№ 00173 SEPTEMBER 2026ARTIFACTCIA HEADQUARTERS, LANGLEY, VIRGINIA

Kryptos K4

The Message That Leaked, the Cipher That Didn't

Unsolved since 1990

In September 2025, two journalists found the plaintext to the CIA's most famous unsolved cipher, misfiled in its own creator's donated archive. Jim Sanborn confirmed it was real. A year on, nobody, not the finders, not the firm that paid $962,500 for the archive, can show how the cipher works.

A close-up photograph of Kryptos, a curved copper sculpture with rows of letters cut through the metal. One panel shows a repeating KRYPTOS-keyed alphabet grid; the adjoining curved panel is dense with encrypted characters, their shapes projected as shadows onto the stone courtyard below.
Kryptos at CIA headquarters, Langley — the keyed alphabet panel Sanborn used to help solve K1 through K3 (left) and one of the sculpture's encrypted copper panels (right), its cut letters casting their shapes onto the ground. K4, 97 characters, is somewhere in text like this.Carol M. Highsmith, courtesy of the Library of Congress · Public domain

What We Know

Jarett Kobek was paging through boxes of Jim Sanborn’s donated papers at the Smithsonian’s Archives of American Art when he hit a scrap of bad handwriting that stopped him: the words “Berlin clock.” It was September 2025. Kobek and journalist Richard Byrne weren’t hunting for a cipher solution — they were researching Sanborn’s Kryptos, the encrypted copper sculpture Sanborn built with retired CIA cryptographer Ed Scheidt for the agency’s Langley courtyard, dedicated November 3, 1990. Three of its four passages had been broken within a decade of installation, first quietly, inside the CIA, then publicly, by outside codebreakers. The fourth, 97 characters beginning “OBKR,” was built to be harder. Sanborn has described the sculpture’s four sections as built to peel back in layers, each one tougher than the last. It had resisted every attempt for thirty-five years.

What Kobek was holding looked like K4’s answer. He and Byrne emailed Sanborn. Sanborn confirmed the scraps were genuine, and asked them to sign a nondisclosure agreement. They refused, but agreed on their own terms to keep the plaintext itself private. Kobek has been explicit, on the record, about what they did and didn’t do: “There’s no way on earth that this is a cryptographic solve, and we have not claimed that.” They’d found an archived answer. They hadn’t broken a code.

Two months later, on November 20, 2025, Sanborn auctioned his entire Kryptos archive — the original K4 coding system among items he kept confidential even from the auction house itself — for $962,500, to Paradigm, a cryptocurrency investment firm. Paradigm’s own account of the purchase, published the following June, adds a detail that complicates the story further: they chose not to look. Sanborn typed the plaintext into a laptop for them, they hashed it, and they deleted the readable copy. Paradigm holds a way to check an answer. It doesn’t hold the answer, and by its own account, doesn’t want to.

The Roadblock

For thirty-five years, K4’s difficulty looked like arithmetic: find the right key, run it against the ciphertext, get English out the other end. The 2025 discovery scrambled that assumption without solving it. The plaintext existing somewhere doesn’t hand anyone the rule that produced it — the specific substitution values, keystream, and gate logic Sanborn and Scheidt built in 1988 to turn one into the other. A cipher without its method is a locked door with the room behind it described to you secondhand: useful, even vindicating, but not the same as holding the key.

What makes this genuinely hard, not just guarded, is that the only two people who can confirm any reconstruction, Sanborn and Scheidt, have spent decades handing out plaintext in single words, years apart, and never the mechanism behind them. The 2025 auction proved they’ll sell the coding charts before they’ll publish them: even Paradigm, now the closest thing the public has to an owner of that material, says it deliberately didn’t read its own purchase. Every reconstruction effort since has had to work from the outside in, matching outputs without ever confirming the process. It’s the exact condition that has already produced one false solve.

Best Guesses

Anchor-Web Reconstruction

An anonymous project called SolveKryptos spent 2026 building outward from what’s actually confirmed: the four anchor words Sanborn released between 2010 and 2020, and the keyed alphabet cut into the sculpture’s own tableau panel. Its current model treats K4 as a variant of a Quagmire III cipher, using letters read directly off the copper as a physical keystream. Across June and July, the site reported several additional values as “closes from public data” — its own term for a value derived from the confirmed anchors rather than the leaked plaintext. The site says so itself, without hedging, though: most of its substitution values are back-solved from the leaked plaintext, not independently recovered. Reproducing the answer and matching Sanborn’s actual method are different tests, and only the first one has been passed. Nobody behind the project has even put a name to it.

Words Without the Method

Elonka Dunin, who has kept the standard public record on Kryptos for over two decades, draws a harder line: “One thing is to have the words. It’s another to have the method. If they don’t have the method, it’s not solved.” Kobek and Byrne, the two people who actually held the plaintext, land closer to her position than to anyone celebrating their find as a solve. On this view, no reconstruction closes the case, however careful its math. Nothing short of Sanborn and Scheidt’s own coding charts can confirm it, and those charts are sitting in a private archive nobody outside Paradigm has read.

Pattern-Matched, Not Cracked

This isn’t K4’s first false dawn. In February 2025, blogger Michael Naughton announced he’d cracked it using the AI model Grok 3, a simple reverse-the-text, apply-Vigenère-with-KRYPTOS method that produced a clean, plausible-looking sentence about the Berlin Clock. It read like a solution. Cryptanalyst Aaron Toponce, cataloguing the parade of ChatGPT-, Claude-, and Grok-generated “solutions” K4 has attracted, checked them against the only plaintext Sanborn has actually confirmed: the letters at the EAST, NORTHEAST, BERLIN, and CLOCK anchor positions. Naughton’s output, like the others, doesn’t put those letters where Sanborn’s own clues say they belong. Sanborn never endorsed it. The real archive sold nine months later anyway.

Built to Resist Reconstruction

Line up Sanborn’s own documented choices and a pattern appears without anyone needing to guess at what’s in his head: four clues in ten years, never the method behind them; a donated archive that turned out to hold the plaintext, seemingly by accident, but never the coding charts; an auction structured so even the winning bidder could decline to look. Paradigm’s own public position treats the mystery as worth protecting, not settling. If that pattern holds, the archive leak may be the only resolution K4 ever gets: a system built, on this reading, so that leaking the message would never hand over the method too.

The Verdict

Sanborn and Scheidt could close this outright today by publishing the actual coding charts. Thirty-five years of releasing single words instead of the method suggests they won’t do it on anyone’s schedule but their own. Short of that, prize money is on the table right now for anyone who can demonstrate a real attack against a K4-class cipher — Paradigm’s Capture-the-Flag competition, still live. That’s the bar the anchor-web reconstruction hasn’t cleared yet: not a model that reproduces a known answer, but one built and tested blind, before its author ever saw the plaintext.

The strongest evidence, if it ever arrives, will look almost dull next to a leaked archive box: an independent reconstruction, built from public data alone, checked afterward against ciphertext its author never had the plaintext for, not fitted to it beforehand. Nobody has produced one yet. Kobek and Byrne found the words by accident. The method still has to be earned.

Where do you stand?

The Rabbit Hole