Kryptos
Partially explainedSummary
A copper sculpture in the courtyard of CIA headquarters carries roughly 1,800 encrypted characters in four passages. Three were broken in the 1990s. The fourth, ninety-seven characters long, has resisted the CIA, the NSA, and thirty-five years of the world's best professional and amateur cryptanalysts.
In September 2025 two researchers obtained its plaintext. They did not break the cipher. They found the answer in a box at the Smithsonian, because the artist had accidentally donated it.
Two months later the artist's archive, including the solution, sold at auction for $962,500 to an anonymous buyer who intends to keep it secret.
The cipher is still unbroken. That distinction is the whole of this record.
What is documented
The object. Kryptos, an S-shaped copper screen flanked by petrified wood, made by the artist Jim Sanborn and dedicated at Langley on 3 November 1990. The encryption was designed with Edward Scheidt, retired chairman of the CIA's Cryptographic Center. Roughly 1,735 characters are cut into the copper, forming four passages, each using a different method.
K1, K2 and K3. All three were broken, and the sequence in which is itself part of the story.
An NSA team solved them in 1993. Nobody knew, because they did not say; the fact emerged from a Freedom of Information Act request in 2013.
A CIA analyst, David Stein, solved them in 1998, working with pencil and paper.
Jim Gillogly, an independent computer scientist, solved them and announced it publicly in 1999, with computer assistance. His was the first public solution, and for years the only one anybody knew about.
The plaintexts include a passage of Sanborn's own composition, a paraphrase of Howard Carter's account of opening Tutankhamun's tomb, and a line, in K2, reading that something is buried out there somewhere.
K4. Ninety-seven characters. Unbroken for thirty-five years.
The clues. Sanborn released fragments of the K4 plaintext over the years to keep the hunt alive: BERLIN in 2010, CLOCK in 2014, and further fragments in 2020. They did not crack it.
The cost to the artist. Sanborn has said publicly that the puzzle has destroyed marriages, brought strangers to his door, and provoked threats against his life. One person has written to him every week for twenty years. He began charging fifty dollars per submitted solution simply to reduce the volume.
The auction. In 2025, aged seventy-nine and in poor health, Sanborn announced that he would auction his complete Kryptos archive, including the K4 solution, and pass the role of keeper to somebody else. He said he no longer had the physical, mental or financial resources to hold it.
The discovery, which is not a solution. In early September 2025, two independent researchers, Jarett Kobek and Richard Byrne, went to the Smithsonian's Archives of American Art and photographed Sanborn's donated papers.
Among them were five pages of scrambled text that Sanborn had inadvertently included in his donation roughly two years earlier. They were copies of documents he had prepared in 1990 to demonstrate to the CIA's historical intelligence staff that the sculpture's text was not offensive.
From these, the researchers derived the K4 plaintext.
Sanborn's reaction, by his own account, was to put his head in his hands. The Smithsonian sealed his papers for fifty years. The researchers stated, in October 2025, that they do not intend to release what they found.
The sale. On 20 November 2025 the archive sold at RR Auction for $962,500, roughly double the high estimate. The buyer is anonymous, has been designated the new keeper, and has undertaken to preserve the secret.
K5. Sanborn has stated that Kryptos was designed to unravel in layers, and that a further passage exists which he calls K5. It has never been published, and the researchers who obtained the K4 plaintext have no knowledge of it.
Leading explanations
There is nothing anomalous here to explain. There is a distinction to protect, and it is the reason this record exists.
K4 has not been solved. Sanborn's own formulation is exact: it has been discovered, not solved. Elonka Dunin, one of the leading independent authorities on the sculpture, put it precisely: having the words is one thing, having the method is another, and without the method it is not solved.
Three people can now read a passage that nobody has decrypted. The encryption system for K4 remains known only to Sanborn, to Scheidt, and now to whoever paid $962,500 for it.
This matters practically, not just semantically. A cipher is broken when somebody can demonstrate the transformation from ciphertext to plaintext. Nobody can. If a second message were encrypted with the K4 system tomorrow, not one person on Earth outside that small circle could read it.
The registry notes a source caution. The clearest statements of the discovered-not-solved distinction have come from the auction house selling the archive, which has an obvious commercial interest in the solution retaining value. The registry states the distinction anyway, because it is cryptographically correct regardless of who is making it, and because the independent researchers who obtained the plaintext have said the same thing themselves.
What the popular version gets wrong
"Kryptos has been solved." It has not. Three of its four passages were solved by cryptanalysis in the 1990s. The fourth was read off a photocopy in an archive, by people who freely say they did not break it.
"Researchers cracked the CIA's unbreakable code." They found it in a box. This is a genuinely remarkable piece of research and it is not cryptanalysis, and the researchers have never claimed otherwise. The headlines did.
"The mystery is over." The method is unknown. K5 exists and is untouched. And the plaintext, held by three parties, is not public.
"Somebody paid nearly a million dollars for a secret that is already out." The buyer paid for the method, the working documents, the coding charts, and K5, none of which the archive discovery touched. Whether that was a good purchase is a separate question, and not one the registry has any view on.
Current status
Partially explained. K1, K2 and K3 are solved. K4's plaintext exists, is known to a handful of people, and is not public. K4's cipher is unbroken and its method is a trade secret. K5 has never been seen.
The registry keeps this record for a distinction that this case makes unusually clean, and that most of the archive depends on: knowing the answer is not the same as knowing why it is the answer.
Somebody could have told you the plaintext of the Zodiac's Z340 at any point in the last fifty years, and it would have proved nothing. Oranchak, Blake and Van Eycke broke it, and that is a different thing entirely.
Sources
- Sanborn, J. and Scheidt, E. Design of the Kryptos encryption, 1988 to 1990.
- Gillogly, J. (1999). Public solution of K1, K2 and K3.
- Stein, D. (1998). CIA internal solution of K1 to K3.
- National Security Agency solution of K1 to K3 (1993), revealed by Freedom of Information Act request in 2013.
- Kobek, J. and Byrne, R. (September 2025). Recovery of the K4 plaintext from Sanborn's donated papers, Smithsonian Archives of American Art.
- The New York Times, 16 October 2025, on the researchers' decision not to release the plaintext.
- RR Auction, sale of the Sanborn Kryptos archive, closed 20 November 2025, hammer price $962,500.
- Dunin, E. Commentary in Scientific American on the distinction between possessing the plaintext and possessing the method.
Last reviewed: July 2026. Records are provisional. Where the evidence changes, the entry changes. Found an error? Tell us.