Cipher Wiki

Recognise the shape. Understand the mechanism. Know what an answer is worth.

Welcome to the Cipher Wiki§

A field guide to the fifty ciphers, codes and encodings this solver knows — one article each, with the facts generated from the solver's own registry and the worked examples produced by actually running the cipher. Read the article, then paste a real puzzle into the solver below it.

Did you know…§

…that al-Kindi, in ninth-century Baghdad, wrote the first known account of cryptanalysis — and made every monoalphabetic cipher obsolete in the same stroke?

Every cipher, one article each§

Grouped by family, straight from the solver's registry: the same descriptions, keyspaces and minimum text lengths the tool works from, so a page cannot quietly disagree with the code it documents. Articles marked full version describe ciphers the pip-installable solver breaks that the browser build does not.

Shift and reciprocal alphabets§

One fixed rule applied to every letter. The whole family falls to exhaustive search, which is why it survives as teaching material rather than as security.

  • Affine — Linear map x -> a*x + b mod 26. Caesar is the special case a=1.
  • Atbash — Hebrew substitution cipher mapping the alphabet onto its reverse.
  • Caesar (ROT-N) — Each letter is shifted by a fixed number of places. ROT13 is shift 13.
  • ROT13 — Caesar shift of 13. Applying it twice returns the original text.
  • ROT47 full version — Rotates printable ASCII (0x21-0x7e) by 47 places. Preserves case and digits.
  • Reverse — The message reversed. Often layered under or over other ciphers.

Monoalphabetic substitution§

A scrambled alphabet, fixed for the whole message. Letter frequencies survive the substitution, which is exactly what breaks it.

  • Keyword substitution full version — Mixed alphabet built from a keyword, then the remaining letters in order.
  • Simple substitution — Every plaintext letter maps to a fixed ciphertext letter. Solved by quadgram hill climbing with restarts.

Polyalphabetic ciphers§

Several alphabets in rotation, so one plaintext letter has several ciphertext forms. Broken in two stages: find the period, then solve each position as a simple shift.

  • Autokey — Key = short primer followed by the plaintext itself. Solved by chain decomposition.
  • Beaufort — C = K - P. Reciprocal: encryption and decryption are the same operation.
  • Gronsfeld — Vigenere restricted to a digit key, so each column has only 10 possible shifts.
  • Porta — Reciprocal polyalphabetic over 13 half-alphabet tables. Same period finding as Vigenere, 13 shifts per column.
  • Quagmire III (keyed alphabet) full version — Vigenere over a keyed alphabet (KRYPTOS by default). Period from IC, columns by chi-squared in keyed space.
  • Sum-clock (additive wheels) full version — Two or more short wheels summed mod 26 over a keyed alphabet. Solved by joint coordinate ascent over the wheels, not by columns.
  • Trithemius / progressive key — Shift increases by a constant step per letter: key[i] = (start + i*step) mod 26.
  • Variant Beaufort — C = P - K: Vigenere encryption with the decryption rule.
  • Vigenère — Repeating-key addition. Cracked by period finding (IC + Kasiski) then per-column Caesar solving.

Transposition ciphers§

The letters are the plaintext's own, only reordered. Frequencies are untouched, so the attack is anagramming rather than statistics.

  • AMSCO transposition full version — Alternating 1-2 letter chunks written into a grid, columns read in key order.
  • Columnar transposition full version — Plaintext written into a grid by rows, read out by columns in key order.
  • Myszkowski transposition full version — Columnar transposition where equal key letters are read together row by row.
  • Rail fence — Plaintext written along a zigzag of N rails, then read off rail by rail.
  • Route transposition full version — Plaintext filled into a grid, read out along a fixed route.
  • Skip / scytale full version — ct = pt[::k] + pt[1::k] + ... + pt[k-1::k]

Polygraphic ciphers§

Letters are enciphered in groups, so single-letter frequencies flatten and the unit of attack becomes the pair or the block.

  • Bifid full version — Each letter becomes (row, column); the coordinates are recombined within a period. Experimental solver.
  • Four-square full version — Digraph substitution across two keyed 5x5 grids. No padding and no reversible pairs, unlike Playfair.
  • Hill cipher (matrix) full version — Blocks of n letters multiplied by an n x n matrix mod 26. Broken by scoring each decryption-matrix row separately.
  • Playfair full version — Digraph substitution on a 5x5 keyed grid. Solved by annealing and genetic search on quadgram fitness.
  • Trifid full version — Three coordinates per letter in a 3x3x3 cube, recombined within a period. Experimental solver.

Wheel and rotor devices§

Physical devices: a stack of mixed alphabets on a spindle. The key is the order of the disks, and the keyspace is enormous.

  • M-94 wheel cipher full version — US Army M-94 (1922-1943): 25 mixed-alphabet wheels on a spindle, one letter per wheel. The key is the wheel order -- the alphabets themselves are the standard published set. Solved by hill climbing over wheel swaps with the read-out row recovered from the text; wants 200+ letters and a generous budget, and the honest-evidence rule caps solutions under 150 letters (25 wheels want ~6 letters each).

Byte-level ciphers§

Byte arithmetic rather than letter arithmetic. The natural home of CTF puzzles and the one family here that routinely carries non-text payloads.

  • Repeating-key XOR full version — XOR with a repeating byte key. Key length from normalised Hamming distance, then per-byte frequency analysis.
  • Single-byte XOR — Every byte XORed with the same key byte. Exhaustively solvable over 256 keys.

Codes and alphabets§

Fixed symbol tables rather than keys. There is nothing to search: recognise the table and the message reads out.

  • A1Z26 (numbered alphabet) full version — Each letter replaced by its position in the alphabet, separated by spaces or dashes.
  • Bacon (letter case) full version — Uppercase/lowercase of ordinary text encodes Bacon's five-bit letters.
  • Bacon cipher full version — Five symbols per letter over a two-letter alphabet. Both the 24-letter (I=J, U=V) and 26-letter tables are tried.
  • Baudot / ITA2 (5-bit) full version — Five bits per character, ITA2 letters table. Distinguished from Bacon by its own letter assignment.
  • Braille (Unicode patterns) full version — Unicode braille cells U+2800..U+28FF, grade 1 letter assignments.
  • Morse code — Dots and dashes per letter; spaces between letters, ' / ' between words.
  • NATO phonetic alphabet full version — One spelling-alphabet word per letter (Alfa Bravo Charlie ...).
  • Polybius square full version — 5x5 coordinate grid (I/J merged). Both digit pairs and tap-code style separators are accepted.
  • Tap code full version — Row and column of a 5x5 grid struck as groups of taps (C=K, I=J).

Encodings§

Not secrecy at all -- transport formats. They are in the solver because puzzles wrap ciphers in them, often several deep.

  • ASCII85 / base85 full version — 5 bytes per 5 characters over the printable ASCII range; ``<~ ~>`` delimiters optional.
  • Base32 full version — 5 bits per character over A-Z2-7, padded to a multiple of 8.
  • Base58 full version — Big-integer base58 over the Bitcoin alphabet, leading '1's encode leading zero bytes.
  • Base64 — 6 bits per character over A-Za-z0-9+/ (or -_ for URLs), padded to a multiple of 4.
  • Binary ASCII — Each byte as 8 bits, separated by spaces (or run together).
  • Decimal ASCII — Byte values in decimal, separated by spaces or commas (0x.. and octal are also accepted).
  • Hex / base16 — 4 bits per hex digit. Requires an even number of digits and at least one a-f.
  • Quoted-printable full version — MIME quoted-printable: =XX escapes and =\n soft line breaks.
  • URL encoding full version — Bytes as %XX hex escapes.
  • uuencode full version — Classic uuencode: a 'begin' header, length-prefixed lines of printable ASCII, then 'end'.

The history§

Three measurements worth knowing§

Alphabet and formatting§

Only dots and dashes suggests Morse; hexadecimal uses only 0–9 and A–F; base64 is usually a multiple of four characters and may end in =. For letter ciphers, note whether spacing survived. A transposition may lose word boundaries while a substitution normally keeps them.

Frequency§

English has uneven letter frequencies: E, T, A and O are common; Q and Z are not. A single-alphabet substitution preserves that unevenness under new names. A repeating-key cipher mixes several distributions together, making the text look flatter.

Index of coincidence§

The index of coincidence measures the chance that two drawn letters are the same. Ordinary English is near 0.067; uniformly random letters are near 0.038. It is a guide, not a verdict, but it is exceptionally useful for separating monoalphabetic and polyalphabetic puzzles.

What this wiki does not promise§

Recognising a classical cipher does not mean a unique solution exists. Short messages can fit several keys; proper names and another language confuse an English scorer; and a one-time pad used correctly has no statistical weakness. Treat an automatic answer as a hypothesis backed by evidence, then read it and verify the recovered key.

Frequently asked questions§

What is the difference between a code and a cipher?

A code substitutes whole words or ideas from a shared book or table. A cipher transforms letters or bytes according to a repeatable rule and a key. Classical puzzle writing often calls both ciphers, but the distinction matters when you decide how to attack a message.

Can this site break every cipher in the wiki?

The browser solver targets the shift family, the periodic family (Vigenère, Beaufort, Variant Beaufort, Porta, Gronsfeld, Trithemius and autokey), monoalphabetic substitution, rail fence and several encodings. The full version of the project searches 50 ciphers — the Hill matrix cipher and the M-94 wheel among them — with quadgram models in six languages. Modern encryption such as AES and RSA is not a classical cipher and is not breakable by these methods.

How much ciphertext is enough?

A short Caesar message may need only a few words because there are 26 keys. A substitution cipher needs roughly 100 letters to become comfortable. Playfair and other polygraphic systems need hundreds or more because the key has much more structure, and a wheel cipher such as the M-94 wants 200 letters or more before the disk order is pinned down.

Who writes this wiki?

The facts — family, key type, keyspace, minimum text, worked examples — are generated from the solver's own cipher registry every time the site is built, and the round trips are verified, so an article cannot quietly disagree with the tool it documents. The history and context are editorial. The full source is on GitHub.

Cipher articles on this wiki are generated from buttcrack's cipher registry when the site is built — their facts tables, worked examples and infoboxes describe the implementation, not an idealised cipher. The history features are editorial. The full source is on GitHub.

Try it live — break a real puzzle

Private by design

Drop in a puzzle. Leave with an answer.

Runs on this device
Try a sample
What this browser solver can—and cannot—do

It tries: Caesar, Atbash, ROT13, affine, Trithemius, rail fence, single-byte XOR, periodic Vigenère-family ciphers, autokey, selected encoding layers (such as Base64, hex, binary, decimal ASCII, Morse, and reverse), and—only with 60+ A–Z letters—statistical substitution.

It does not: prove a decryption, cover every classical cipher, or break modern encryption such as AES or RSA. Its ranking model is tuned for English, so a high score is a lead to verify with the method, key, and source context—not a guarantee.

Short text, non-English plaintext, non-Latin or symbol alphabets, missing keys, and unsupported formats can all leave no high-confidence answer. When that happens, the result includes input-specific observations and suggested next checks; those observations are not a claim to know the exact cause.

No account. No upload. No stored text. The complete solver runs in your browser.

This tool is free and has no account, no upload, no tracking of your text

Everything runs in your browser. If it saved you time, keeping it alive costs nothing but a click.