Every cryptogram you solve is a promise kept. Somebody encoded a sentence, and the structure of English guarantees that patient work will recover it. That promise is what makes the puzzle fair.
Now consider the ciphers where the promise was never made. A handful of encrypted texts have absorbed the attention of professional cryptanalysts, wartime codebreakers, university mathematicians, and tens of thousands of hobbyists, and have given up nothing. Three are famous: a set of treasure ciphers from Virginia, a message from a serial killer in Northern California, and a 15th-century book written in a script that exists nowhere else on earth. Each has resisted for a different reason, and those reasons are worth understanding.
Why some ciphers stay closed
Before the stories, the mechanics. A cipher survives attack for one of four reasons, and only one of them is glamorous.
- It is too short. Cryptanalysis is a statistical craft, and statistics need material. A message of a dozen characters may have many grammatical, sensible solutions with no way to choose between them.
- It depends on an external key. If the method requires a specific book, page, or edition that nobody has identified, the cipher is not really a puzzle. It is a lock whose key is somewhere else.
- It is not what it appears to be. A text that was never meaningful cannot be made meaningful, and no amount of effort will distinguish an unbreakable cipher from an elaborate fake.
- It uses more than one layer. Substitution followed by rearrangement defeats attacks that would break either step alone.
All three of the famous unsolved ciphers below fall into these categories. None of them is unsolved because the encryption was mathematically sophisticated.
The Beale ciphers and the treasure in Bedford County
In 1885 a pamphlet appeared in Lynchburg, Virginia, titled The Beale Papers. It told of a man named Thomas J. Beale who, around 1820, buried a fortune in gold, silver, and jewels somewhere in Bedford County, and left behind three encrypted messages describing the treasure, its precise location, and the heirs entitled to it. Beale entrusted a locked box to a local innkeeper, Robert Morriss, and was never heard from again.
Three numbered ciphertexts, each a long sequence of numbers rather than letters. One of them has been read. Two have not, and people have been digging in Bedford County for well over a century.
How the middle cipher fell
Beale Cipher No. 2 was broken because someone guessed its key, and the guess was the Declaration of Independence.
The method is a book cipher. You number the words of an agreed text, and to encode a letter you write down the number of any word beginning with that letter. The word "friend" might encode an F. Because a long document contains hundreds of words starting with common letters, the same letter can be represented by dozens of different numbers, which wrecks the frequency analysis that cracks ordinary substitution ciphers. This is why book ciphers were popular with people who needed real security and had no mathematics.
It also explains why book ciphers are all or nothing. Identify the key text and the message unwraps almost mechanically. Fail to identify it and there is nothing to analyse but a column of integers. Cipher No. 2, decoded against a slightly modified Declaration, describes the contents of the vault. Ciphers No. 1 and No. 3, which would tell you where it is and who it belongs to, do not respond to the Declaration or to any other document anyone has proposed.
The evidence that Beale was a story
Serious doubt attaches to the whole affair, and the most interesting doubt is cryptographic rather than historical.
In 1980 the cryptographer Jim Gillogly decoded Cipher No. 1 using the Declaration of Independence anyway, expecting noise. Instead he found a stretch reading ABFDEFGHIIJKLMMNOHPP. An alphabetical run of that length does not occur by chance in random numbers, and it is not English either. Something structured is in there, but it is not a message.
That result cuts two ways, which is why it has kept the debate alive rather than ending it. It might mean the pamphlet's author padded the unsolved ciphers with patterned filler, having only ever bothered to construct one real message. Or it might mean No. 1 has a second layer applied on top of the book cipher. Add the anachronistic vocabulary in Beale's supposed letters and the absence of any independent record of the man, and the balance of expert opinion leans towards a 19th-century pamphlet sold for fifty cents. Leans, but has not settled.
Zodiac's 408: broken in a week by two schoolteachers
In the summer of 1969, during a series of murders in Northern California, a 408-character cipher arrived in three parts at three Bay Area newspapers. The case itself remains one of the most painful unsolved investigations in American history, and the ciphers are only a small part of it.
The 408 lasted about a week. It was solved on August 8, 1969, not by the FBI or Navy cryptanalysts who were working on it, but by Donald and Bettye Harden, a schoolteacher couple from Salinas. They guessed correctly that a man taunting newspapers would begin with the word "I" and would probably use the word "kill", and worked outward from there.
The cipher was homophonic substitution: multiple symbols assigned to a single letter, so that the frequency of the plaintext is smeared across many characters. It is a real defence and it defeats casual attack, but a 408-character sample is plenty of material once you have a foothold. The decoded message contained no name.
Zodiac's 340: fifty-one years
Three months later a second cipher of 340 characters arrived. It resisted for fifty-one years.
It fell in December 2020 to three private citizens working together across three continents: David Oranchak, an American software developer, Sam Blake, an Australian mathematician, and Jarl Van Eycke, a Belgian cipher enthusiast. The FBI confirmed their solution.
The reason for the half-century delay was layering. The 340 was homophonic substitution, like the 408, but the text had also been rearranged, read off in diagonals rather than straight across. Any attack that assumed normal reading order was working on scrambled input and could never converge, no matter how good the substitution analysis was. Once the transposition scheme was identified, the substitution gave way. The message, again, named nobody.
The two that are still standing
Two shorter Zodiac ciphers remain unread. One is 32 characters and purportedly gives the location of a bomb. The other is 13 characters, presented as the answer to the question of the writer's identity.
The 13-character cipher is the cleanest illustration in this article of a point cryptanalysts make often and the public rarely believes. It is probably not solvable, and not because it is clever. Thirteen characters is simply too little evidence. Many different plausible names can be fitted to it, each internally consistent, with nothing in the cipher itself to prefer one over another. A solution you cannot verify is not a solution. It is a guess wearing a solution's clothes, which is exactly why every few years someone announces they have read it and no cryptographer is persuaded.
The Voynich Manuscript: a book in no known language
The strangest of the three is not a message but a library object. The Voynich Manuscript is a richly illustrated codex of roughly 240 vellum pages, written throughout in a script that appears in no other document in existence. It is named for Wilfrid Voynich, the Polish book dealer who acquired it in 1912 from a Jesuit college near Rome, and it now sits in the Beinecke Rare Book and Manuscript Library at Yale as MS 408, fully digitised and free for anyone to examine.
It is genuinely old. Radiocarbon dating at the University of Arizona in 2009 placed the vellum between 1404 and 1438, which retired the long-standing theory that Voynich forged it himself. Whoever made it, made it in the early 15th century.
The illustrations only deepen the problem. There are botanical drawings of plants that do not match known species, astronomical diagrams, pages of women bathing in green pools connected by tubes, and dense sections resembling pharmaceutical recipes. It has the unmistakable shape of a practical reference book, and not one line of it can be read.
Why Voynich defeats everyone
The decisive fact is statistical. Voynichese behaves like language. Its word frequencies follow the distribution real languages follow, its word lengths cluster the way natural vocabulary clusters, and it shows the internal structure you expect from writing rather than from a keyboard mashed at random.
That is why the manuscript cannot be dismissed as decoration, and it is also why every proposed reading collapses. Claimed solutions arrive regularly, including confident announcements of proto-Romance languages and medical shorthand, and each is examined by scholars and fails the same test: the method that supposedly produced the reading cannot produce a consistent reading of the rest of the book. The strongest surviving hypotheses are that it encodes a real language by an unknown method, that it records a constructed language, or that it is a very sophisticated 15th-century fake built to look like language, which the statistics say would have required a system rather than mere scribbling.
What this means for the puzzle on your screen
These three cases share something worth noticing. Not one of them is unsolved because of brilliant encryption. They are unsolved because a key was lost, because a message was too short to pin down, because a second layer hid the first, or because there may be nothing there.
The ciphers that get broken, meanwhile, get broken by people like the Hardens and by hobbyists like Oranchak's team, working with patience and ordinary technique. That is the encouraging half of the story. And it is the exact opposite of the situation with a well-made cryptogram, which carries a guarantee none of these texts offers: the answer is really in there, English itself is the key, and nobody has hidden anything from you but the letters.