CryptographyAI EngineeringHistory

ENIGMA Cracked: An 85-Year-Old Nazi Code Just Got Broken

How modern computation and a clever guess finally decrypted a German Army message from 1941.

HS
Harsha Sridhar
9 min read · September 28, 2026
ENIGMA Cracked: An 85-Year-Old Nazi Code Just Got Broken — cover

On July 10, 1941, a German soldier sat in the town of Rosenow and radioed a question to his commanding unit. He needed to know the route of march. He typed his message into an Enigma machine, cranked through the encryption, and transmitted the ciphertext over the airwaves.

That message sat unbroken for 85 years.

Until last month, when a small team of researchers finally cracked it. Not with a room full of codebreakers. Not with a stolen codebook. With raw computation, a good guess, and a lot of patience.

The decrypted plaintext? "Please specify the route of march. I am in Rosenow, Rosenow. Immediate reply by radio."

A mundane military logistics request. But the story of how it got unlocked is anything but mundane.

Why this message survived so long

During World War II, Britain's codebreakers at Bletchley Park broke thousands of Enigma messages. They had help: captured codebooks, repeated message formats, lazy operators who reused settings. The system they built around Alan Turing's Bombe machines was extraordinary, but it relied on those operational shortcuts.

This particular message had none of them.

It was encrypted with the standard Army Enigma I machine using Reflector B, but the specific key for that day was never recovered. No codebook. No known-plaintext shortcut from Bletchley's wartime archives. The intercept sat in the records as ciphertext, untouched, for decades.

After the war, most of the interest in Enigma shifted to historical scholarship. The machine's cryptographic strength wasn't enough to resist a modern attack in theory, but nobody had both the computational resources and the motivation to go after a single orphaned message.

That changed in 2026.

The attack: 4.29 billion guesses

The team's approach was conceptually simple. Brutally expensive, but simple.

They started with a guess. Cryptanalysts call it a "crib," which is a chunk of plaintext you suspect appears somewhere in the message. The researchers guessed that the word "ROSENOW" appeared in the text, because the message was intercepted near that town. Specifically, they guessed the doubled form "ROSENOWROSENOW," which is a common pattern in German military radio messages when emphasizing a location name.

That crib became the anchor for the entire attack.

Here is the logic. The Enigma machine has a known structure: three rotors chosen from a set of five, a reflector, ring settings for each rotor, and a plugboard that swaps pairs of letters. If you know (or guess) a fragment of the plaintext and where it sits in the message, you can test whether a given machine configuration would produce the observed ciphertext at those positions.

The crib was 14 characters long. The full message was 82 characters. That means the crib could sit at 68 different positions within the message. For each position, they had to test every possible rotor configuration.

How many configurations? The rotor order alone gives 60 possibilities (five rotors, pick three, order matters). Each rotor has 26 ring settings and 26 starting positions. The plugboard, with its 10 swapped pairs, adds another enormous factor. When you multiply it all out, the team faced 4.29 billion distinct rotor-and-placement combinations to evaluate.

They split the work into 43,016 batches and ran them in parallel.

Crib Placement 68 positions Rotor Search 4.29B combos Plugboard Filter 97,337 keys Header Match 923 keys Language Check Final decrypt ✓ Verified independently against 14.8M physical keys
The five-stage attack pipeline that cracked the MVUEH message.

Filtering the noise

Running 4.29 billion combinations doesn't mean you get 4.29 billion answers. Most configurations fail immediately. The crib doesn't line up. The rotor settings produce gibberish at the known positions. Those get thrown out.

What survived the initial pass: 97,337 candidate keys. Still too many to check by hand, but a massive reduction from billions.

The next filter was the message header. Enigma messages started with a short indicator sequence that told the receiving operator which settings to use. The intercepted message had a recorded header. Of those 97,337 candidates, only 923 produced an output consistent with that header.

Now you're in the range where you can actually look at the results. The researchers checked each of those 923 decryptions for whether the output looked like plausible German. Not just random letters, but actual words. Sentence structure. Military vocabulary.

One key produced coherent German text. One.

The verification nobody expected

Here is the part that makes this more than just a neat computation exercise.

The team didn't stop at finding one answer that looked right. They ran an independent verification pass. Instead of starting from the crib and working forward, they tested 14.8 million physical key configurations against the full message, checking whether any other key could produce the same plaintext.

None did. The solution was unique.

That kind of verification matters because crib-based attacks have a known weakness: if your guessed plaintext is wrong, you can still sometimes find keys that produce plausible-looking output by coincidence. The independent pass ruled that out. The message really does say what they think it says.

What the message actually said

After all that computation, the decrypted text is almost anticlimactic:

Please specify the route of march. I am in Rosenow, Rosenow. Immediate reply by radio.

A German soldier, stuck in a small town in what is now Poland, asking for directions. No strategic secrets. No battle plans. Just a guy who needed to know where to go next.

There is something poignant about that. Eighty-five years of cryptographic silence, billions of computations, and the answer is a lost soldier asking for help.

The human-AI angle

The research was completed across September 14 and 15, 2026, and the team was explicit about one thing: this was not a human team using AI as a calculator. It was a structured collaboration between human researchers and multiple specialist AI agents, each with a defined role, running in parallel under human direction.

The humans brought the domain expertise. They knew which cribs to try, how Enigma's plugboard constraints could prune the search space, and what "plausible German military text" actually looks like. But the interesting part is what happened on the AI side.

Five agents, five jobs

The team didn't throw one general-purpose model at the problem. They ran five categories of specialist agents simultaneously, each responsible for a different phase of the work:

Evidence agents went first. Their job was to examine the source material and record every possible reading of the intercepted message before anyone knew the answer. Think of them as the archivists: capturing raw observations without the bias of hindsight.

Search agents built and ran the actual computational experiments. They wrote the programs that tested 4.29 billion rotor configurations across 43,016 batches, with checkpoints that let work resume if anything crashed. These were the workhorses.

Context agents compared the findings against historical references. They checked whether the language patterns, military vocabulary, and message structure were consistent with other solved Enigma messages from the same era. If the search agents found a candidate decryption, the context agents asked: "Does this sound like something a German soldier would actually transmit in 1941?"

Review agents operated independently from the others. Their entire purpose was to reproduce results from scratch and verify that every part of the declared search space had actually been covered. No gaps. No missed batches. No silent failures in the parallelization.

A coordinating agent sat on top, reducing duplicated work across the other four groups and turning disagreements into further verification checks rather than consensus votes.

SPECIALIST AGENTS (parallel) Evidence Record observations Search Run experiments Context Historical matching Review Reproduce results COORDINATION Coordinating Merge + de-duplicate Human Domain expertise Final decisions
The multi-agent architecture: four specialist agent types work in parallel, feeding findings to a coordinating agent that de-duplicates and escalates to human researchers.

Disagreement as a feature, not a bug

Here is the part that makes this architecture worth studying beyond the Enigma result.

When two agents disagreed on a finding, the system didn't resolve it by majority vote. It didn't average the outputs or defer to whichever agent had higher confidence scores. Instead, a disagreement automatically triggered additional verification. The coordinating agent would route the contested result back to the review agents for independent reproduction.

The team accepted results on the basis of reproducible evidence, not agent agreement. That is a meaningful design choice. Most multi-agent setups in 2026 still lean on consensus or confidence thresholds, which means a confidently wrong majority can overrule a correct minority. This team avoided that entirely.

The result was a system where throwing more agents at the problem didn't just add speed. It added rigor. Every parallel workstream was also a parallel check on the others.

Why it matters beyond history

You might read this and think: cool story, but who cares about a message from 1941?

Fair question. Here is why it matters.

First, it is a real-world proof that modern computation can break ciphers that were considered practically secure for decades. The Enigma machine was never mathematically unbreakable. Everyone knew that. But "theoretically breakable" and "actually broken on a single orphaned message with no cribs, no codebook, and no operational shortcuts" are very different things. This team closed that gap.

Second, the methodology is interesting. Crib-based attacks are old. Parallel computation is old. But combining them with AI-driven language verification to filter candidates is new. The pipeline they built isn't just useful for Enigma. It is a template for attacking any historical cipher where you have partial plaintext guesses and a known machine structure.

Third, and this is the part that sticks with me: there are other unbroken messages out there. Intercepts from WWII that never got decoded because Bletchley Park didn't have the right cribs or the right day's settings. Some of those messages might contain genuinely important historical information. Letters home. Intelligence reports. Orders that shaped battles.

This team just showed that "unbroken" doesn't have to mean "unbreakable." It just means nobody has thrown enough compute at it yet.

* * *

The next time someone tells you that AI is only good for generating marketing copy and chatbot responses, point them at this. A team of humans and AI agents just read mail that was sealed shut in 1941.

Some envelopes just take 85 years to open.

References

Enjoyed this?

I write about distributed systems, agentic AI, and the strange places engineering and the cosmos overlap.