Single-byte XOR

From the Buttcrack Cipher Wiki — the free field guide to classical ciphers

Single-byte XOR — Every byte is XORed with the same key byte.

Every byte XORed with the same key byte. Exhaustively solvable over 256 keys.

A worked example§

Encrypting a sample with the cipher itself, at build time:

MEET ME BY THE OLD CLOCK TOWER AT DAWN

Key: 66

produces the ciphertext

0f070716620f0762001b62160a07620d0e0662010e0d010962160d150710620316620603150c

This example is generated by running the cipher when the page is built, and the round trip is checked, so it always matches what the solver does.

How it is broken§

Two hundred and fifty-six keys, scored by byte frequency. The first exercise in every CTF crypto track.

History and context§

Not a classical cipher but the most common one in practice, because it is four lines of code and looks like encryption to anyone who does not look twice.

See also§

Repeating-key XOR

Browse every cipher in the Byte-level ciphers family, read the history of codebreaking, or return to the wiki main page.

Frequently asked questions§

How is the Single-byte XOR broken?

Two hundred and fifty-six keys, scored by byte frequency. The first exercise in every CTF crypto track.

What key does the Single-byte XOR use?

one byte. There are 256 possible keys.

How much ciphertext do I need?

At least 4 characters for this solver to attempt it; short messages can be readable and still not be proof.

Can I break a Single-byte XOR on this page?

Yes — the browser solver on this page handles it directly. Paste the ciphertext into the solver and press the button.

The facts in this article are generated from buttcrack's cipher registry when the site is built, so they describe the implementation you can run on this page. Registry-generated content is checked against the code; the history is editorial.

Try it live — break a real puzzle

Private by design

Drop in a puzzle. Leave with an answer.

Runs on this device
Try a sample
What this browser solver can—and cannot—do

It tries: Caesar, Atbash, ROT13, affine, Trithemius, rail fence, single-byte XOR, periodic Vigenère-family ciphers, autokey, selected encoding layers (such as Base64, hex, binary, decimal ASCII, Morse, and reverse), and—only with 60+ A–Z letters—statistical substitution.

It does not: prove a decryption, cover every classical cipher, or break modern encryption such as AES or RSA. Its ranking model is tuned for English, so a high score is a lead to verify with the method, key, and source context—not a guarantee.

Short text, non-English plaintext, non-Latin or symbol alphabets, missing keys, and unsupported formats can all leave no high-confidence answer. When that happens, the result includes input-specific observations and suggested next checks; those observations are not a claim to know the exact cause.

No account. No upload. No stored text. The complete solver runs in your browser.

This tool is free and has no account, no upload, no tracking of your text

Everything runs in your browser. If it saved you time, keeping it alive costs nothing but a click.