The shape of a crypto challenge
Introductory CTF crypto is mostly recognition. The underlying operations are simple — base64, hex, XOR, a classical cipher — and the difficulty comes from not knowing which ones were applied, in what order, and how many times. Experienced players recognise the shapes instantly. This tool does the recognising for you and then does the work as well.
Identifying encodings by shape
Base64
Alphanumerics plus + and /, length a multiple of four, often
ending in one or two = padding characters. Mixed case with occasional digits is
the tell.
Hex
Only 0-9 and a-f, always an even number of characters. If you
see a long string that happens to contain no letters past f, it is hex and not a
cipher.
Binary and decimal
Runs of 0 and 1 in groups of eight, or space-separated numbers
in the 32 to 126 range — the printable ASCII window. Both are common obfuscation for text
that is otherwise in the clear.
XOR
XOR is its own inverse, which is what makes it convenient and what makes it breakable. With a single-byte key there are 255 candidates; the solver tries every one, discards those producing non-printable bytes, and scores the rest against English. With a repeating multi-byte key the structure is identical to Vigenère: find the key length by looking at the index of coincidence of each byte position, then solve each position independently.
Working the layers
The solver treats decoding as a search tree rather than a fixed pipeline. At each node it tries every direct cipher, and separately tests whether the text is a valid encoding it can unwrap. Unwrapping produces a child node and the process repeats. The answer returned is the leaf with the highest confidence, reported with the complete chain that produced it — so you learn the structure of the challenge, not just the flag.
Frequently asked questions
What is single-byte XOR and why is it everywhere in CTFs?
Every byte of the plaintext is XORed with the same one-byte key. There are only 255 keys to try, so it is trivially breakable, which makes it the standard warm-up challenge in introductory CTF crypto categories.
How deep can the layers go?
The browser version peels up to three encoding layers. The full version goes six layers deep, searches 50 ciphers and scores in six languages, which is what you want for harder challenges.
Can it handle flag formats?
Yes, incidentally — flags like ctf{...} are usually surrounded by enough English or structured text for the scoring to lock on. Very short flag-only inputs are harder because there is little statistical signal.
Why does it sometimes pick the wrong layer to unwrap?
Hex and base64 character sets overlap, so a string can be validly interpretable as either. The solver tries both branches and keeps whichever produces the more English-like result rather than committing to the first guess.