Skip to content
SecAIQ

AI Model Cracks a Long-Unsolved Enigma Message on Its Own

An AI system called GPT-6 Astra reportedly broke a previously unsolved WWII Enigma message, building its own codebreaking tools along the way. Here is what happened and why it matters for cryptography and AI safety.

Written by Safa PAKSU· Published Sep 26, 2026 ·4 min read

An old puzzle, a new kind of solver

A message encrypted with the Enigma machine, the cipher device used by German forces in the Second World War, has reportedly been decrypted by an AI system after resisting human efforts for decades. Security researcher Bruce Schneier highlighted the result on his blog on 22 September 2026, describing it as "pretty amazing". The system involved is called GPT-6 Astra.

What makes the story notable is not only that the message was solved, but how. According to the account Schneier quoted, the AI carried out the whole break by itself.

What happened

Carter Leffer, the person running the experiment, gave the AI a simple task: see whether it could break any of the still-unbroken Enigma messages published on the Crypto Cellar Research website. That site collects historical Enigma intercepts that have never been deciphered. Nothing more specific was requested.

From there, the reported sequence of steps was:

  • The AI reviewed the unsolved messages on the site and judged message number 172, labelled MVUEH, to be the most promising candidate.
  • It suspected that the hidden text of message 173, labelled SIPVX, might be related to that of message 172.
  • After trying a range of approaches, it settled on a crib: the repeated place name "ROSENOW ROSENOW".
  • It wrote its own Python and C++ software, including an Enigma simulator and an Enigma "Bombe" (a software version of the electromechanical search machines used in the war).
  • It then ran a thorough search built around that crib, which ultimately led to the break.

Why a crib matters

A crib is a piece of text that a codebreaker guesses, or knows, appears somewhere in the original message. Enigma had a large number of possible settings, so testing them blindly was impractical. A good crib narrows the search dramatically, because only settings that turn the guessed text into the encrypted letters can be correct. Wartime codebreakers relied on predictable phrases such as routine headings and reports. Here, a place name that appeared twice in a row gave the AI the foothold it needed.

What the result does and does not tell us

It is worth keeping perspective. Enigma is a historical cipher, and modern encryption↗ is built on very different mathematics. Nothing in this report suggests that today's encryption standards have been weakened, and there is no need for ordinary users to change how they protect their data because of it.

The result is still meaningful for several reasons:

  • Autonomy. The AI chose its target, formed a hypothesis, built specialised tools and iterated until it worked. That is a multi-step research workflow, not a single answer to a question.
  • Tool building. Writing working simulator and search code from scratch is the kind of practical engineering that codebreaking requires.
  • Not an isolated case. A commenter on Schneier's post, Frode Weierud, noted that a different AI model, described as Anthropic's Claude Opus 5, separately broke another unsolved message (number 205/285, labelled FMNGI) on 20 September 2026, using a different crib. We have relied on that comment as reported and have not independently verified it.

Why it matters for security and AI safety

Cryptanalysis and vulnerability↗ research share a pattern: forming a hunch, testing it with custom software, and refining until something gives. Systems that can do this with little supervision are useful for defenders, for example in reviewing old or weak cryptographic designs. The same skills could also help attackers, which is why researchers continue to track what advanced AI models can do on their own.

The practical lessons for organisations and individuals are modest but real:

  • Use current, well-reviewed encryption standards and avoid home-made or legacy ciphers.
  • Retire old cryptographic systems and keep software up to date, since weaknesses in aging designs are likely to be found faster as automated tools improve.
  • Avoid predictable, repeated content in protected messages and formats where possible, because predictable text is exactly what cribs exploit↗.
  • Treat claims about AI capability with interest but care, and look for independent confirmation from the researchers who maintain the puzzles.

The bigger picture

The Enigma story is a vivid, easy-to-understand example of AI systems moving from answering questions to carrying out extended technical work. That is encouraging for research and history enthusiasts who want long-standing puzzles solved. It is also a reminder for the security community to keep measuring these abilities openly, so that defences and safety practices keep pace.

Source: Schneier on Security

#AI #cryptography #Enigma #GPT-6 Astra #codebreaking #frontier AI #research
View as Markdown

Was this helpful?

Share on