Frode Weierud’s Crypto Cellar Research keeps a list of German Army Enigma messages from July 1941, and the page is more honest than most puzzle collections. Batch A holds 48 ciphertext messages, and the note above them says they have never been broken. Most are hand cipher, probably a variation of Doppelkastenschlüssel, and most of the Enigma messages in the batch are very short, which is why Weierud’s project decided to spend its effort on the April 1945 Flossenbürg messages instead. Message Nr. 172, prefixed MVUEH, was sent by a radio station with the tactical callsign 2ny and received at 17:30 on 10 July 1941 by the Ib station of the SS-Totenkopf division’s quartermaster, which logged it as the 172nd incoming message of the month. It is 82 letters long, it is a logistics message asking for a route, and it resisted everyone for twenty-one years.
On 15 September 2026, Carter Leffer contacted Weierud to ask him to validate a break. Weierud’s own account of what happened next is the part worth reading. GPT-6 Astra had been directed only to see whether it could break any of the unbroken messages published on the site. It read the list, decided Nr. 172 was the most promising target, and immediately suspected something else: that the plaintext of Nr. 173, a message Alex Shovkoplyas had broken in June 2017, might overlap with the plaintext of the one still open. After trying many approaches, it settled on the repeated place name ROSENOW ROSENOW as a crib. To use that crib it wrote Python and C++ for an Enigma simulator and an Enigma Bombe, ran the search, and came back with the key.
The breakthrough makes sense in hindsight and would not have made sense at all in advance. The key for MVUEH uses a wheel order of 253, while both other messages from that day use 512, and the plugboard and ring settings are off the daily key as well. The transcription in the surviving message form contains several errors. And the machine’s left-hand wheel makes a turnover at the 72nd letter, an event rare enough to break the standard crib attacks. The recovered plaintext runs 82 letters against Nr. 173’s 94, and the two are almost the same message; the gap is one enciphering mistake and a repeated sender signature.
The detail that has stayed with me is further down the page. Weierud quotes from Astra’s own logs, where the model had been doing archive work: it traced the received corpus to a private collection, named the Bundesarchiv volumes RS 3-3/20a and RS 3-3/63b, noted that the original image of Nr. 172 remained unlocated, and recorded that no correspondence had been sent. Weierud had spent several weeks reading those same Bundesarchiv files. His summary of the two-day run is that what it achieved would take a human researcher weeks or even months, and he calls himself, as an old cryptanalyst, still in awe.
Hacker News gave the writeup 590 points and 371 comments, and the argument that followed is more interesting than the break. The top comment asked how many more of these articles we were going to get, on the grounds that the work required no skill, no imagination, and appeared to have happened by dumb luck. The most quoted reply was shorter: the reason these are unsolved is that no one was working on them. One commenter compared it to a computer reporting the ten-quintillionth digit of pi. Someone else corrected the thread’s vocabulary, pointing out that Enigma was already known to be weak and that nothing here bears on the cryptography anyone actually uses. A commenter who tried to reproduce the result posted a transcript of a rival model solving the same message in about 45 minutes, then elsewhere in the same thread admitted that an earlier round of testing had fed the models text that was not the ciphertext at all. And the break report itself was published on a chatgpt.site page, which one reader described as slopped up.
🎩 Cask’s Take
The word doing the work in this story is unsolved, and Weierud’s own page shows what it meant here. His team looked at Batch A, judged it mostly hand cipher with very short Enigma messages, and went to spend its time on a different collection. The label that came out of that decision was accurate and had nothing to do with difficulty. Twenty-one years is a long time to leave something on a shelf, but sitting on a shelf is not the same as resisting, and it is worth separating the two.
What changed is not cryptanalysis. Enigma fell to Polish mathematicians in 1932 and to Turing’s Bombe in 1940; the mathematics of this message was solved decades before the message was. What changed is that the cost of trying dropped far enough for one person with one model to point it at a shelf and leave. That is the whole finding, and it is less flattering than the headlines, because it says the constraint was never capability. It was whether anyone would spend a career on a single short logistics message from a division’s quartermaster traffic.
The part I would keep from the run is not the key. It is the sequence: choose the target from a list on the basis of promise, guess that a neighbouring message might share content, derive the crib from the neighbour, build the instrument, run it. Weierud, who had been staring at this ciphertext for years, thought the suspicion about Nr. 173 was the clever part. And the archive logs at the bottom of the page are the check: named volumes, a source image that could not be located, no correspondence sent, no claim of access it did not have. The break is only worth repeating because the person who maintains the list checked it, which is the strongest form of verification available in this genre.
So the top comment is half right, and the useful half is the half it did not intend. When attempts are nearly free, the bottleneck moves off capability and onto attention. The problems that stay unsolved will increasingly be the ones nobody thought it worth pointing a machine at, and that is a budgeting question wearing the costume of a benchmark result. It is also, for anyone old enough to have a shelf of their own, a slightly uncomfortable one.
The list said unsolved for twenty-one years. What it meant was unattended, and the gap only opened once trying got cheap enough that somebody would attempt it without being paid to.