The Kryptos sculpture at CIA headquarters remains among the world’s most famous unsolved codes despite over 22 years of hints from its creators.
The sculpture’s centerpiece, hidden away in a courtyard, features curved copper plates that together stand nearly 10 feet tall. Carved out of the plates with a jigsaw are 1,732 letters and four question marks. Half of these characters encode four sets of encrypted messages, each more difficult than the last.
Like many Kryptos aficionados, I’ve spent hundreds of hours wrestling with the final unsolved piece of the code. Perhaps the greatest mystery isn’t the part left to extract. Rather, it’s why we’re still trying to solve this infuriatingly addictive puzzle.
Most of Kryptos was solved during the 1990s, initially by staff at the NSA and the CIA who didn’t publicize their accomplishments beyond the intelligence community. The first amateur cryptanalyst to get that far, Jim Gillogly, used his Pentium II. We now have faster computers in our pockets. But the fourth and final section, a tiny passage known as K4, seems to be impenetrable.
K4 has merely 97 characters. Just how short is that? It’s the same length as this paragraph, minus punctuation and spaces.
My fascination with Kryptos started in June 2005 after I heard an NPR story on my drive to work. As I slogged through Beltway traffic around D.C., this enigmatic sculpture felt irresistibly close. I could have driven there in under 30 minutes, not that it would have done me any good. The CIA allows a vanishingly small number of approved academic and civic groups to tour its grounds.
The closest that regular people can get to seeing Kryptos is buying a small replica from the Spy Museum Store or visiting one of the similar pieces made by the artist, Jim Sanborn, such as Antipodes at the Smithsonian’s Hirshhorn Museum and Sculpture Garden. Otherwise, one has to rely on pictures posted by the rare visitor, such as Gillogly or Elonka Dunin, a leading expert on Kryptos.
Kryptos adepts keep poking at K4, tantalized by patterns that emerge from those apparently random characters. Our efforts surge when prompted by new hints or theories. There have been reports of fans becoming truly obsessed, even to the point of quitting their jobs. Some of those stories were later refuted, at least in their intensity. It’s possible that expert cryptanalysts at the NSA or CIA or elsewhere have solved K4 and don’t want it publicized. That’s another reason why Kryptos is so maddening.
The fame of Kryptos has inspired numerous Web sites for those who want to learn more or, ideally but less likely, find the solution. Dunin’s Kryptos page provides an excellent starting point. The Rumkin site has cryptographic tools that could be useful for experimenting with K4, including the decryption techniques used in K1 and K2 and K3. These might be used in tandem or in part for K4.
Individual codebreakers have also developed tools for their own attempts, such as the program Gillogly used to solve K1. K3.2 Purists, like the CIA employee who quietly achieved the same goal a year earlier, can use pencil and paper.
If you think you’ve figured out the answer to K4, Sanborn has a page where you can enter the first 10 letters and see if you’re correct.
There are several possible reasons why K4 has remained unsolved for so long. It’s very short, which generally makes it harder to gain insights from letter frequencies and n-gram repetitions. In addition, K4 could employ masking techniques to make such frequency analyses even less helpful. The encryption might combine multiple techniques in sequence or use a nonstandard technique that relies on aesthetics rather than on methods commonly known to cryptanalysts.
Maybe there was an error in the encryption process that makes solving it all but impossible. Or maybe Sanborn is just messing with us and K4 is an elaborate hoax.
Kryptos remains a great challenge to geeky muscles by demanding both math and programming skills along with a love for ferreting out elusive patterns. Unlike most puzzles, however, Kryptos can become a bottomless time-sink with little prospect of a satisfying reward. When you get stuck and frustrated, the solution isn’t readily available. Rather, it’s locked in a safe deposit box, the location of which Sanborn has kept to himself and a few others.
Like providing a proof for a theorem that previously lacked a solution, trying to decrypt a famously knotty code has elements of megalomania in the act. The possibility is remote that you’ll experience an epiphany that lets you break through where others have failed, even though examples abound of such flashes of genius in the mathematical world.