Venona was a secret US program that ran from 1943 to 1980 and decrypted roughly 3,000 Soviet spy cables. The Soviets reused one-time pad keys. That single mistake let Meredith Gardner and the SIS read KGB traffic for decades.
On February 1, 1943, a small team inside the US Army's Signal Intelligence Service began examining Soviet diplomatic messages that had been accumulating since 1939. The team had no name. The work later became known as Venona, and it ran in secret for 37 years.
Venona decrypted roughly 2,900 to 3,000 Soviet messages out of hundreds of thousands intercepted. That is a tiny fraction. But that fraction was enough to expose Julius and Ethel Rosenberg, confirm the testimony of Whittaker Chambers and Elizabeth Bentley, identify Klaus Fuchs as a Manhattan Project spy, and prove that Soviet espionage inside the United States during and after World War II was far more extensive than anyone publicly admitted.
The technical story is simple and strange. The Soviet system used a one-time pad, which is mathematically unbreakable when used correctly. The Soviets did not use it correctly. Under wartime pressure, they reused key material. That error turned an unbreakable cipher into a breakable one.
You can experiment with the one-time pad mechanism itself using our Vernam Cipher tool, and see how Soviet field ciphers worked with our VIC Cipher tool, which implements the hand cipher carried by KGB officer Reino Hayhanen.
Venona began at Arlington Hall, Virginia, the headquarters of the Signal Intelligence Service (SIS), the precursor to the National Security Agency. The initiative came from Colonel Carter Clarke, who was concerned about Soviet intentions even though the Soviet Union was a wartime ally of the United States. Clarke ordered the SIS to examine Soviet diplomatic communications that had been intercepted and stored since 1939 but never analyzed.
The work was slow. The early team included Genevieve Feinstein, Frank Lewis, and others, but the cryptanalyst who made the biggest difference was Meredith Gardner. Gardner was a linguist with a background in German, French, and other languages who taught himself Russian well enough to work with Soviet ciphertext. He arrived at Arlington Hall in 1946 and began making progress against KGB traffic.
The program was compartmented to an extreme degree. Even within the SIS and its successor, the Armed Forces Security Agency and then the NSA, only a small circle knew Venona existed. The FBI was brought in as a liaison because the decrypted messages pointed to espionage inside the United States, which was a domestic law enforcement matter. Special Agent S. Wesley Reynolds was briefed by Colonel Carter Clarke on September 1, 1947, shortly after the National Security Act of July 26, 1947 created the Central Intelligence Agency. The timing was not coincidental: the new intelligence architecture required careful handling of a source this sensitive.
The NSA's official Venona page hosts the declassified documents, and the CIA's Venona monograph covers the intelligence impact in detail.
The Soviet system was a code superenciphered with a one-time pad. The first layer converted the plaintext Russian (or English, or other language) into a sequence of four-digit code groups using a codebook. The second layer added a one-time pad key, digit by digit, to produce the ciphertext.
The one-time pad is the only cipher that has a mathematical proof of perfect secrecy. Claude Shannon proved this in his 1949 paper "Communication Theory of Secrecy Systems," published in Bell System Technical Journal. If the key is truly random, used exactly once, and kept secret, the ciphertext reveals zero information about the plaintext. Every plaintext of the same length is equally probable. Brute force is meaningless because every possible plaintext is a valid decryption.
The catch is in the word "once." A one-time pad key page must be used one time. If you reuse the same key page for two different messages, you create what cryptanalysts call a two-time pad (or sometimes a one-time pad reuse). When you add the two ciphertexts together, the key cancels out, and you are left with the sum of the two plaintexts. That sum is no longer random. It has structure, because language has structure, and that structure can be exploited.
This is exactly what the Soviets did. Wartime pressure and the manufacturing limits of Soviet key-material production meant that key pages were occasionally duplicated and sent to different stations. The SIS analysts discovered this when they noticed that pairs of intercepted messages, when subtracted, produced output that had the statistical signature of natural language rather than random noise.
The mistake was not small. According to the declassified NSA history, enough key material was reused across the five separate Soviet systems that the analysts could build overlapping cribs and recover plaintext incrementally. The five systems were trade representatives, diplomats, KGB, GRU (army intelligence), and GRU-Naval. Each had its own codebook and its own one-time pad key schedules, but the reuse problem affected several of them.
Our Vernam Cipher tool demonstrates the one-time pad in its purest form. If you type the same key for two different messages, you can see exactly how the security collapses.
Once the analysts knew that key pages were being reused, the attack was mechanical but laborious. The technique is often called crib-dragging.
The process starts with two messages that share the same key page. Call them C1 and C2. Because C1 = P1 + K and C2 = P2 + K (where + is modular addition and K is the shared key), subtracting gives C1 - C2 = P1 - P2. The key is gone. What remains is the difference of the two plaintexts.
If the analyst can guess a word or phrase that appears in one of the messages, they can subtract it from the difference at every possible position. Where the guess is correct, the result is readable text from the other message. Where the guess is wrong, the result is garbage. A correct guess at one position unlocks text that can be used as a crib for the other message, which unlocks more text, and so on.
Meredith Gardner was skilled at this. The first real break into KGB traffic came around 1946. By 1949 and 1950, the team was reading significant volumes of KGB and GRU messages from 1944 and 1945. The work was never fast. Each message could take days or weeks, and many messages were never fully recovered. Of the hundreds of thousands of intercepted Soviet messages, only about 3,000 were decrypted to any usable degree.
The FBI history pages describe how the Bureau used Venona product to investigate and prosecute espionage cases, and the Wikipedia article on Venona provides a consolidated overview with citations to the NSA and FBI sources.
Venona's decrypts named names. The most famous case was Julius Rosenberg, whose KGB codename was LIBERAL. The decrypted messages showed that Julius had recruited contacts and passed technical information to the Soviets. His wife, Ethel Rosenberg, also appeared in the traffic. The Venona evidence gave the government what the trial testimony of Ethel's brother, David Greenglass, had not: independent, documentary proof of involvement. The Rosenbergs were executed on June 19, 1953.
Klaus Fuchs was identified through Venona as a Soviet source inside the Manhattan Project. Fuchs, a German-born British physicist, had passed atomic weapons research to his Soviet handler. Venona decrypts helped confirm his role, and he was arrested in Britain in 1950 after a confession. He was convicted and sentenced to 14 years.
Elizabeth Bentley and Whittaker Chambers had both testified publicly about Soviet espionage networks in the United States before Venona was known. Their testimony was controversial and widely doubted at the time. Venona confirmed large parts of what they had said. Bentley had run a Soviet spy network in Washington. Chambers had been a courier for a Soviet cell that included Alger Hiss, a former State Department official. The Hiss case became one of the defining political controversies of the early Cold War, and Venona decrypts (though not all were shared publicly at the time) supported the case against him.
Igor Gouzenko, a GRU code clerk at the Soviet embassy in Ottawa, defected to Canada in September 1945. His defection was independent of Venona but complementary. He brought out documents and codebook material that helped the Western allies understand Soviet espionage methods. The Gouzenko affair is sometimes credited as the event that started the Cold War in intelligence terms.
The CIA's historical review of Venona covers these cases in detail, and the NSA's released documents include the actual decrypted cables referencing LIBERAL and other codenames.
Venona was kept secret for decades. The NSA and its predecessors did not tell even close allies that the Soviet one-time pad traffic had been partially broken. The concern was that any leak would cause the Soviets to change their systems, ending the program.
The secrecy had costs. Several people were prosecuted or persecuted on the basis of Venona-derived evidence that could not be disclosed in court. The Rosenbergs' defense team never saw the actual decrypts. In some cases, the FBI built parallel evidentiary chains so that Venona would not have to be mentioned at trial.
There is a persistent question about whether the Soviets learned of Venona through their own agents. Kim Philby, the British intelligence officer who was a Soviet mole, worked in Washington from 1949 to 1951 and had some access to US signals intelligence work. Philby himself wrote in his memoir My Silent War (1968) that he became aware of the Venona work. Whether the Soviets fully grasped the scope of the break, or whether they dismissed it, is debated by historians. The fact that Venona continued to produce decrypts into the 1950s and 1960s suggests that whatever the Soviets learned, they did not shut the system down fast enough to stop the bleeding.
The program was finally canceled in 1980. The first public release of Venona decrypts came on July 11, 1995, when Director of Central Intelligence John Deutch announced the declassification at a ceremony at CIA headquarters. The roughly 3,000 decrypted messages were released in six batches over the following years. The full set is now available through the NSA and CIA.
Our Cipher Identifier can help you recognize one-time pad and other cipher types from ciphertext samples, though it cannot, of course, break a properly used one-time pad. Nothing can.
Venona was a secret US cryptanalysis program run by the Signal Intelligence Service and its successors from February 1, 1943 until 1980. It decrypted roughly 2,900 to 3,000 Soviet diplomatic and intelligence messages, exposing spies including Julius and Ethel Rosenberg and Klaus Fuchs. The first public release of decrypts was in July 1995.
The Soviet system used a code superenciphered with a one-time pad, which is unbreakable if the key is used once. The Soviets reused key pages due to wartime production pressure. This created two-time pad pairs that let analysts subtract ciphertexts to recover the difference of the plaintexts, then use guessed words (cribs) to drag out readable text.
Meredith Gardner was the lead cryptanalyst on the Venona project at Arlington Hall. A linguist who taught himself Russian, he produced the first significant breaks into KGB traffic around 1946 and led the incremental recovery of plaintext throughout the late 1940s and 1950s.
Yes. Decrypted KGB messages identified Julius Rosenberg under the codename LIBERAL and showed his role in passing information to the Soviets. Ethel Rosenberg also appeared in the traffic. The Venona evidence was not disclosed at their 1951 trial, but it provided independent confirmation of their involvement.
The first Venona decrypts were released publicly on July 11, 1995, by Director of Central Intelligence John Deutch. The approximately 3,000 decrypted messages were released in six batches. The full set is now available through the NSA and CIA.
VIC Cipher
Encrypt and decrypt using the VIC cipher, the Cold War hand cipher used by Soviet spy Reino Häyhänen. Combines a straddling checkerboard, chain addition, and double columnar transposition. Never broken by cryptanalysis. Browser-based.
Vernam Cipher (One-Time Pad)
Encrypt and decrypt text using the Vernam cipher, the XOR-based one-time pad that Shannon proved is perfectly secure.
Code Identifier
Identify the cipher or encoding used in a piece of text. Paste encoded or encrypted data and the code identifier returns ranked candidates with confidence scores.
The Zodiac Killer Ciphers: How Z340 Was Solved After 51 Years
For 51 years, a 340-character cipher sat in FBI files. It was solved in December 2020 by three amateur codebreakers working from home. Z13 and Z32 remain unsolved. Here is how it was done.
The Enigma Machine: How It Worked and How Bletchley Park Broke It
On July 9, 1941, Bletchley Park decoded an Enigma message that saved 103 ships. The machine looked like a typewriter. It had one mathematical flaw. Learn how rotors, reflectors, and plugboards worked.