The device§
Twenty-five brass disks, each about an inch and a half across, threaded onto a spindle in a frame. Every disk carries the alphabet in a different scrambled order around its rim, and the set of alphabets is fixed and public — what the enemy never knew was the order the disks were threaded in, which is one of 25 factorial arrangements: roughly a septillion, or about 83 bits. To encrypt, the sender turned the disks to spell the first 25 letters of the message along one row, then read the ciphertext off any other row. Twenty-five letters at a time, the whole message went round and round the spindle.
Why it is stronger than it looks§
A Vigenère key of length 25 gives each position of the period a shift — a Caesar cipher with 26 possibilities, crackable by frequency analysis on a few dozen letters of that column. The M-94 gives each position an entire mixed alphabet with no relationship to its neighbours. Nothing about column 1 tells you column 2, and the flat letter statistics that expose a monoalphabetic substitution never appear. When it was adopted in 1922 it was genuinely strong for field traffic, and the Army used it for low-level messages into the 1940s.
Recognising wheel-cipher ciphertext§
Letters only, no key rhythm, and statistics that look polyalphabetic: the index of coincidence sits near random because the same plaintext letter encrypts differently each time it appears. The tell is the period. Every 25th letter went through the same disk, so if you split the text into 25 columns, each column is a pure monoalphabetic substitution and its letter frequencies look natural — split it into any other number and they stay flat. A column-wise index-of-coincidence spike at exactly 25, on a message whose length is a multiple of 25 or close to one, is the fingerprint. (A Vigenère with a 25-letter key looks similar at this distance; the two are told apart by trying the cheap Vigenère attack first.)
How the orders fall§
83 bits is far beyond brute force, but the search does not have to be blind. Swapping two disks on the spindle changes only the letters at two of the 25 positions, so a hill climb can start from a random order, swap pairs, and keep every swap that makes some reading of the message look more like language — measured with letter n-gram statistics, exactly as a substitution solver scores candidate alphabets. The row the sender read from is part of the key but costs nothing extra: with the disks in the true order, one of the 26 rows reads as plaintext and the other 25 read as noise, so the search simply scores the best row of each candidate order. A few thousand swaps, restarted from several random orders, converge on the true arrangement from about 200 letters. That is not a weakness of the implementation; it is what actually happened to wheel-cipher traffic, and why the device was retired.
Honest limits§
Below about 150 letters the recovered order cannot be distinguished from a near-miss — 25 wheels each want a handful of letters of evidence before the answer is proven rather than plausible, and a good solver says so instead of guessing. Short messages that also stack an encoding layer around the wheel are the hard case. If you are working one by hand, look for the period-25 column structure first, then try the full version of the buttcrack solver with a generous budget, or hand it a suspected order as a key hint.
Return to the cipher wiki field guide for the other common classical families.
Frequently asked questions§
What was the M-94?
A cylindrical cipher device used by the US Army from 1922 until 1943, and by the Navy as the CSP-488. Major Joseph Mauborgne designed it in 1917 from Colonel Parker Hitt's ideas, and the same wheel principle had been reinvented several times before, most famously by Thomas Jefferson around 1795.
How does it differ from Vigenère?
Vigenère shifts each position by a key letter, so every column of the period is a Caesar cipher. On the M-94, every position of the period runs through its own completely scrambled alphabet, one per disk. The period is exactly 25 because there are 25 disks, and frequency analysis per column no longer works — each column needs its full mixed alphabet recovered.
Can this page break an M-94 message?
No. The browser solver on this page handles the common puzzle families; a wheel cipher needs a hill-climbing search over disk orders with quadgram scoring, which is in the full version of the project. It recovers a genuinely secret 25-disk order from about 200 letters of ciphertext, and a suspected order can be tested instantly with a key hint.
Why is disk 17 famous?
One of the standard disks spells ARMYOFTHEUS — 'ARMY OF THE US' — around its rim, starting at A, which is how the device's origin is identified at a glance. The full 25-disk set was public: it was engraved on every device manufactured, and only the spindle order was secret.
How much ciphertext does a break need?
About 200 letters for a reliable recovery with a real search budget, and 150 is the floor below which even the true order cannot be proven — 25 wheels each want roughly six letters of evidence. Longer messages are dramatically easier; 300 or more usually falls within seconds.