In September 2025 journalists found the Kryptos K4 plaintext on scraps of paper in the Smithsonian archives. The cipher itself was never cracked. Here is the difference between recovered and solved, and what Sanborn revealed next.
In September 2025, two journalists emailed the sculptor Jim Sanborn with the correct plaintext of Kryptos K4. Headlines called it a solve. It was not.
Jarett Kobek and Richard Byrne had not broken the cipher. They found the deciphered text on scraps of paper sitting in the Smithsonian Institution archives, referenced by Sanborn's own auction announcement as "coding charts." Sanborn's response was blunt: "K4 has not been solved or decrypted." The method, the key, and the algorithm that turns those 97 ciphertext characters into readable English are still unknown to the public.
This post separates what actually happened from the "Kryptos solved" framing that spread in late 2025. You can experiment with the ciphers Sanborn did use on the first three panels with our Kryptos cipher tool.
Kryptos is a encrypted copper sculpture by Jim Sanborn, installed in the courtyard of the Central Intelligence Agency headquarters in Langley, Virginia, in 1990. Sanborn worked with Ed Scheidt, the retiring chairman of the CIA's Cryptographic Center, to design ciphers that would be challenging but not impossible. The sculpture's left panel holds four encrypted passages, labeled K1 through K4, totaling 869 characters.
K1 and K2 use a keyed Vigenere cipher with a modified alphabet (KRYPTOSABCDEFGHIJLMNQUVWXZ) and the keywords PALIMPSEST and ABSCISSA. K3 uses a route transposition cipher that scrambles character order. The first three passages were solved between 1992 and 1999. An NSA team solved K1 through K3 internally in 1992, though this was not publicly revealed until years later. CIA analyst David Stein solved the same three passages by hand, working pencil and paper over lunch breaks, and presented his work in 1998. Computer scientist Jim Gillogly independently solved K1 through K3 in 1999 using a Pentium PC and published his method publicly.
K4 is different. It is 97 characters long and begins with "OBKR." No one has produced a verified cryptographic solution in 35 years. You can read the full background and the solved passages on the Wikipedia Kryptos article, and the CIA maintains an official Kryptos page describing the sculpture's history.
In August 2025, Sanborn announced he would auction off the K4 solution and related documents, ending 35 years of personal stewardship over the puzzle. The auction listing referenced "coding charts" among the materials. That detail turned out to matter more than anyone expected.
On September 3, 2025, journalists Jarett Kobek and Richard Byrne emailed Sanborn with the correct K4 plaintext. They had not cracked anything cryptographically. Following the auction announcement's reference to "coding charts," they searched the Smithsonian Institution archives and found scraps of paper bearing the deciphered text. The plaintext was sitting in a box, documented and waiting.
The New York Times reported the recovery in October 2025. Sanborn confirmed the text was correct but drew a hard line on what it meant. He asked Kobek and Byrne to sign non-disclosure agreements. They refused. They did, however, agree not to publish the plaintext. As of this writing, the public does not know what K4 says, and the journalists who found it are keeping it to themselves.
This is the detail that got lost in coverage. Finding the answer written down is not the same as deriving it from the ciphertext. If you want to understand why that distinction matters, try identifying an unknown cipher yourself with our cipher identifier and notice how different the work of "what is this" is from "what does this say."
The word "solved" gets used loosely in cipher coverage. In cryptanalysis it has a specific meaning: you have derived the method and key that transform ciphertext into plaintext, and you can reproduce the transformation. A recovered plaintext, by contrast, is just the output. You know what the message says. You do not know how it was encrypted.
K4 in 2025 is the second case. Kobek and Byrne found the plaintext in the Smithsonian archives. The cryptographic method, the key, and the relationship between "OBKR" and the first plaintext word remain unknown to the public. Sanborn said so directly: "K4 has not been solved or decrypted." He was not being pedantic. Without the method, no one can verify the solution independently, and no one can confirm whether the recovered text is complete or whether scraps are missing.
This matters for a practical reason. A cryptographic solution is falsifiable. You can take the key, apply it to the ciphertext, and check the output. A recovered document is an assertion. You trust the archive, the handwriting, and the provenance. The Smithsonian scraps are strong evidence, but they are not proof of the mechanism.
Compare this to the Zodiac Z340 cipher, which was solved in 2020 when David Oranchak, Jarl Van Eycke, and Sam Blake identified the transposition route and substitution key, then applied them to produce readable English that the FBI verified. That was a solve. K4 in 2025 was a recovery. The Scientific American coverage of Kryptos has tracked this distinction carefully across the years.
In November 2025, Sanborn appeared at the International Spy Museum in Washington, D.C., and released four new clues. Two historical events figure in the K4 solution: a 1986 trip Sanborn took to Egypt, and the 1989 fall of the Berlin Wall. He also clarified that "BERLINCLOCK," a string long suspected to be a clue, refers to the World Clock (the Berlin Uhr, a public art installation in Berlin). He counseled solvers to use "creativity."
Sanborn also confirmed something that had been rumored for years: there is a K5. It is 97 characters, like K4, and it will be released only when K4 is solved. Note the word "solved," not "recovered." The auction, announced in November 2025 per the Washington Post, will include both the K4 and K5 solutions and the related documents.
The Egypt and Berlin clues point at the content of the plaintext, not the cipher mechanism. They tell you what the message is about. They do not tell you how it was encrypted. This is consistent with Sanborn's long practice of releasing clues that narrow the interpretive space without revealing the algorithm. If K1 and K2 are any guide, the mechanism could be a keyed Vigenere variant, which you can study hands-on with our Vigenere cipher tool. But K4 could just as easily be something Scheidt and Sanborn designed from scratch, in which case none of the standard tools will identify it.
If you were working on K4 before September 2025, the recovery changes your problem in one specific way. You now know the plaintext exists and is recoverable from documents. You do not have the plaintext yourself, but you know the message is finite, specific, and tied to Egypt and Berlin in 1986 and 1989.
That is actually useful. It constrains the search space. A 97-character message about a 1986 Egypt trip and the 1989 Berlin Wall is not arbitrary text. If you produce a candidate decryption that reads like random English, it is probably wrong. If you produce one that references those events, it deserves a closer look.
What the recovery does not give you is the key. Until someone derives the method from the ciphertext, or the auction winner publishes the solution documents, K4 remains cryptographically unsolved. The plaintext is known to a small number of people. The cipher is not.
For anyone who wants to attempt the real problem, the honest starting point is that K4 may not be a standard cipher at all. It may be a custom construction. Frequency analysis, Index of Coincidence, and Kasiski examination all assume a known cipher family. If K4 breaks those assumptions, you are doing original cryptanalysis, not running a known attack. That is a harder, slower kind of work, and it is the work that has gone unfinished for 35 years.
No. In September 2025 journalists Jarett Kobek and Richard Byrne found the K4 plaintext on scraps of paper in the Smithsonian Institution archives. Jim Sanborn confirmed the text was correct but stated that K4 has not been solved or decrypted. The cryptographic method and key remain unknown to the public.
The public does not know. Kobek and Byrne agreed to keep the plaintext secret despite refusing to sign NDAs. Sanborn has said the solution involves a 1986 trip to Egypt and the 1989 fall of the Berlin Wall, and that BERLINCLOCK refers to the World Clock, but the actual decrypted text has not been published.
K5 is a second unsolved 97-character message that Sanborn confirmed exists in 2025. It will be released when K4 is solved. The November 2025 auction of the K4 solution documents will also include the K5 solution.
An NSA team solved K1 through K3 internally in 1992. CIA analyst David Stein solved them by hand and presented his work in 1998. Computer scientist Jim Gillogly independently solved them with a computer in 1999. K1 and K2 use a keyed Vigenere cipher. K3 uses a route transposition cipher.
K4 has been unsolved for 35 years since the sculpture was installed at CIA headquarters in 1990. The 97-character passage beginning with OBKR resisted every public cryptographic attempt, and the September 2025 plaintext recovery from Smithsonian archives did not produce the encryption method.
Kryptos Sculpture Decoder
Encrypt and decrypt with the Kryptos sculpture ciphers: keyed Vigenere (K1, K2) and route transposition (K3) using the modified KRYPTOS alphabet from Jim Sanborn's CIA artwork.
Code Identifier
Identify the cipher or encoding used in a piece of text. Paste encoded or encrypted data and the code identifier returns ranked candidates with confidence scores.
Vigenère Cipher
Polyalphabetic substitution cipher using a keyword for enhanced encryption.
The Zodiac Killer Ciphers: How Z340 Was Solved After 51 Years
For 51 years, a 340-character cipher sat in FBI files. It was solved in December 2020 by three amateur codebreakers working from home. Z13 and Z32 remain unsolved. Here is how it was done.
The Voynich Manuscript: The World's Most Mysterious Undeciphered Book
A 240-page book in a script that matches no known language, with plants that do not exist, carbon-dated to the early 1400s. Studied for 600 years. Still unread. Here is what we know and what we do not.