Hill cipher (matrix)

From the Buttcrack Cipher Wiki — the free field guide to classical ciphers

Hill cipher (matrix) — Blocks of n letters are treated as a vector and multiplied by an n-by-n matrix modulo 26. The matrix must be invertible mod 26, which means its determinant must be odd and not a multiple of 13.

Blocks of n letters multiplied by an n x n matrix mod 26. Broken by scoring each decryption-matrix row separately.

A worked example§

Encrypting a sample with the cipher itself, at build time:

MEET ME BY THE OLD CLOCK TOWER AT DAWN

Key: HILL

produces the ciphertext

MUYTMURPHAKQXYYNKUOHOGIXWBVHYV

This example is generated by running the cipher when the page is built, and the round trip is checked, so it always matches what the solver does.

How it is broken§

Linearity is fatal. Decryption is row-separable — each plaintext position depends on one row of the inverse matrix — so rows are scored independently. That turns 157,248 invertible 2x2 keys into 676 row evaluations, and makes 3x3 tractable at all.

History and context§

Lester Hill, 1929, in the American Mathematical Monthly: the first cipher built on linear algebra, and a teaching example ever since of why linearity and secrecy sit badly together.

See also§

Playfair · Bifid · Four-square · Trifid

Browse every cipher in the Polygraphic ciphers family, read the history of codebreaking, or return to the wiki main page.

Frequently asked questions§

How is the Hill cipher (matrix) broken?

Linearity is fatal. Decryption is row-separable — each plaintext position depends on one row of the inverse matrix — so rows are scored independently. That turns 157,248 invertible 2x2 keys into 676 row evaluations, and makes 3x3 tractable at all.

What key does the Hill cipher (matrix) use?

matrix or keyword (n*n letters). The keyspace is unbounded in practice.

How much ciphertext do I need?

At least 40 characters for this solver to attempt it; short messages can be readable and still not be proof.

Can I break a Hill cipher (matrix) on this page?

Not with the browser build, which targets the common puzzle families. The desktop version searches it: see the Windows app page.

The facts in this article are generated from buttcrack's cipher registry when the site is built, so they describe the implementation you can run on this page. Registry-generated content is checked against the code; the history is editorial.

Try it live — break a real puzzle

Private by design

Drop in a puzzle. Leave with an answer.

Runs on this device
Try a sample
What this browser solver can—and cannot—do

It tries: Caesar, Atbash, ROT13, affine, Trithemius, rail fence, single-byte XOR, periodic Vigenère-family ciphers, autokey, selected encoding layers (such as Base64, hex, binary, decimal ASCII, Morse, and reverse), and—only with 60+ A–Z letters—statistical substitution.

It does not: prove a decryption, cover every classical cipher, or break modern encryption such as AES or RSA. Its ranking model is tuned for English, so a high score is a lead to verify with the method, key, and source context—not a guarantee.

Short text, non-English plaintext, non-Latin or symbol alphabets, missing keys, and unsupported formats can all leave no high-confidence answer. When that happens, the result includes input-specific observations and suggested next checks; those observations are not a claim to know the exact cause.

No account. No upload. No stored text. The complete solver runs in your browser.

This tool is free and has no account, no upload, no tracking of your text

Everything runs in your browser. If it saved you time, keeping it alive costs nothing but a click.