Zodiac Z13, Somerton Man, Kryptos K4, Voynich, Beale, and Ricky McCormick. Six famous unsolved ciphers, their current status as of August 2026, and why each one resists solution.
Some ciphers are unsolved because they are too short. Some are unsolved because the key is lost. Some are unsolved because the system itself is unknown. And at least one, Kryptos K4, is unsolved even though the plaintext was recovered in September 2025, because nobody can figure out the cryptographic method that produced it.
This post covers six of the most famous unsolved cipher cases, with their current status as of August 2026. The list includes the Zodiac Killer's Z13 and Z32, the Somerton Man code, Kryptos K4, the Voynich Manuscript, the Beale ciphers, and the Ricky McCormick notes. Each case resists solution for a different reason, and understanding those reasons teaches you more about cryptanalysis than any solved case can.
You can explore the Zodiac ciphers interactively with our Zodiac Cipher Explorer and the Beale ciphers with our Beale Ciphers tool.
The Zodiac Killer sent four ciphers to Bay Area newspapers between 1969 and 1970. Two are solved: Z408 (cracked in 1969 by Donald and Bettye Harden) and Z340 (cracked in December 2020 by David Oranchak, Jarl Van Eycke, and Sam Blake, verified by the FBI in January 2021). Two remain unsolved: Z13 and Z32.
Z13 is a 13-character cipher mailed on April 20, 1970, accompanied by the message "My name is ---." It was presumed to encode the killer's name. Z32 is a 32-character cipher mailed on June 26, 1970, accompanied by a map of the San Francisco Bay Area with a crosshair over Mount Diablo. It was presumed to encode geographic coordinates for a bomb.
Both are unsolved for the same reason: they are too short. With 13 characters, thousands of English names can be forced to fit the ciphertext pattern. The repeating-symbol constraints in Z13 (positions 1/12, 3/11, 8/13, and 5/7/9) narrow the field, but not enough to produce a unique solution. Z32 has the same problem. Without external evidence, there is no way to verify any proposed plaintext.
In 2025-2026, independent investigator Alex Baber claimed to have decoded Z13 as "Marvin Merrill" (an alias for Marvin Margolis) using AI and traditional cryptanalysis, with verification by former NSA codebreaker Ed Giorgio. Analyst Steve Hodel published a rebuttal in February 2026 arguing that the Merrill reading violates Z13's repeating-symbol constraints under standard substitution rules. The FBI has not verified any Z13 solution.
A January 2026 paper published on Zenodo took a different approach to Z32. It formally analyzed Z32 as a constraint satisfaction problem and argued that the cipher is structurally undecipherable, defining it as an "anti-cipher" that encodes a terminal state rather than recoverable content. If correct, Z32 has no solution to find.
You can examine all four Zodiac ciphers and test your own theories with our Zodiac Cipher Explorer.
On December 1, 1948, a dead man was found on Somerton Beach in Adelaide, South Australia. He carried no identification. A scrap of paper in his pocket read "Tamam Shud" (Persian for "finished" or "ended"), torn from a copy of the Rubaiyat of Omar Khayyam. The book was later found, and inside it were five lines of handwritten letters that appeared to be a code.
The code has never been cracked. It consists of approximately 50 letters arranged in five lines, with some letters crossed out and replaced. Australian military intelligence examined it in the 1950s and could not identify the system. Multiple amateur and academic attempts over seven decades have failed to produce a verified solution.
The man's identity was also unknown for decades. In 2022, a team led by Derek Abbott of the University of Adelaide used DNA genealogy to identify the man as Carl Webb, a Melbourne-born electrical worker who disappeared in 1947. However, the identification has not been formally confirmed by the South Australian coroner as of August 2026. The code itself remains unsolved regardless of the identity question.
The Somerton Man code resists solution for two reasons. First, the system is unknown. It does not match any standard cipher classification. Second, the text is short enough that many plaintexts can be forced to fit. Some researchers, including Abbott, have suggested it may be a one-time pad or a book cipher using the Rubaiyat as the key text. If it is a one-time pad, it is mathematically unbreakable without the key. If it is a book cipher, the specific edition of the Rubaiyat used as the key has not been recovered.
The Wikipedia article on the Tamam Shud case documents the full history and the various proposed solutions, none accepted by the cryptographic community.
Kryptos is a sculpture by Jim Sanborn installed at the CIA headquarters in Langley, Virginia, in 1990. It contains four encrypted sections. K1, K2, and K3 were solved between 1999 and 2005 by CIA analyst David Stein and NSA cryptanalysts. K4, a 97-character section, remained unsolved for 35 years.
In September 2025, the Smithsonian Institution announced that the K4 plaintext had been recovered. The recovery was not a cryptographic breakthrough in the traditional sense. Sanborn had provided the plaintext to the Smithsonian as part of an archival project, confirming what the text said. The cryptographic method, however, remains unknown. Sanborn has not fully disclosed the encryption system he used for K4, and cryptanalysts have not independently reproduced the plaintext from the ciphertext using a deterministic algorithm.
This is an unusual situation. In most unsolved cipher cases, the plaintext is the unknown. Here, the plaintext is known but the method is not. Cryptanalysts are now working backward from the plaintext and ciphertext to deduce the algorithm, a process called known-plaintext analysis. Sanborn has also announced that a fifth section, K5, exists, though its contents and location have not been disclosed.
You can explore the Kryptos cipher, including the solved sections and the K4 ciphertext, with our Kryptos Cipher tool.
The Voynich Manuscript is a 240-page illustrated codex written in an unknown script. Carbon dating of the parchment places it in the early 15th century, approximately 1404-1438. It is held at Yale University's Beinecke Rare Book and Manuscript Library under the catalog number MS 408.
The manuscript contains text in an unknown writing system, accompanied by illustrations of plants, astronomical diagrams, and figures in pools of liquid. No one has decoded the text. The script does not match any known writing system. Statistical analysis of the text shows properties consistent with natural language: word length distributions follow Zipf's law, and there are repetitive word patterns. But the language, if it is a language, has never been identified.
The manuscript resists solution because the writing system is entirely unknown. If it is a cipher, the system has no analog in the cryptographic literature. If it is a constructed language, the grammar and vocabulary are lost. If it is meaningless gibberish, as some researchers have argued, then there is nothing to solve.
The Beinecke Library's Voynich Manuscript page provides high-resolution scans of the entire manuscript. The Wikipedia article summarizes the major proposed solutions and why none have been accepted.
The Beale ciphers are three ciphertexts published in an 1885 pamphlet by James B. Ward, titled "The Beale Papers." According to the pamphlet, a man named Thomas J. Beale buried a treasure of gold, silver, and jewels in Bedford County, Virginia, in the 1820s and left the ciphers with an innkeeper before departing and never returning.
B1 and B3 are unsolved. B2 was solved by Ward himself, who reported that it used the Declaration of Independence as a book cipher. Each number in B2 corresponds to the first letter of a word at that position in the Declaration. The decoded text describes the treasure's location in Bedford County.
B1, which purportedly encodes the treasure's exact location, and B3, which lists the heirs, have never been cracked. They have been subjected to extensive analysis using various key texts, including the Bible, the Constitution, and Shakespeare's works. No solution has been verified.
The Beale ciphers resist solution because they are book ciphers with unknown key texts. A book cipher is only as solvable as the key text is identifiable. If Beale used an obscure document that no longer exists, or a document with a specific printing or edition that has been lost, the ciphers are permanently unsolvable. The short length of B1 and B3 also means that many texts can be made to produce plausible-looking plaintext, making verification impossible without finding the treasure.
You can work with the Beale ciphers and try different key texts using our Beale Ciphers tool.
On June 30, 1999, the body of 41-year-old Ricky McCormick was found in a Missouri cornfield. He had been murdered. Two handwritten notes in his pockets contained approximately 30 lines of mixed letters, numbers, and parentheses. The FBI's Cryptanalysis and Racketeering Records Unit, which reportedly solves 99 percent of the ciphers it receives, could not break them.
In March 2011, the FBI published the notes and asked the public for help. The response was overwhelming, but no solution was accepted. McCormick's family said he had used his own coded writing since boyhood and that no one had ever been able to read it.
The leading hypothesis is that the notes are an idiolectic cipher: a system invented and used by a single person, where the key is not a mathematical value but a lifetime of personal associations. From the cryptanalyst's perspective, such a cipher is functionally equivalent to a one-time pad. Even with all the ciphertext in the world, recovering the plaintext requires recovering the author's mental model.
The McCormick notes resist solution because the system is unknown and unique to one person. The FBI tested standard ciphers including Vigenere, Playfair, Hill, and columnar transposition. None fit. Nick Pelling, a cipher historian who studied the notes, suggested in a 2024 analysis that the number groups could be references to locations in downtown St. Louis, rendered in McCormick's idiosyncratic style. Without someone who shared McCormick's environment, the notes may be permanently unreadable.
These six cases illustrate the four reasons a cipher can resist solution.
Too short. Z13 (13 characters) and Z32 (32 characters) are mathematically underdetermined. Many plaintexts fit the ciphertext, so no proposed solution can be verified without external evidence. This is the same problem that makes short one-time pad segments unbreakable: there is not enough data to constrain the solution space.
One-time pad or lost key. The Somerton Man code may be a one-time pad using the Rubaiyat as the key. If the key text is lost or the specific edition is unknown, the cipher is mathematically unbreakable. The Beale ciphers B1 and B3 face the same problem if the key text is an obscure or lost document.
Unknown system. The Ricky McCormick notes and the Voynich Manuscript use systems that do not match any known cipher or writing system. Standard cryptanalysis assumes you know the algorithm and need to find the key. When the algorithm itself is unknown, there is no framework to work within.
Known plaintext, unknown method. Kryptos K4 is the rare case where the plaintext is known but the encryption method is not. This turns the problem inside out. Instead of finding the plaintext, cryptanalysts must deduce the algorithm from a known plaintext-ciphertext pair, which may or may not be possible depending on how Sanborn constructed it.
The common thread is that unsolved ciphers are unsolved because they break the assumptions that standard cryptanalysis relies on. Frequency analysis assumes a monoalphabetic substitution. The Kasiski examination assumes a repeating key. Brute force assumes a known algorithm with a finite key space. When none of these assumptions hold, the tools of classical cryptanalysis have nothing to grip.
You can identify which cipher system a given ciphertext might belong to using our Cipher Identifier, though it, like all identification tools, requires the system to be within its known catalog.
The Voynich Manuscript is arguably the most famous unsolved cipher, studied for over a century without a verified solution. The Zodiac Z13 and Z32 ciphers, Kryptos K4, and the Beale ciphers are also among the most widely studied unsolved cases.
The K4 plaintext was recovered in September 2025 when the Smithsonian confirmed the text from materials provided by sculptor Jim Sanborn. However, the cryptographic method remains unknown. Cryptanalysts are now working to deduce the algorithm from the known plaintext-ciphertext pair. A fifth section, K5, has also been announced.
Z13 is only 13 characters long. With so few characters, thousands of English names can be forced to fit the ciphertext pattern. The repeating-symbol constraints narrow the field, but not enough to produce a unique, verifiable solution. A 2025-2026 claim that Z13 decodes to "Marvin Merrill" is disputed because it does not satisfy the cipher's structural constraints.
The Beale ciphers were published in an 1885 pamphlet by James B. Ward. B2 was solved using the Declaration of Independence as a book cipher. B1 and B3 remain unsolved. Some researchers believe the entire story is a hoax, while others continue searching for the key texts. No treasure has ever been found in Bedford County, Virginia.
An idiolectic cipher is a system invented and used by a single person, where the key is a lifetime of personal associations rather than a mathematical value. The Ricky McCormick notes are the leading example. From the cryptanalyst's perspective, an idiolectic cipher is functionally equivalent to a one-time pad: recovering the plaintext requires recovering the author's mental model.
Zodiac Cipher Explorer
Explore all four Zodiac Killer ciphers (Z408, Z340, Z13, Z32) with interactive symbol grids, substitution tools, and verified solutions.
Beale Ciphers Decoder
Decode the Beale ciphers using a book cipher with the Declaration of Independence. Solve Beale No. 2 and experiment with your own key texts for the unsolved No. 1 and No. 3.
Kryptos Sculpture Decoder
Encrypt and decrypt with the Kryptos sculpture ciphers: keyed Vigenere (K1, K2) and route transposition (K3) using the modified KRYPTOS alphabet from Jim Sanborn's CIA artwork.
Code Identifier
Identify the cipher or encoding used in a piece of text. Paste encoded or encrypted data and the code identifier returns ranked candidates with confidence scores.
The Zodiac Killer Ciphers: How Z340 Was Solved After 51 Years
For 51 years, a 340-character cipher sat in FBI files. It was solved in December 2020 by three amateur codebreakers working from home. Z13 and Z32 remain unsolved. Here is how it was done.
The Somerton Man: Australia's Tamam Shud Cipher That's Never Been Solved
On December 1, 1948, a man was found dead on Somerton Beach in Adelaide with a torn scrap reading 'Tamam Shud.' A code in a copy of the Rubaiyat has never been decoded. A 2022 DNA identification is contested. Here is what is known.
Kryptos K4 Is Not Solved. Here's What Actually Happened in 2025
In September 2025 journalists found the Kryptos K4 plaintext on scraps of paper in the Smithsonian archives. The cipher itself was never cracked. Here is the difference between recovered and solved, and what Sanborn revealed next.
The Voynich Manuscript: The World's Most Mysterious Undeciphered Book
A 240-page book in a script that matches no known language, with plants that do not exist, carbon-dated to the early 1400s. Studied for 600 years. Still unread. Here is what we know and what we do not.
The Ricky McCormick Cipher: Two Notes the FBI Cannot Crack
A 41-year-old man was found dead in a Missouri field in 1999. Two notes in his pockets were written in a code the FBI has never broken. His family says he could barely read. Here is what we know.