Every cryptogram on this site is built on one of the oldest ideas in written communication: swap each letter of a message for another letter, consistently, and the message becomes unreadable to anyone who does not know the swap. That is a monoalphabetic substitution cipher. It is simple enough to explain in a sentence, and it kept state secrets for the better part of two millennia. Its long decline from serious military tool to morning coffee diversion is one of the more charming stories in the history of writing.
Sparta and the first military secrets
The earliest systematic secret writing we can date belongs to the Greeks, and to Sparta in particular, around the fifth and sixth centuries BC. The Spartan device most often cited is the scytale: a tapered rod around which a narrow strip of parchment was wound in a spiral. The sender wrote his message along the length of the rod, then unwound the strip, leaving a meaningless column of letters. Only a rod of matching diameter would realign them.
It is worth being precise here, because the scytale is frequently misdescribed. It is not a substitution cipher at all. It is a transposition cipher: the letters of the message are the correct letters, merely shuffled into the wrong order. Substitution and transposition are the two fundamental operations of classical cryptography, and nearly every cipher before the computer age is some combination of the two. The cryptogram is pure substitution. The letters you see on screen are the wrong letters in the right order.
Caesar's three-letter shift
The first substitution cipher with a famous name attached belongs to Julius Caesar. According to Suetonius, writing in the second century AD, Caesar protected his correspondence by replacing each letter with the letter three places further along the alphabet. A became D, B became E, and so on. His nephew Augustus reportedly used a shift of one, and neglected to wrap around at the end of the alphabet, which suggests the family understanding of the method was not deep.
What we now call the Caesar cipher is the simplest possible substitution: a single fixed rotation of the alphabet, giving only twenty-five possible keys. Anyone can break it by trying all of them, an approach so straightforward it now serves mainly as a teaching exercise. But the underlying insight was sound, and it generalizes. Rather than shifting the alphabet, scramble it completely. There are twenty-six letters, so there are roughly four hundred septillion possible scrambles, a number large enough that guessing them one at a time is hopeless even for a modern machine. For centuries this seemed like security.
Al-Kindi and the birth of codebreaking
It was not security, and the man who worked out why was Abu Yusuf Yaqub ibn Ishaq al-Kindi, a polymath working in ninth-century Baghdad. In a treatise usually translated as the Manuscript on Deciphering Cryptographic Messages, al-Kindi laid out the single most important technique in the history of code breaking, and the one that makes the puzzle on this site solvable at all.
His observation was that letters are not used equally. In any sufficiently long passage of a given language, some letters appear constantly and others barely at all. Scrambling the alphabet hides which letter is which, but it does nothing to hide how often each one appears. If the most common symbol in an English ciphertext appears about thirteen percent of the time, it is almost certainly standing in for E. Count the symbols, rank them, compare the ranking against the known frequencies of the language, and the enormous keyspace collapses. Al-Kindi had shown that the strength of a cipher has very little to do with the number of possible keys.
This is the reason experienced solvers do not begin a cryptogram by guessing. They begin by counting.
Mary, Queen of Scots, and the cost of a broken cipher
Frequency analysis reached Europe slowly, and the consequences of not knowing about it could be severe. The most famous illustration is the trial of Mary, Queen of Scots. Imprisoned in England and conspiring with Anthony Babington to assassinate Elizabeth I, Mary corresponded in a nomenclator, a substitution cipher supplemented with special symbols for common words and names. She believed it unbreakable.
Elizabeth's spymaster Francis Walsingham employed a cryptanalyst named Thomas Phelippes, who broke the cipher and read the correspondence as it passed. Phelippes went further and forged an addition to one of Mary's letters, requesting the names of the conspirators. The decrypted letters were produced at her trial in 1586, and she was executed the following year. It remains the clearest case in history of a cipher failure costing someone their head.
From secret to sport
By the sixteenth century, serious cryptographers had moved on. Polyalphabetic ciphers, which switch between several different substitution alphabets as the message proceeds, spread the letter frequencies out and blunt al-Kindi's method. The best known is usually credited to Blaise de Vigenere, though it was actually described earlier by Giovan Battista Bellaso, and it resisted attack for some three hundred years until Charles Babbage and Friedrich Kasiski independently found the way in during the nineteenth century.
The simple substitution cipher, meanwhile, was left with nothing serious to do. And here the story takes its pleasant turn: having failed as a tool of statecraft, it was adopted as entertainment. Medieval European monks are often credited with the first recreational ciphers, treating them as exercises in ingenuity rather than secrecy. By the eighteenth and nineteenth centuries, encrypted messages had become a fixture of newspapers and magazines, used for puzzles, for advertisements, and for lovers whose families disapproved.
Poe, the great popularizer
No one did more to make cryptograms a popular pastime than Edgar Allan Poe. Writing for Alexander's Weekly Messenger in 1839 and 1840, Poe issued an open challenge to readers: send him any monoalphabetic substitution cipher and he would solve it. Readers sent them in volume, and he solved them, publishing the solutions along with a certain amount of self-congratulation.
He then turned the technique into fiction. The Gold-Bug, published in 1843, hangs its entire plot on a cipher, and its hero William Legrand explains frequency analysis to the narrator at length before locating Captain Kidd's treasure. It won a newspaper prize, became one of Poe's most widely read stories in his lifetime, and taught a generation of readers how the method worked. The English word cryptogram itself dates from around 1849, assembled from Greek roots meaning hidden and written.
The thread runs unbroken from there to here. The American Cryptogram Association was founded in 1930 and still publishes. Newspaper puzzle pages carried a daily cryptogram throughout the twentieth century, usually a quotation, usually attributed, exactly as ours is.
Why the cipher outlived its own defeat
There is a neat irony in all this. The substitution cipher makes a poor secret keeper precisely because it preserves the structure of the language underneath: the word lengths, the repeated letters, the apostrophes, the rhythm of vowels and consonants. Every one of those leaks is a gift to an attacker.
But those same leaks are what make it a good puzzle. A cipher that hid its structure perfectly would be unsolvable by hand and no fun whatsoever. The cryptogram survives because it is beatable, and beatable through reasoning rather than brute force. When you notice that a three-letter word appears four times and conclude it must be THE, you are using al-Kindi's insight, more or less unmodified, eleven centuries later.