A ranked catalogue of every major Kryptos K4 solution claim from the NSA team in 1992 to the 2025 Smithsonian plaintext recovery. Who showed working, who was verified, and why no public cryptographic solution to K4 exists.
Kryptos K4 has attracted claims for 35 years. Most of them are wrong. A few are credible for the wrong reason. One, in 2025, gave us the plaintext without giving us the cipher.
This post ranks the major K4-related claims since 1990 by credibility, using three criteria: did the claimant show their working, was the result independently verified, and did Jim Sanborn confirm it. The ranking is blunt on purpose. A claim that produces the right answer by reading it off a document is not the same as a claim that derives the answer from the ciphertext. You can test your own K4 hypotheses with our Kryptos cipher tool and see which category your work falls into.
A credible K4 claim has to do three things, and most claims do one at most.
First, show the working. A plaintext with no method attached is a guess. The cryptanalysis community needs the key, the algorithm, and the steps that turn "OBKR" into readable English. Second, independent verification. Someone other than the claimant has to apply the method to the ciphertext and get the same output. Third, confirmation from Sanborn, who holds the solution and has consistently distinguished real progress from noise.
A claim that meets all three is a solve. A claim that meets the first two is a strong candidate. A claim that meets only the third is a recovery, not a solve. Everything else is speculation. The Wikipedia Kryptos article tracks the public history of these claims, and Elonka Dunin's Kryptos reference site has maintained the longest-running independent record of attempts and clues.
Here are the major K4-related claims since 1990, ranked from highest credibility to lowest. Note that several of these are credible for K1 through K3, not for K4. That distinction is the whole point.
1. The September 2025 Smithsonian recovery (Kobek and Byrne). Highest credibility for the plaintext, zero credibility as a cryptographic solve. Journalists Jarett Kobek and Richard Byrne found the K4 plaintext on scraps of paper in the Smithsonian Institution archives, referenced by Sanborn's auction announcement as "coding charts." Sanborn confirmed the text was correct. He also stated plainly that K4 has not been solved or decrypted. The method and key are unknown. This claim is verified by the source himself but is a document recovery, not cryptanalysis. Reported by the New York Times in October 2025.
2. David Stein (CIA, 1998, K1-K3). High credibility, but for the wrong passage. Stein solved K1, K2, and K3 by hand over lunch breaks at the CIA, using pencil and paper cryptanalysis. He presented his work in 1998. His method was sound and reproducible. He did not solve K4. Stein's work is credible because it showed the working and was independently reproducible, but it does not belong on a K4 list except to establish that the first three panels are settled.
3. Jim Gillogly (1999, K1-K3). Same category as Stein. Gillogly solved K1 through K3 with a computer, independently confirming Stein's hand solution. His method was published and verifiable. He did not solve K4. Gillogly's contribution was confirming that the first three passages yield to standard cryptanalysis, which narrowed the mystery to K4 specifically.
4. The NSA team (1992, K1-K3). The NSA solved K1 through K3 internally in 1992, before Stein and Gillogly, but the work was classified and not revealed until later. Credible by definition, given the agency, but not a K4 solution and not publicly verifiable at the time. The Scientific American coverage of Kryptos has documented this timeline in detail.
5. Elonka Dunin's reference work (ongoing). Dunin is not claiming a solution. She maintains the most thorough public database of Kryptos clues, attempts, and analysis. Her credibility comes from rigor, not from a solve claim. If you are working on K4, her site is the starting point. She has co-authored a book on Kryptos and has engaged directly with Sanborn over many years.
6. Amateur K4 attempts (hundreds, all wrong). Sanborn at one point charged a $50 fee to review submitted K4 solutions. Every single one was wrong. These claims fail all three criteria: no reproducible working, no independent verification, no Sanborn confirmation. They are noise. The fee was not a gatekeeping mechanism for quality. It was a filter for volume.
7. Fringe claims. Various online posts claim K4 is a hoax, a misprint, or already secretly solved by the CIA. None show working. None are verified. Sanborn has consistently denied them. They rank last.
As of August 2026, no one has published a method that turns the 97 K4 ciphertext characters into verified plaintext. The Smithsonian recovery gave us the answer. It did not give us the algorithm.
This is the gap that matters. A cryptographic solution is a procedure. You take the ciphertext, you apply the key, you get the plaintext. Anyone can repeat it. The Smithsonian recovery is a fact. The plaintext is written on paper in an archive. You can trust the archive, but you cannot reproduce the transformation because you do not know what the transformation is.
Sanborn has said the K4 solution involves a 1986 trip to Egypt and the 1989 fall of the Berlin Wall, and that BERLINCLOCK refers to the World Clock. These are content clues. They tell you what the message is about. They do not tell you how it was encrypted. If K1 and K2 are any guide, the mechanism could involve a keyed Vigenere construction, which you can study with our cipher identifier and related tools. But K4 may be a custom design that does not match any known cipher family, in which case standard identification tools will not help.
The November 2025 auction, announced per the Washington Post, will include the K4 and K5 solution documents. Whoever buys them will possess the method. Whether they publish it is a separate question.
If someone produces a real cryptographic solution to K4, here is what the evidence chain should look like.
They would publish the algorithm, the key, and the step-by-step decryption. The output would match the Smithsonian plaintext (which is still secret, so verification would require Sanborn or the auction winner to confirm). The method would be reproducible, meaning a third party could apply it to the ciphertext and get the same result. And Sanborn would confirm that the method matches the one he and Ed Scheidt designed.
None of the existing claims meet this bar. The Smithsonian recovery meets the confirmation bar but not the method bar. The K1-K3 solves meet the method bar but are not K4 solves. The amateur attempts meet none of the bars.
This is why the ranking above puts the Smithsonian recovery first on plaintext confidence but flags it as a non-solve. It is also why the amateur attempts rank last. A wrong method is worse than no method, because it wastes the time of anyone who tries to build on it. If you are attempting K4 yourself, the Vigenere cracker is a reasonable starting point for testing keyed-substitution hypotheses, but expect to go beyond standard tools if K4 is a custom construction.
No. As of August 2026 no public cryptographic solution to K4 exists. The September 2025 Smithsonian recovery produced the plaintext but not the method. Jim Sanborn confirmed the text but stated that K4 has not been solved or decrypted.
No one has a verified cryptographic method for K4. David Stein, Jim Gillogly, and an NSA team solved K1 through K3 between 1992 and 1999, but none cracked K4. Elonka Dunin maintains the most thorough public reference work on K4 but does not claim a solution.
Yes. Sanborn at one point charged a $50 fee to review submitted K4 solutions. Every submission was wrong. The fee functioned as a volume filter for the large number of amateur attempts he received.
It is a real recovery of the plaintext, not a cryptographic solution. Journalists found the deciphered text on documents in the Smithsonian archives. The encryption method and key remain unknown, so the cipher itself is still unsolved.
Elonka Dunin's Kryptos reference site at elonka.com/kryptos is the longest-running independent record of clues and attempts. The Wikipedia Kryptos article provides a verified overview, and Scientific American has tracked the story in depth over many years.
Kryptos Sculpture Decoder
Encrypt and decrypt with the Kryptos sculpture ciphers: keyed Vigenere (K1, K2) and route transposition (K3) using the modified KRYPTOS alphabet from Jim Sanborn's CIA artwork.
Code Identifier
Identify the cipher or encoding used in a piece of text. Paste encoded or encrypted data and the code identifier returns ranked candidates with confidence scores.
Vigenère Cracker
Auto-crack Vigenère ciphers using Kasiski examination and frequency analysis.
Kryptos K4 Is Not Solved. Here's What Actually Happened in 2025
In September 2025 journalists found the Kryptos K4 plaintext on scraps of paper in the Smithsonian archives. The cipher itself was never cracked. Here is the difference between recovered and solved, and what Sanborn revealed next.
The Zodiac Killer Ciphers: How Z340 Was Solved After 51 Years
For 51 years, a 340-character cipher sat in FBI files. It was solved in December 2020 by three amateur codebreakers working from home. Z13 and Z32 remain unsolved. Here is how it was done.