Substitution Ciphers

From the Buttcrack Cipher Wiki — the free field guide to classical ciphers

A scrambled alphabet, used consistently§

In a monoalphabetic substitution cipher, each plaintext letter maps to one different ciphertext letter for the entire message. A key might map A to Q, B to W and so on, but it need not follow any keyboard or keyword pattern. Unlike Caesar, there is no small numerical key to enumerate.

Why it still falls§

English is highly redundant. E remains the commonest plaintext letter even after it is renamed; THE retains the pattern of three distinct letters; and HELLO retains the pattern 0-1-2-2-3. Word boundaries make newspaper cryptograms easier, but continuous ciphertext still contains n-gram frequencies such as TH, HE and ING.

From hand solving to hill climbing§

A hand solver starts with frequency counts, one-letter words, doubled letters and likely short words. An automatic solver starts similarly, then scores the decrypted text with a language model. It swaps two assignments in a candidate alphabet, keeps swaps that improve quadgram fitness, and restarts from perturbed keys to escape local optima. The result is a search guided by English rather than a futile walk through every permutation.

Use enough text§

With fewer than about 60 letters, the statistical evidence is thin; with 150 or more, common patterns repeat and recovery becomes much steadier. Do not treat a beautifully English-shaped 30-letter output as proof. Verify that the recovered key consistently transforms the full message.

For a pair-based cipher whose statistics are less familiar, continue to Playfair.

Frequently asked questions§

How many keys does a substitution cipher have?

A full mixed alphabet has 26 factorial possible permutations, about 4 × 10 to the power of 26. Exhaustive search is impractical, which is why substitution is more interesting than Caesar despite using the same basic idea.

What patterns survive a substitution?

Every occurrence of a plaintext letter becomes the same ciphertext letter, so word lengths, repeated letters and repeated word patterns survive. THE and THAT have different letter-pattern signatures, and doubled letters strongly constrain guesses.

Why do solvers sometimes miss rare letters?

A ciphertext that never uses Q, J or Z contains almost no evidence about where that plaintext letter maps. Several keys can decrypt the observed text equally well; context, a crib or more ciphertext resolves the ambiguity.

The facts in this article are generated from buttcrack's cipher registry when the site is built, so they describe the implementation you can run on this page. Registry-generated content is checked against the code; the history is editorial.

Try it live — break a real puzzle

Private by design

Drop in a puzzle. Leave with an answer.

Runs on this device
Try a sample
What this browser solver can—and cannot—do

It tries: Caesar, Atbash, ROT13, affine, Trithemius, rail fence, single-byte XOR, periodic Vigenère-family ciphers, autokey, selected encoding layers (such as Base64, hex, binary, decimal ASCII, Morse, and reverse), and—only with 60+ A–Z letters—statistical substitution.

It does not: prove a decryption, cover every classical cipher, or break modern encryption such as AES or RSA. Its ranking model is tuned for English, so a high score is a lead to verify with the method, key, and source context—not a guarantee.

Short text, non-English plaintext, non-Latin or symbol alphabets, missing keys, and unsupported formats can all leave no high-confidence answer. When that happens, the result includes input-specific observations and suggested next checks; those observations are not a claim to know the exact cause.

No account. No upload. No stored text. The complete solver runs in your browser.

This tool is free and has no account, no upload, no tracking of your text

Everything runs in your browser. If it saved you time, keeping it alive costs nothing but a click.