The Pigpen cipher is not just a movie prop. Freemasons used it in lodge records and gravestones for over a century. Confederate prisoners used a variant in the Civil War. Here is the real history.
The Pigpen cipher shows up in National Treasure, Assassin's Creed, and countless escape rooms. It looks exotic, all angles and dots arranged in geometric grids. But it is not a Hollywood invention. Freemasons used it for real secrecy in the 18th and 19th centuries. It appears on gravestones, in lodge minutes, and in Rosicrucian texts from the same period. Confederate prisoners used a variant during the US Civil War.
The cipher is also called the Masonic cipher, Freemason cipher, Napoleon cipher, or tic-tac-toe cipher. All these names refer to the same geometric substitution system. It is a monoalphabetic substitution cipher, which means it is trivially broken by frequency analysis. But it was never meant to resist a trained cryptanalyst. It was meant to keep casual snoopers out of Masonic records, and for that purpose it worked well enough for over a hundred years.
You can encode and decode text with the Pigpen cipher using our Pigpen Cipher tool.
The Pigpen cipher is a geometric substitution cipher. Instead of replacing each letter with another letter, it replaces each letter with a symbol derived from the shape of the grid segment that contains it. The result looks like a series of boxes, angles, and dots rather than readable text.
The cipher goes by many names. "Pigpen" comes from the resemblance of the grid shapes to animal enclosures. "Masonic cipher" and "Freemason cipher" reflect its documented use by Freemasons. "Napoleon cipher" is a less common name, sometimes attributed to its appearance in French Masonic contexts. "Tic-tac-toe cipher" refers to the grid shape. All describe the same system.
The cipher is classified as a monoalphabetic substitution cipher. Each plaintext letter maps to exactly one symbol, and that mapping does not change throughout the message. This is the same class as the Caesar cipher and the Atbash cipher. You can experiment with both using our Atbash Cipher tool and Caesar Cipher tool. All monoalphabetic substitution ciphers share the same weakness: they preserve letter frequencies, which makes them vulnerable to frequency analysis.
The Pigpen cipher uses four grids to hold the 26 letters of the English alphabet. Two grids are 2x2 squares (tic-tac-toe shapes), and two are X-shaped quadrants. The letters A through I are placed in the first tic-tac-toe grid. J through R go in the second. S through V go in the first X-shaped grid, and W through Z go in the second.
To distinguish the two tic-tac-toe grids, the second one is drawn with dots. Similarly, the second X-shaped grid uses dots. The symbol for each letter is the shape of the grid segment that surrounds it. For example, if A is in the upper-left cell of the first grid, its symbol is an L-shape (two lines forming the left and top borders of that cell). If B is in the top-center cell, its symbol is an upside-down U (two vertical lines connected by a top line).
The exact placement of letters varies by tradition. Some versions place A in the top-left, others in the bottom-left. Some use a single 3x3 grid for A-I and a second for J-R. The X-shaped grids can be oriented differently. But the principle is always the same: the grid segment around the letter becomes the symbol.
Here is a concrete example. The word "CAB" in a standard arrangement would encode as three distinct geometric shapes: the right-side-open box for C, the left-and-top L-shape for A, and the top-and-sides inverted-U for B. Someone who knows the grid can read these shapes back as letters. Someone who does not know the grid sees only a row of angular marks.
You can see this in action with our Pigpen Cipher tool, which converts text to symbols and back in real time.
The Pigpen cipher is not a theoretical construct or a movie invention. It appears in real historical documents from the 18th and 19th centuries.
Masonic lodge records. Freemasons used the Pigpen cipher to keep minutes of lodge meetings and ritual text private. The cipher appears in lodge records from both sides of the Atlantic. David Kahn, in his book "The Codebreakers" (1967, Macmillan), documents the use of the Pigpen cipher by Freemasons and notes that it was "the standard cipher of the Freemasons" for keeping records. Members of a lodge could read the minutes because they all knew the grid. Non-members could not.
Gravestones. Pigpen symbols appear on Masonic gravestones in the United States and the United Kingdom. These are typically short inscriptions, sometimes just the deceased's initials or a lodge affiliation encoded in the geometric symbols. The stones date from the late 1700s through the 1800s. They are visible in churchyards and cemeteries in New England, Virginia, and parts of England. The Wikipedia article on the Pigpen cipher includes photographs of such gravestones.
Rosicrucian and Hermetic texts. The cipher appears in 18th-century Rosicrucian and Hermetic manuscripts, where it was used to conceal alchemical and philosophical content. Some versions add extra symbols beyond the standard 26-letter grid to represent esoteric concepts. These variants are sometimes called "Rosicrucian cipher" and are related to but distinct from the standard Masonic Pigpen.
The US Civil War. Confederate prisoners of war used a Pigpen-style substitution system. The Confederate cipher disk, a physical device consisting of two rotating brass discs, used a Pigpen-like geometric substitution as one of its modes. According to the US National Security Agency's historical records, both Union and Confederate forces used a variety of field ciphers, and the Pigpen variant was among the simpler systems employed by captured officers to communicate without their guards' knowledge.
These examples establish the Pigpen cipher as a genuine historical cipher, not a fictional one. Its appearance in movies and games is a reflection of its real history, not the source of it.
The Pigpen cipher is a monoalphabetic substitution cipher. This means it has the same weakness as every other cipher in that class: it preserves the frequency distribution of the plaintext letters.
In English, the letter E appears roughly 12.7 percent of the time, followed by T at about 9 percent and A at about 8 percent. In a Pigpen-encrypted message, the symbol that replaces E will appear at the same 12.7 percent rate. A cryptanalyst who counts symbol frequencies and compares them to standard English letter frequencies can recover the grid mapping in a matter of minutes, given a few hundred characters of ciphertext.
This is not a theoretical attack. Frequency analysis has been used to break monoalphabetic substitution ciphers since the 9th century, when the Arab scholar Al-Kindi described it in his "Manuscript on Deciphering Cryptographic Messages." Al-Kindi's work, documented by Jim Al-Khalili in his history of Islamic science, predates European cryptanalysis by centuries. The technique is the foundation of classical cryptanalysis.
The Pigpen cipher was never intended to resist this attack. Freemasons used it to keep records away from non-members who might glance at a document but not sit down with a frequency table. For that purpose, the visual obscurity of the symbols was sufficient. Against a trained cryptanalyst, the cipher falls immediately.
You can practice frequency analysis on Pigpen-encrypted text using our Substitution Cipher Helper, which lets you map symbols to letters and check the result against English frequency distributions.
The standard Pigpen cipher uses a fixed grid. The letters always go in the same positions, so anyone who knows the system can decode any message. Several variants modify this to increase security.
Rosicrucian cipher. The Rosicrucian variant adds extra symbols to the grid system, sometimes representing whole words or concepts rather than individual letters. It also uses a different geometric arrangement in some versions. The Rosicrucian cipher appears in 18th-century Hermetic and alchemical texts and is associated with the Rosicrucian order, a mystical society that overlapped with Freemasonry in membership and interests.
Knights Templar variant. Some Masonic traditions, particularly those associated with the Knights Templar degree, use a modified Pigpen grid with a different letter arrangement. The variant is sometimes called the "Knights Templar cipher" and uses a triangular grid structure instead of the standard tic-tac-toe and X shapes.
Keyed grids. A more cryptographically interesting variant uses a keyword to determine the letter placement in the grids. Instead of A through I in the first grid in alphabetical order, the letters are placed in the order determined by a keyword. For example, with the keyword "CIPHER," the first grid would contain C, I, P, H, E, R, followed by the remaining letters in alphabetical order. This makes the cipher a keyed monoalphabetic substitution, which is still breakable by frequency analysis but requires more ciphertext to identify the mapping since the standard alphabetical order cannot be assumed.
None of these variants change the fundamental classification. They are all monoalphabetic substitution ciphers, and they all fall to frequency analysis. The keyed variant is slightly harder to crack because the solver cannot assume the standard grid, but the frequency distribution of the symbols still reveals the mapping given enough text.
The Freemasonry information resources at the Grand Lodge of England and the Wikipedia article on the Pigpen cipher provide additional detail on these variants and their historical context.
The Pigpen cipher has no practical security value in the modern world. It is weaker than ciphers that were considered obsolete centuries ago. But it remains useful for three reasons.
First, it is an excellent teaching tool. The geometric grid system makes the concept of substitution concrete and visual in a way that letter-to-letter substitution does not. Students can see how the cipher works by looking at the shapes, and they can break it by counting frequencies. This makes it a standard first lesson in classical cryptanalysis courses.
Second, it appears constantly in puzzle hunts, escape rooms, and CTF challenges. The distinctive symbols are instantly recognizable to anyone who has seen them before, and the grid system is simple enough to reconstruct from a short ciphertext. If you encounter Pigpen symbols in a puzzle, the standard grid is the first thing to try.
Third, it is a living piece of cryptographic history. The gravestones, lodge records, and Civil War documents that contain Pigpen symbols are real artifacts that you can visit and read. The cipher connects a 9th-century Arab cryptanalytic technique (frequency analysis) to an 18th-century fraternal society's record-keeping to a 21st-century escape room puzzle. That continuity is worth understanding.
If you want to encode your own text in Pigpen symbols or decode a message you have found, use our Pigpen Cipher tool.
Yes. The Pigpen cipher is also called the Masonic cipher, Freemason cipher, Napoleon cipher, or tic-tac-toe cipher. All these names refer to the same geometric substitution system where letters are placed in grids and encoded as the shapes of their grid segments.
Yes. Freemasons used the Pigpen cipher in the 18th and 19th centuries to keep lodge records and ritual text private. David Kahn documents this in "The Codebreakers" (1967). The cipher appears on Masonic gravestones, in lodge minutes, and in Rosicrucian texts from the period.
No. The Pigpen cipher is a monoalphabetic substitution cipher, which means it preserves letter frequencies. It can be broken by frequency analysis, a technique described by the Arab scholar Al-Kindi in the 9th century. It was never designed to resist trained cryptanalysts, only to keep casual readers from understanding Masonic records.
Confederate prisoners of war used a Pigpen-style substitution system. The Confederate cipher disk, a physical rotating-disc device, used a geometric substitution similar to Pigpen as one of its modes. The NSA's historical records document the use of various field ciphers by both Union and Confederate forces.
The Rosicrucian cipher is a variant of the Pigpen cipher that adds extra symbols and sometimes uses a different geometric arrangement. It appears in 18th-century Rosicrucian and Hermetic texts and is associated with the Rosicrucian order, a mystical society that overlapped with Freemasonry.
Every Cipher in National Treasure, Explained
National Treasure uses the Ottendorf cipher, invisible ink, Pigpen cipher, and the real Silence Dogood letters. Some of the cryptography is real. Some is Hollywood. Here is the breakdown.
The Atbash Cipher: 2,500-Year-Old Encryption Still Used in Puzzles
The Atbash cipher is 2,500 years old, appears in the Hebrew Bible, and is self-inverse. It has no key space and zero security. Here is why it still matters.