The Vigenère Cipher

From the Buttcrack Cipher Wiki — the free field guide to classical ciphers

A Caesar shift that changes every letter§

Vigenère assigns each keyword letter a shift. With the key LEMON, the shifts 11, 4, 12, 14 and 13 repeat across the message. The same plaintext letter may therefore encrypt to different ciphertext letters. This defeats the simple “most common letter is E” reasoning that breaks Caesar immediately.

Find the period before the key§

If the key has five letters, take every fifth ciphertext character. Each resulting column was encrypted by one fixed Caesar shift. The attack is therefore: propose a key length, split into columns, and measure whether each column behaves like English. The average index of coincidence rises when the proposed period is a multiple of the real period.

Recover and refine§

Once the period is known, compare each column's letter frequencies with expected English frequencies to choose a shift. That produces a first key. On short texts, refine it by changing one key letter at a time and rescoring the whole plaintext: language model context resolves columns too sparse for frequency analysis alone.

Limits of the method§

Short messages and long keys leave too few letters in each column. A period that is a multiple of the true key can also look convincing; prefer the shortest key that explains the text. Variants such as Beaufort use a different algebraic direction but retain the same repeating-period weakness.

For a cipher that uses one fixed alphabet instead, see the substitution cipher guide.

Frequently asked questions§

Why was Vigenère called unbreakable?

It hides ordinary letter frequencies better than a single substitution. Before the period was understood, analysts could not tell which of several shifts had enciphered each E. The repeated keyword is the weakness that eventually made systematic attacks possible.

What is Kasiski examination?

Repeated ciphertext fragments can result from repeated plaintext fragments aligned under the same part of the keyword. Distances between them often share factors with the key length. It suggests periods to test; it does not recover the key on its own.

What makes a Vigenère cipher genuinely secure?

If the key is truly random, as long as the message, used once and kept secret, the construction is a one-time pad. A repeating dictionary word is the critical flaw in ordinary Vigenère.

The facts in this article are generated from buttcrack's cipher registry when the site is built, so they describe the implementation you can run on this page. Registry-generated content is checked against the code; the history is editorial.

Try it live — break a real puzzle

Private by design

Drop in a puzzle. Leave with an answer.

Runs on this device
Try a sample
What this browser solver can—and cannot—do

It tries: Caesar, Atbash, ROT13, affine, Trithemius, rail fence, single-byte XOR, periodic Vigenère-family ciphers, autokey, selected encoding layers (such as Base64, hex, binary, decimal ASCII, Morse, and reverse), and—only with 60+ A–Z letters—statistical substitution.

It does not: prove a decryption, cover every classical cipher, or break modern encryption such as AES or RSA. Its ranking model is tuned for English, so a high score is a lead to verify with the method, key, and source context—not a guarantee.

Short text, non-English plaintext, non-Latin or symbol alphabets, missing keys, and unsupported formats can all leave no high-confidence answer. When that happens, the result includes input-specific observations and suggested next checks; those observations are not a claim to know the exact cause.

No account. No upload. No stored text. The complete solver runs in your browser.

This tool is free and has no account, no upload, no tracking of your text

Everything runs in your browser. If it saved you time, keeping it alive costs nothing but a click.