straight across, was re-checked on the verified texts and still fails (best 8 of 24 known letters, a chance-level score); that re-check is not yet in the repository. Also in September 2026, we found that an older claim, that self-keying (autokey) ciphers cannot fit the known letters even when combined with any letter rearrangement, was wrong: an explicit rearrangement of the 97 carved letters followed by ciphertext-keyed self-keying decryption reproduces all 24 known letters. Self-keying applied directly to the carved text is still ruled out for starting keys of up to 25 letters; with a rearrangement it is not ruled out, though that is not a lead.
Summary
What we established
- 721.7B+ configurations evaluated across recorded experiments, with no solution-grade signal in the bounded classical slices tested so far
- Most standard single-layer classical ciphers are ruled out within the project’s direct-positional additive-key frame; a few are only partly tested
- A few anomaly surfaces remain live: the Stehle local regularity and the W-delimiter interpretation as a multi-layer-only component after its single-layer construction saturated. The CT-perturbation hypothesis is demoted, not closed: the May 2026 search tested every one-letter substitution in the carved text and found nothing, and later single-error searches (August and September 2026) were also empty, which leaves two-character and archive-anchored differences untested
- Multiple earlier signals were retired when controls failed, and in August and September 2026 we found and corrected errors in some of our own earlier methods (see Retired Claims above)
What remains unknown
- The cipher type and key. The site cannot claim to have exhausted non-standard or bespoke space.
- Whether each carved letter decrypts to the plaintext letter in the same position. Sanborn’s clues fix where the words sit in the plaintext, and the usual reading lines them up with the carved letters, but that rests on newspaper narration and remarks relayed from conversations, not on his own quoted words
- Whether the carved
Ws are ciphertext or delimiters, and whether any physical or procedural segmentation rule is real - Whether K4 contains filler characters under any independently justified rule; the old statistical filler-letter (“null”) palette is retired
- Running keys combined with rearrangements (only a limited set of source texts has been tested that way), running keys from non-public or non-English sources, or running keys combined with monoalphabetic substitution + non-standard transposition
- Bespoke procedural mechanisms using Sanborn’s encoding charts or physical installation features
- Whether K5, archive photographs, or other primary-source evidence would reveal new constraints
- Anything we haven’t thought of. If you have an idea we haven’t tested, tell us — that is exactly why this site exists.