On July 9, 1941, Bletchley Park decoded an Enigma message that saved 103 ships. The machine looked like a typewriter. It had one mathematical flaw. Learn how rotors, reflectors, and plugboards worked.
On July 9, 1941, Bletchley Park decoded an Enigma message revealing the German battlecruiser Lutzow heading toward Atlantic convoys. The Admiralty rerouted the convoys. 103 ships survived because a machine that looked like a typewriter had one mathematical flaw.
The Enigma was not broken by a single genius. The story that Alan Turing alone cracked it is a myth. The Polish Cipher Bureau broke Enigma in 1932. Marian Rejewski, Jerzy Rozycki, and Henryk Zygalski reconstructed the machine's internal wiring without ever seeing one, using mathematical group theory. They built the first electromechanical bomba in 1938. Turing and Gordon Welchman improved the design at Bletchley Park in 1940, creating the bombe that could handle the increased complexity of the German naval Enigma.
You can simulate the Enigma machine yourself with our Enigma Machine Simulator, which lets you configure rotors, reflector, and plugboard settings.
The Enigma was invented by Arthur Scherbius, a German electrical engineer who patented the design in 1918. He died on May 13, 1929, after a carriage accident, but his company continued manufacturing the machine. The German military adopted the Enigma I in 1930, adding a plugboard (Steckerbrett) that significantly increased the key space.
By World War II, the Enigma was used by the German Army (Wehrmacht), Navy (Kriegsmarine), Air Force (Luftwaffe), and intelligence services. Each service used different settings, key schedules, and procedures. The Kriegsmarine Enigma (M4, introduced in 1942) used four rotors instead of three, making it the most secure variant and the hardest to break.
The first Enigma machine purchased by the UK was acquired in 1926 by Edward Travis of the Government Code and Cipher School (GC&CS) for 30 pounds in Berlin. This machine, serial number A320, is one of only five surviving Enigma D models and is currently on display at Bletchley Park's Block C Visitor Centre on loan from GCHQ until early 2027. In November 2024, fragments of an Enigma machine were discovered on Sobieszewska Island near Gdansk, Poland, by the Latebra Foundation, including eight rotors and casing fragments from a German communications post.
The Enigma is an electromechanical rotor cipher machine. When you press a key, an electrical current flows through a series of components that scramble the signal, and a lamp lights up showing the encrypted letter. Here is the path the current takes:
Keyboard -> Plugboard (Steckerbrett) -> Entry wheel -> Rotor 1 -> Rotor 2 -> Rotor 3 -> Reflector -> Rotor 3 (reverse) -> Rotor 2 (reverse) -> Rotor 1 (reverse) -> Entry wheel -> Plugboard (reverse) -> Lampboard
The rotors are the core of the machine. Each rotor is a wheel with 26 electrical contacts on each side, connected by internal wiring that creates a permutation of the 26 letters. When a key is pressed, the rightmost rotor advances one step. After 26 steps, it triggers the middle rotor to advance one step (this is called "stepping" or "turnover"). After the middle rotor completes a full revolution, the left rotor advances. This means the electrical path changes with every keypress, so the same plaintext letter encrypts to different ciphertext letters each time.
The reflector (Umkehrwalze) sits to the left of the rotors. It connects pairs of letters, sending the current back through the rotors via a different path. The reflector makes the Enigma reciprocal: if A encrypts to B with a given setting, then B encrypts to A with the same setting. This means the same machine configuration is used for both encryption and decryption, which was operationally convenient but also a cryptographic weakness.
The plugboard (Steckerbrett) sits between the keyboard and the entry wheel. It uses cables to swap pairs of letters before they enter the rotors and after they exit. With 10 plugs (the standard German Army configuration), the plugboard swaps 20 of 26 letters, adding approximately 150 trillion possible combinations to the key space.
The total key space for a three-rotor Enigma with 10 plugboard pairs is approximately 158 quintillion (158 x 10^18) combinations. This is why the Germans believed it was unbreakable.
The first break came from Poland. Marian Rejewski (1905-1980), a mathematician at the Polish Cipher Bureau (Biuro Szyfrow), attacked Enigma in 1932 using mathematical group theory. He was given French intelligence reports containing Enigma key settings obtained by a German spy, but he had never seen the machine itself. Working from intercepted ciphertext and the key settings, he used the cycle structure of permutations to deduce the rotor wiring. This was an extraordinary mathematical achievement: he reconstructed the internal wiring of the rotors purely from ciphertext analysis.
Rejewski and his colleagues built the bomba kryptologiczna in 1938, an electromechanical machine that could test Enigma settings automatically. It used six sets of rotors to check all possible settings in parallel, exploiting the fact that the German message key was repeated at the beginning of each transmission. The bomba could find the daily key in about two hours.
In July 1939, as war approached, the Polish Cipher Bureau shared everything they knew with British and French intelligence: the reconstructed Enigma wiring, the bomba design, and their cryptanalytic methods. Without this transfer, the British effort would have started from scratch.
Alan Turing arrived at Bletchley Park in 1939. He designed an improved version of the bomba, called the bombe, which did not rely on the repeated message key (the Germans had stopped repeating it). Instead, Turing's bombe exploited "cribs": known or guessed plaintext fragments within the ciphertext. For example, German weather reports routinely began with "WETTER" (weather), and messages often ended with "HEILHITLER."
Gordon Welchman improved Turing's design with the "diagonal board," which exploited the reciprocal property of the Enigma to dramatically reduce the number of false stops. The Turing-Welchman bombe became the primary tool for breaking Enigma throughout the war. By 1945, over 200 bombes were in operation at Bletchley Park and its outstations.
The Kriegsmarine M4 (four-rotor Enigma) was the hardest to break. It was introduced in February 1942 for U-boat communications, and Bletchley Park went dark on naval Enigma for ten months until new techniques and a captured codebook allowed them to resume. The work of mathematician Max Newman and engineer Tommy Flowers on the Colossus computer (for breaking the Lorenz cipher, not Enigma) laid the groundwork for post-war computing.
Our Enigma Machine Simulator lets you configure all the historical settings. Here is a worked example using the standard Wehrmacht configuration:
Settings: Rotors I, II, III (left to right); Reflector B; Ring settings A-A-A; Plugboard AB CD EF; Initial positions A-A-A
Input: AAAAA
Output: BDZGO
Each A produces a different output letter because the right rotor advances after each keypress. This is the fundamental property that makes Enigma a polyalphabetic cipher: the same plaintext letter maps to different ciphertext letters depending on position.
You can verify this with the simulator. Change the plugboard settings and the output changes completely. Change the rotor order and the output changes completely. This is why the daily key settings, distributed in codebooks, were so critical: without the correct settings, decryption was impossible even if you had the machine.
For CTF challenges involving Enigma, the key information is usually the rotor order, reflector type, ring settings, plugboard pairs, and initial positions. The Crypto Museum has comprehensive documentation of all Enigma variants and their settings.
The Enigma had one design flaw that was mathematically exploitable: a letter could never encrypt to itself. Because the reflector sends the current back through the rotors via a different path, the ciphertext letter is always different from the plaintext letter. This means if you press A, you can get any letter except A.
This property was exploited by Turing and Welchman. If you have a crib (known plaintext) and the ciphertext, you can immediately eliminate any position where a plaintext letter matches the corresponding ciphertext letter. This is called a "contradiction" and it eliminates impossible settings rapidly. The bombe was designed to find contradictions mechanically.
The plugboard was also weaker than the Germans believed. With only 10 plugs, 6 letters remained unplugged (unsteckered). The Polish grill method and early British techniques exploited unplugged letters. If the Germans had used 13 plugs (swapping all 26 letters), some early attacks would have failed. A 2024 analysis by Suzanne Carter at Bletchley Park corrected the calculation of unique rotor start positions, reducing the number to be subtracted from 676 to 650, amending the previously stated 16,900 to 16,926.
The Enigma was also weakened by operational procedures. The repetition of the message key (before it was discontinued), the predictable structure of German messages (standard greetings, weather report formats), and the non-clashing rule (a rotor could not be in the same position on consecutive days) all reduced the effective key space and gave Bletchley Park entry points.
Marian Rejewski and the Polish Cipher Bureau broke Enigma in 1932, reconstructing the rotor wiring mathematically. Alan Turing and Gordon Welchman improved the approach at Bletchley Park from 1939-1940 with the bombe. The popular narrative that Turing alone broke Enigma is incorrect. The Polish contribution was foundational.
The Enigma used rotors with internal wiring to scramble letters, a reflector to send the current back through the rotors (making it reciprocal), and a plugboard to swap letter pairs. Each keypress advanced the rotors, changing the electrical path. The same letter never encrypted to itself due to the reflector design.
The three-rotor Enigma with a plugboard had approximately 158 quintillion possible key combinations. The Germans believed this key space was too large for brute force. The flaw was not in the key space size but in the machine's design (letters never encrypt to themselves) and in operational procedures that leaked information.
The exact number is unknown, but surviving machines are rare. The first Enigma purchased by the UK (serial A320, an Enigma D model) is on display at Bletchley Park until early 2027. In November 2024, fragments of an Enigma were discovered on Sobieszewska Island in Poland, including eight rotors.
Historians estimate that the work of Bletchley Park shortened the war by approximately two to four years. The Polish Cipher Bureau's 1932 breakthrough was the foundation. Intelligence from decrypted Enigma messages (called "Ultra") was critical in the Battle of the Atlantic and the Normandy landings.
Enigma Machine Simulator
Simulate the WWII German Enigma cipher machine with configurable rotors, reflector, plugboard, and ring settings.
Code Identifier
Identify the cipher or encoding used in a piece of text. Paste encoded or encrypted data and the code identifier returns ranked candidates with confidence scores.
Cryptogram Solver
Automated solving of substitution ciphers using frequency analysis and pattern recognition.
Frequency Analysis Explained: How to Break Any Substitution Cipher
Al-Kindi discovered frequency analysis in 9th-century Baghdad. The technique still breaks CTF substitution ciphers today. Here is how it works and how to apply it.
How to Solve a CTF Cryptography Challenge: A Practical Framework
The hardest part of CTF crypto is identifying what you are looking at. Learn the four-step recognition-to-decryption framework for classical, encoding, and substitution cipher challenges.