Workbench
Configure a transposition + substitution pipeline and score it against K4’s 24 known crib positions. All computation runs locally in your browser. Nothing leaves this page unless you opt in below to share promising results.
Your odds of solving K4 right here (spoiler: astronomical)
This workbench exposes well over 1035 possible configurations (a hand-entered 97-letter rearrangement alone allows about 10152). At 3 per minute, 8 hours a day, 365 days a year, even 1035 would take about 2 × 1029 years (more than ten quintillion universe lifetimes). Bring snacks.
You are more than 1012× more likely to win the Powerball twice in a row than to stumble on the answer here in a year of trying. And yet, someone, someday, might try an “obvious” keyword that over 35 years of PhDs missed and crack the last unsolved message at CIA headquarters. That’s cryptanalysis.
Over 721.7B+ configs have been evaluated by this project. Most of the remaining space is not honestly enumerable.
What we know about K4 (research context)
At the 1990 dedication Sanborn said there are “two systems of enciphering the bottom text”. The lower half of the panel holds both K3 and K4, so how that applies to K4 alone is an interpretation, not a fact. Pure transposition is impossible (CT has 2 E’s, cribs need 3), so at least one layer is substitution. Beyond that, the architecture is open: the live questions are about ordering, segmentation, and whether any procedural layer is present.
Eliminated proven impossible (algebraic)
- Repeating-key substitution on the raw 97 characters (Vigenère, Beaufort and Variant Beaufort, key lengths 1–26, on both the A–Z and the KRYPTOS alphabet)
- Pure transposition (CT has 2 E’s, cribs need 3)
- Filler letters removed (any 24 of the 97, none of them known-plaintext letters) + repeating-key substitution on the 73 letters left (key lengths 1–23, standard or KRYPTOS alphabet)
- Self-keying (autokey), plaintext- and ciphertext-keyed, on the raw 97 characters with a starting key of up to 25 letters. With an unrestricted rearrangement layer added, it is not ruled out.
Eliminated tested exhaustively
- Columnar transposition (widths 4–9, every column order) × repeating-key substitution (key lengths 1–24, A–Z alphabet): no combination fits (exhaustive re-run, August 2026)
- Single-letter and 1M-word dictionary self-keying keys on the raw 97 characters
Open territory viable
- Non-standard transpositions (serpentine, spiral, Myszkowski) with a longer or non-repeating key (with repeating keys of length 2 to 7 they were tested, no signal)
- Self-keying (autokey) or running key after undoing a rearrangement
- Custom tableaux, including repeating keys that use a different alphabet for plaintext than for ciphertext (for example two different keyword-mixed alphabets), or one keyword-mixed alphabet used the K1/K2 way with a key of 23 letters or of 26 or more
- Filler-letter hypotheses (for example 24 fillers leaving 73 letters) with a non-repeating key: not ruled out, but no independent evidence supports them
- W-delimiter hypothesis: the 5 W characters at positions 20, 36, 48, 58, 74 divide K4 into 6 segments of 20|15|11|9|15|22 chars. That makes them a bounded layout to test, not evidence of a delimiter: the old width-21 repeated-bigram effect that vanishes when the Ws are removed also weakens or vanishes when other letters spread through the text are deleted, so it says nothing about the Ws (Finding 1). Use the “W-segment” transposition and the “W positions only” filler setting to explore this.
About near misses (23/24)
A 23/24 is not a sign of a hidden delimiter. Long keys and flexible methods reach
23/24 by chance, and none of the 24 known-plaintext positions holds a carved
W. The idea that all five carved Ws decrypt to one separator
letter such as X, Q or Z does not work with any
repeating key of up to 26 letters on the standard or KRYPTOS alphabet: a key with no
repeated letters would need a length of 1 or 2 to fit the gaps between the Ws,
and the known plaintext rules out every repeating key of up to 26 letters on those alphabets
anyway. Some keys of 27 letters or more do fit the known plaintext, and this argument does
not rule them out. If only some of the Ws do, or the key never repeats,
the idea makes no prediction that can be tested
(Finding 1).
Quick presets
Vigenère + KRYPTOS
Classic first guess eliminated
Beaufort + KA alphabet
Kryptos-keyed Beaufort eliminated
Columnar w=7 + Vig
Columns + repeating key eliminated
Rail fence + Beaufort
Short keys tested no signal
Serpentine + Vig
Short keys tested no signal
DEFECTOR 15/24
Historic high score disproven
W-delimiter (92-char)
Single-layer saturated multi-layer only
Try your own
Blank slate
K4 Ciphertext
One hypothesis: 24 of the 97 letters are filler, leaving 73.
Extracted CT (0 chars, 0 fillers removed):
6 W-delimited segments as grid rows: 20 | 15 | 11 | 9 | 15 | 22 chars (sum = 92). Set step 0 to “W positions only” first to extract the 92-char text.
Enter a substitution key above to see results.
Transposed CT
Plaintext
Derived keystream at crib positions
Bean constraint (k[27]=k[65]): --. This also checks the 242 Bean inequalities. With no transposition and the A–Z alphabet, the correct solution must pass, but passing does not make a result correct. With a transposition or the KRYPTOS alphabet selected, these constraints do not apply and a correct solution can show FAIL.
Period consistency analysis
For each period, counts how many crib-position keystream values conflict (fall on the same key letter but need different key values). Zero conflicts = consistent with that period.
Session history (0 attempts)
Cipher toolkit inspired by enigmator by Merricx.