On September 15, 2026, OpenAI’s GPT-6 Astra independently decrypted a World War II German Enigma ciphertext known as MVUEH in just two days. Comprising a concise 82 letters, the intercept had resisted cryptanalysis for 21 years since its inclusion in public databases of unsolved ciphers in 2005. Over the past two decades, numerous amateur and professional cryptanalysts poured immense computing power into exhaustive keyspace searches, all coming up empty-handed.
The true significance of this breakthrough lies far beyond showcasing raw AI compute. For the first time, an AI model executed the complete, end-to-end workflow of a research cryptanalyst. It selected the target message, gathered circumstantial historical evidence, wrote custom Enigma machine simulators and Bombe decryption tools from scratch, and independently tracked down original German Federal Archives reference codes to verify the historical context. Rather than operating merely as a guided equation solver, the model behaved as an autonomous digital historian.
What had baffled human researchers for over two decades was not the mathematical perfection of the Enigma algorithm itself. Instead, the stumbling block was a human transcription error in the original transmission, coupled with an exceptionally rare mechanical rotor stepping that occurred right at the 72nd letter. Human researchers routinely pruned such low-probability edge cases to make their searches computationally tractable. Unburdened by human preconceptions, the AI systematically exhausted the rejected branches.
21 Years Unbroken: Tripped Up by a Rare Rotor Step at Letter 72
To appreciate why this 82-letter telegram proved so elusive, one must look back to the Eastern Front on July 10, 1941. At 17:30 that afternoon, the radio station of the SS Totenkopf Division quartermaster intercepted a brief transmission from callsign 2ny, logged as message Nr. 172. Transcribed by the operator and designated MVUEH, the ciphertext remained sealed in historical archives for decades as one of the few surviving unsolved wartime Enigma intercepts—a legendary hard nut to crack on cryptography forums.
Figure: A preserved German military Enigma cipher machine. Source: Wikimedia Commons, CC BY-SA 2.0 fr
At the heart of the Enigma machine lies a set of electromechanical rotors. Each keypress advances the rotor mechanism by one step, altering the internal electrical pathways and generating up to 1.59 × 10^20 possible cryptographic combinations. Typing the same letter consecutively produces different ciphertext outputs every time. For an 82-letter message, human analysts universally presumed that the leftmost, slowest-moving rotor would never advance during such a brief burst. That common-sense assumption pruned the search space by a factor of 26, but it also discarded the branch leading to the solution.
Astra’s brute-force exploration uncovered an ironic hardware reality: as the 72nd letter was struck, the leftmost rotor crossed its turnover notch and advanced one position. This unexpected mechanical turnover invalidated every conventional heuristic pruning strategy. While human experts discarded the low-probability scenario to conserve compute, the machine methodically mapped every physical gear position, uncovering the rare stepping that had confounded researchers for decades.
A Twin Cipher and a 15-Letter Crib: Exploiting Repeated Place Names
Brute force alone cannot penetrate the astronomical combinatorial space of Enigma settings; Astra required external historical context. Scanning historical records, the model identified a companion transmission sent on the very same day: message Nr. 173 (intercept code SIPVX). This 94-letter message had been deciphered on June 9, 2017, by cryptanalyst Alex Shovkoplyas. Recognizing that both messages shared identical tactical backgrounds and transmission conditions, Astra inferred they likely originated from the same radio detachment.
The daily key setups for the two intercepts, however, were not identical. While both utilized rotor order 512, their plugboard connections (stecker) and initial ring settings differed significantly. Applying SIPVX’s parameters directly to MVUEH failed. Astra shifted focus to plaintext patterns, selecting a bold crib: the repeated German place name “ROSENOW ROSENOW”. In German military communications, Rosenow served as both a township and an administrative district name; repeating it was the telegraphic equivalent of typing “NEW YORK NEW YORK”.
Betting on a 15-letter crib (including space) carried immense computational risk. If those 15 letters did not appear in the original message, every computational cycle would be wasted. But Enigma possessed a fatal hardware flaw: a letter could never encipher to itself. Capitalizing on this property, longer cribs exponentially prune invalid key candidates. Astra wrote tailored Python and C++ Enigma simulators and virtual Bombe decryption routines on the fly. Anchored by the repeated place name, it eliminated false states and locked onto the correct machine setup.
Figure: Replica of the Turing-Welchman Bombe at Bletchley Park. Source: Wikimedia Commons, CC BY 2.5
Once deciphered, the plaintext revealed mundane operator errors. The original message read: “Btte Marschweg angeben. Bin in Rosenow, Rosenow. Sofort drahten. Waschbusch.” (“Please indicate route of march. Am in Rosenow, Rosenow. Wire immediately. Waschbusch.”) The radio operator had slipped, misspelling “Bitte” as “Btte”, and omitted a second sender signature present in SIPVX. These irregularities shortened the message from 94 to 82 letters, completely throwing off traditional human frequency analysis.
Writing Its Own Code and Hunting Down Archival Reference Numbers
What astonished the cryptographic community most was the machine’s autonomous initiative in historical archival research. To validate its decryption and establish historical provenance, Astra navigated external historical archival systems without human intervention, locating the exact archival file numbers in the German Federal Archives (Bundesarchiv): RS 3-3/20a and RS 3-3/63b.
These obscure archival signatures were not cataloged on standard cryptographic portals like Crypto Cellar. Frode Weierud, the custodian of Crypto Cellar, recounted spending weeks in traditional archives verifying these very files years ago. Astra completed the entire decryption, script writing, radio log correlation, and archival cross-referencing in under 48 hours.
This achievement marks an operational leap for large language models. Moving from isolated hints to primary archival records and verifying transmission logs moves an AI far beyond a passive computing utility. A digital system gathering archival evidence behaves fundamentally no differently than a cryptanalyst burning the midnight oil at Bletchley Park.
The table below contrasts the human and AI cryptanalytic workflows:
| Stage | Human Cryptanalyst Workflow (2005–2026) | GPT-6 Astra Workflow (September 2026) | Time Comparison |
|---|---|---|---|
| Target Selection | Manual forum posting and message curation | Analyzed ciphertext traits; autonomously selected twin message Nr. 172 | Days for both |
| Hypothesis Building | Pruned search space by assuming no left rotor stepping in short texts | Explored unpruned state space; built high-confidence crib around repeated place names | AI achieved broader coverage |
| Tool Development | Relied on existing open-source Enigma decryption suites | Autonomously wrote custom Python/C++ simulators and Bombe search routines on the fly | Minutes for AI vs. zero new development for humans |
| Archival Research | Traveled to archives; sifted through microfilms and physical records | Autonomously queried external historical archives to locate file reference numbers | Several weeks for humans vs. hours for AI |
Community Debate and Open-Source Verification: Auditing Human Typographical Errors
The demonstration quickly climbed to the top of Hacker News, accumulating over 500 upvotes within hours. Predictably, skepticism emerged in the comments: some wondered whether human researchers had secretly broken the cipher first, with OpenAI buying the discovery for PR. Given recent marketing theatrics across the tech industry, the community treated such skepticism with measured nuance.
Yet technical proofs remain objectively verifiable. The community applied the ultimate reproducibility test: re-encrypting Astra’s recovered plaintext using its published rotor settings and keys. The resulting ciphertext matched the historical intercept character-for-character: ICRVSORMCCWQTATYEVFXDBZGGSNXWLPSYWZYTCBSWULRTBZCVGODVJUSLSOOMJQJZSXSEBZPEYMDNXJYTC. Independent developers also reported replicating the end-to-end break locally using Gemini 3.8 Flash in just 45 minutes.
An 82-letter enigma resisted human analysis for 21 years. Handed the problem, the AI deployed no esoteric magic beyond standard algorithmic principles. It simply audited the obscure corners that humans had dismissed as too tedious to check. It did not overlook the anomalous rotor step at character 72, nor did it choke on the telegrapher’s missing “i”. In this 85-year-old cryptologic duel, the machine did not triumph through superior intellect; it won because it never tires of relentless trial and error.
Reference Links:
- The MVUEH break
- HN Discussion (item?id=49801324)