Skip to content

openai

GPT-6 Astra broke an Enigma message stuck since 2005

Promtime

The German Army message that had defeated every attempt since 2005 turned out to say almost exactly what a message broken back in 2017 already said, and the two texts differ by twelve letters. Frode Weierud validated the break on 15 September 2026 and published the details at Crypto Cellar Research; the work is credited to OpenAI GPT-6 Astra, run by Carter Leffer.

At a glance

  • Leffer's only instruction was to try any of the unbroken Enigma messages on the Crypto Cellar Research page, and Astra chose Nr. 172, MVUEH, logged at 17:30 on 10 July 1941.
  • The recovered key uses wheel order 253, against 512 for the two other keys known from that day, and Astra wrote its own Enigma simulator and Bombe in Python and C++ to find it.
  • Astra's logs cite Bundesarchiv volumes RS 3–3/20a and RS 3–3/63b plus a private collection that Weierud cannot place, and he is still reading those logs to reconstruct how the break ran.

If you have not followed this corner of research: the raw material is a published list of intercepted wartime messages that nobody has ever read. Crypto Cellar Research's own Enigma history notes that from 15 December 1938 three wheels were chosen from a set of five, giving 60 possible arrangements, one for every day of the month. Nr. 172 sat unbroken since 2005; its neighbour Nr. 173, SIPVX, fell to Alex Shovkoplyas on 9 June 2017.

MVUEH is 82 letters, SIPVX is 94, and the plaintexts are nearly the same

MVUEH was sent by a station with the tactical callsign 2ny and received by the radio station of the SS-Totenkopf Quartiermeister, Ib, at 17:30 on 10 July 1941. Ib entered it as Nr. 172 in its log of incoming messages for July 1941.

The key Shovkoplyas recovered for SIPVX in 2017 was already a curiosity: same wheel order 512 as the daily key for 10 July, but different plug connections and a different ring setting. It did not open MVUEH. The key Astra found is different again, down to the wheel order, 253.

The difference between the two plaintexts comes down to two slips. The word Bitte was enciphered in MVUEH as Btte, and the sender's signature, Waschbusch, appears twice in SIPVX.

What stopped the break: transcription errors and a turnover at the 72nd letter

Two things made MVUEH awkward. The transcription of the ciphertext from the original message form contained several errors, so part of what everyone had been attacking was wrong. And the break revealed that the Enigma's left-hand wheel makes a turnover at the 72nd letter, in an 82-letter message.

Think of the three wheels as an odometer: the right one steps with every letter, the left one almost never moves inside a single message. When it does move, the machine's wiring path changes partway through the text, so an attack that assumes one configuration across the whole message stops matching after that point. Such a turnover is rare and is known to complicate a break; Weierud writes that these factors may have prevented an earlier solution.

Astra picked the target, chose the crib and built the Bombe itself

Leffer pointed the model at the list and nothing more. Astra read the unbroken messages, decided Nr. 172 was the most promising, and quickly suspected that the plaintext of Nr. 173 might be related to it.

It tried many approaches before settling on the repeated place name ROSENOW ROSENOW as a crib, meaning a stretch of guessed plaintext you can test against the ciphertext. Then it wrote the tooling, an Enigma simulator and an Enigma Bombe, in Python and C++. According to IronMonkey, the switch to C++ for the core Bombe search reflected the performance demands of the brute-force stage, with Python used for rapid prototyping.

IronMonkey also describes the stated objective of the exercise: to evaluate whether a high-order AI agent could perform end-to-end historical cryptanalysis on real cold-case ciphers without human intervention or pre-defined attack vectors. Weierud puts the human equivalent of Astra's two days at weeks or months.

The logs name Bundesarchiv volumes RS 3–3/20a and RS 3–3/63b

In July 2026 Weierud posted a note on the 1941 Message List: research in the German Bundesarchiv had turned up collections of radio messages, one of them from the SS-Totenkopf Division's logistics command, the Nachschubführer. Those messages were added to the list in bold, with an NF indicator after the message number.

Weierud thinks Astra found that note, because one log entry reads:

Original-source access lead. The completed evidence pass traced the received corpus to a private collection and found concrete Bundesarchiv radio-message volumes, including RS 3–3/20a and RS 3–3/63b. Catalogue records have been inspected; the original received no.172 image remains unlocated, and the available archive viewer has not yet exposed the relevant scans in this environment. No correspondence has been sent.

The two file references are correct, Weierud writes, but they are not on the Crypto Cellar Research website. He spent several weeks himself researching the files Astra names.

The cryptanalysis is the checkable half: a key and a plaintext either decipher a ciphertext or they do not, and Weierud says it was immediately clear Leffer had the right ones. The archive trail is the other half, and it is not clear what the private collection is, whether Astra reached the Bundesarchiv's digitised holdings or found the files somewhere else. In our view that gap, rather than the break, is the part worth reproducing.

Still inside the Astra logs

Weierud says the log analysis is ongoing and is still turning up details; he has not said when or whether the full reconstruction will be published. The original image of received message Nr. 172 remains unlocated, which leaves the transcription errors uncorrected against the source document. The 1941 Message List still carries other unbroken messages, and nothing in the write-up says whether Astra will be pointed at them.

Related stories

  1. GPT-6 Astra ships and Brockman declares the AGI era
  2. OpenAI's newest model found a way out of its RL sandbox
  3. Mathematicians get a say in how OpenAI reports its math
  4. Two zero-days behind the OpenAI Hugging Face hack, rebuilt
  5. Every chatgpt.com page carries 377 KB of flag decisions
  6. 8Braid pins an exact margin inside OpenAI's fluid proof

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.