Enigma message MVUEH left a German Army radio station on 10 July 1941 and was logged at 17:30 that day as incoming message Nr. 172 by the radio station of the SS-Totenkopf Division’s quartermaster. It is 82 letters long. Since 2005, when it was published among the unbroken messages on Frode Weierud’s Crypto Cellar Research site, it had resisted every attempt to read it. On 15 September 2026, developer Carter Leffen sent Weierud a key and a plaintext produced with OpenAI’s GPT-6 Astra, and Weierud says it was “immediately clear he had found the correct key and plaintext”.
Tom’s Hardware summed the story up as ChatGPT-6 Astra cracking an 85-year-old Enigma-coded message in two days. The headline is accurate as far as it goes, but the primary sources add detail it leaves out. The “two days” is the span of the investigation, while Leffen says the model itself ran for roughly ten hours on about 650 million tokens. Leffen’s own case study calls the work “researcher-led”, while Weierud credits the model with doing it “entirely on its own”. Six days later a second unbroken Enigma message fell to Anthropic’s Claude Opus 5, with far more human guidance.
This article sets out what the 1941 Enigma message says and why it stayed unbroken, how the break was made, what the headline numbers measure, who did the work, and what is still unsolved. It closes with what the result means for any business weighing agentic AI for research. For background on the model, see our report on GPT-6 Astra crossing OpenAI’s Critical cybersecurity threshold and our AI models and tools hub.
Table of contents
- What the 1941 Enigma Message Says and Why It Stayed Unbroken
- How ChatGPT-6 Astra Broke the MVUEH Enigma Message
- Two Days or Ten Hours? What the Enigma Message Numbers Measure
- Who Really Broke the Enigma Message: Model or Researcher?
- A Second Enigma Message Falls to Claude Opus 5
- What an AI Enigma Message Break Means for Business Security
- The Enigma Messages Still Unbroken
- Frequently Asked Questions About the Enigma Message Break
- References
What the 1941 Enigma Message Says and Why It Stayed Unbroken
The MVUEH Enigma message is short and routine, which is part of why it was hard to break. Its sender, a radio station using the tactical callsign 2ny, wanted directions. The recovered German reads, with spaces added: BTTE UM ANGABE DES MARSQWEGES X BEFINDE MIQ IN X ROSENOW ROSENOW X SOFORT FUNKANTWORT X WASCHBBSCH. In English: “Please specify the route of march. I am in Rosenow, Rosenow. Immediate reply by radio.” The signature is tentatively read as Waschbusch.
The 82 letters and the recovered key
Enigma operators wrote Q for CH and used X to separate phrases, so MARSQWEGES is Marschweges and MIQ is mich. The text also carries two slips made in 1941: BTTE for Bitte, and WASCHBBSCH for the signature. The key that turns the ciphertext into that text is set out below, as published in Leffen’s completion report of 16 September.
| Item | The MVUEH Enigma message |
|---|---|
| Message | Nr. 172, indicator MVUEH, 10 July 1941 |
| Route | Callsign 2ny to the SS-Totenkopf quartermaster (Ib), received 17:30 |
| Length | 82 cipher letters |
| Machine | Enigma I with reflector B |
| Rotor order | II, V, III (wheel order 253) |
| Ring settings | H M F (08 13 06) |
| Header | GTA / KCI, giving a body start of RWD |
| Plugboard | AC BE DG FH KN MO PR SU TV XZ |
| Status before September 2026 | Unbroken since it was published in 2005 |
Why this Enigma message resisted attack for 21 years
Weierud gives three reasons in his write-up. First, the key was not the one anyone expected. Every other message from 10 July 1941 used wheel order 512, including Nr. 173, SIPVX, which Alex Shovkoplyas broke on 9 June 2017 with a plugboard and ring setting slightly different from the daily key. MVUEH used wheel order 253, so neither known key from that day could open it.
Second, the published transcription of the ciphertext contained several errors, and a single misread letter can make a correct key look wrong. Third, the machine’s left-hand wheel turns over at the 72nd letter, an event Weierud calls rare and “known to complicate a break”. Any one of these would slow an attack on a short Enigma message. Together they explain two decades of failure.
Where the Enigma message came from
The message belongs to a body of German Army traffic that reached Weierud and his colleagues in 2001, and which they first broke into in March 2003; Geoff Sullivan and Olaf Ostwald share the copyright on the lists. In July 2026 Weierud found further collections in the German Bundesarchiv, including outgoing messages from the SS-Totenkopf Division’s supply command, the Nachschubführer. That find mattered, because it supplied a second, outgoing copy of this Enigma message, numbered NF 88/61, alongside the received copy.
How ChatGPT-6 Astra Broke the MVUEH Enigma Message
According to Weierud, Leffen’s instruction was simple: see whether GPT-6 Astra could break any of the unbroken Enigma messages published on the Crypto Cellar site. The model reviewed the list, judged Nr. 172 the most promising target and “quickly suspected” that the known plaintext of SIPVX was related. The guess was right. The two plaintexts turned out to be almost identical, differing by twelve letters because of the BTTE slip and a repeated signature in SIPVX.
Choosing the crib
A crib is a stretch of plaintext a codebreaker guesses in advance, and Bletchley Park lived on them. GPT-6 Astra settled on the repeated place name ROSENOWROSENOW from SIPVX, 14 letters, and searched for the places it could sit in the 82-letter ciphertext. Because an Enigma machine never encrypts a letter to itself, 31 of the 69 possible positions could be rejected at once, leaving 38. The case study is candid that the known SIPVX text “helped motivate the crib; it was not a blind prediction.”
Building its own Enigma simulator and Bombe
To run that search, the model wrote its own tools. Weierud says GPT-6 Astra developed “the necessary Python and C++ software for an Enigma simulator and an Enigma Bombe”, the second a software descendant of the machine Alan Turing and Gordon Welchman designed at Bletchley Park. The case study adds that early hill-climbing searches missed known answers even when given some correct settings, so the controls were tightened before any larger search on the Enigma message was trusted.
Handling the uncertain handwriting
Before searching, the evidence work recorded twelve positions where the handwriting could be read more than one way, giving 13,824 permitted readings. The search could pick among those recorded letters but could not invent new ones. The final reading changed three positions from the earlier transcription (27, 43 and 47) and differs from the published received transcription in eight places, all within the declared alternatives.
The search in numbers
Leffen’s completion report puts a figure on every stage of the search. The counts span nine orders of magnitude, so the chart plots them on a logarithmic scale: bar length is proportional to the number of digits, not the raw value.
The 4.29 billion total is 60 rotor orders × 107 stepping classes × 17,576 electrical anchors × 38 crib placements. Each bar is its base-10 logarithm divided by 9.63, the logarithm of that total, so the single final key is drawn as a sliver. For comparison, the case study puts the standard machine at about 159 quintillion daily configurations, which is why brute force alone was never the plan. The recovered text ranked first even when scoring ignored the crib, and the 68 letters around it, which the search never imposed, came out as connected German.
Two Days or Ten Hours? What the Enigma Message Numbers Measure
Several durations are circulating for this Enigma message break. They measure different things, and the coverage has mixed them. Tom’s Hardware’s “two days” follows Weierud’s line that “what it has achieved in two days would take a human researcher weeks or even months”, and the case study dates the investigation to 14 and 15 September 2026. Early coverage, including a Rundown AI item republished by Blockchain.News on 17 September, reported about ten hours instead.
What each Enigma message figure counts
| Figure | Source | What it measures |
|---|---|---|
| Two days | Weierud; Leffen case study | Span of the investigation, 14 to 15 September 2026 |
| Roughly 10 hours | Leffen on X, 17 September | Run time of GPT-6 Astra at its Extra High setting |
| 650 million tokens | Leffen, replies on X | Model usage, about 70% of his weekly Pro allowance |
| 13 min 28 s | Weierud, FMNGI write-up | Final key search for the second Enigma message, on an Apple M2 |
| Weeks or months | Weierud | His estimate for a human researcher doing the same work |
| 85 years | 1941 to 2026 | Age of the Enigma message |
| Since 2005 | Weierud | How long the message had been public and unbroken |
The case study itself declines to give a total. “The two days describe the span of the investigation,” it says, and “the logs do not provide a complete total for human or model reasoning hours”, because parallel search processes cannot simply be added together. Leffen’s ten-hour figure, posted on X, is his own account of how long Astra Extra High ran.
Two calendar days are treated here as an upper bound of 48 hours, so the ten-hour run is 21% of the bar (10 ÷ 48). The FMNGI search, 13 minutes and 28 seconds, is 0.22 hours, which rounds to a sliver.
What the Enigma message break cost in compute
Leffen said that after he entered the instruction “/goal don’t stop working until you solve the problem” he did not expect to see it finish, and that the run used 70% of his weekly allowance on a ChatGPT Pro account, roughly 650 million tokens. In a follow-up reply he put the cost at “$200”, the monthly price of the Pro plan whose new sign-ups OpenAI paused on 10 September, as we covered in our report on ChatGPT Pro subscriptions going on hold.
Metered through the API, the same work would look very different. OpenAI lists GPT-6 Astra at $10 per million input tokens and $50 per million output tokens, with separate, lower rates for cache reads and writes. Billed as uncached input alone, 650 million tokens would come to $6,500 (650 × $10). The real mix of cached, uncached and output tokens is not public, so treat that as an illustration of scale, not a bill.
The part Leffen says took longest
Leffen also wrote that he “spent 99x more effort on building the website to describe the challenge and solution than any of my efforts on breaking the code”, adding that Astra did “all of the heavy lifting” on the site too. The site includes a working 3D Enigma machine, a letter-by-letter replay of the decryption, and downloadable evidence that runs to a 134.8 MB audit archive.
Who Really Broke the Enigma Message: Model or Researcher?
The accounts differ most on who made the decisions. Weierud gives the model the credit: “the most astonishing thing about this break is that the GPT–6 Astra did it entirely on its own.” Leffen’s case study frames the same work as “a researcher-led investigation with GPT-6 Astra and parallel specialist agents”, in which “the researcher set the goal and pushed the investigation forward.” His post on X sits closer to Weierud, listing nine things Astra did “autonomously”, from searching historical archives to cross-checking the results.
| Question | Weierud, Crypto Cellar | Leffen case study | Leffen on X |
|---|---|---|---|
| Who chose MVUEH? | The model | “We”, for its second copy, header and related traffic | Not stated |
| Who found the crib? | The model | Suggested by the solved SIPVX text | “Find contextual clues” listed as autonomous |
| Who wrote the tools? | The model, in Python and C++ | Agents built the search programs | The model |
| Human role | Pointed it at the unbroken list | Set the goal and pushed the work | Iterated with it on the website |
| Verification | Weierud, 15 September | Separate simulators and a SAT check | Expert validation before posting |
How specialist agents divided the Enigma message work
The case study describes a team of agents, not a single chat. Evidence agents examined the sources and recorded possible readings before any answer was known. Search agents built the programs and ran experiments with checkpoints, so work could resume. Context agents compared language and historical clues with solved messages, and review agents reproduced results independently. A coordinating agent merged the findings and “turned disagreements into further checks”, and results were accepted on reproducible evidence “rather than agreement between agents.”
The unexplained private collection
One detail in the logs is unresolved. Weierud quotes an entry in which the model traced the corpus “to a private collection” and found Bundesarchiv radio-message volumes RS 3-3/20a and RS 3-3/63b, noting that “no correspondence has been sent.” Weierud confirms the file references are correct but says they are not on his site. He does not know what the private collection is, or whether the model reached the Bundesarchiv’s digitised files. For how far agents can go in online records, see our report on OpenAI’s agent swarms and online databases.
What the case study refuses to claim
The limits are worth quoting, because the headlines dropped them. “This is not the original breaking of Enigma, and no first-ever or corpus-wide breakthrough is claimed.” The case study says “Waschbusch” is tentative and the precise Rosenow has not been established. It also says the search on this Enigma message is complete only within its stated assumptions: three rotors from I to V, reflector B, ten plugboard pairs and the literal ROSENOWROSENOW crib.
A later check strengthens the result. Searching the published ciphertext with no letters changed, using SOFORTFUNKANTWORT at positions 55 to 71, the team found 4,056 physical keys, and exactly one matched the recorded header: the same key. Because that phrase was learned from the answer, the report labels it a post-discovery check, not a blind rediscovery.
A Second Enigma Message Falls to Claude Opus 5
On 21 September Weierud received an email from Jack Willis, a cybersecurity executive, announcing the break of another Enigma message: Nr. 285, FMNGI, of 31 July 1941. It was, Weierud wrote, “yet another AI Enigma break, only six days after the MVUEH break.” This one used Anthropic’s Claude Opus 5, and Weierud draws the contrast plainly: the FMNGI attack “was more directed and relied on strong human guidance.”
How Jack Willis set Claude up
Willis gave Claude a cryptanalytical workbench written in Go, supplied the historical material and “set it free to investigate”. Claude first transcribed the scanned outgoing form, Nr. 205 NF, recording ambiguous characters rather than resolving them. As a control it used ALQFI, an already broken message of 28 August 1941 sent between the same two radio stations, to test its reading of the FMNGI Enigma message.
A signature that kept giving
The crib came from a habit documented in Sullivan and Weierud’s 2005 Cryptologia article, Breaking German Army Ciphers: the signature of Friedrich Hartjenstein, which gave the 14-letter crib XHARTJENSTEINX. The final search ran on 20 September 2026 and, Willis reported, took 13 minutes and 28 seconds on an Apple M2 machine. The plaintext, KOLJNNE VON X KORPSNACHSCHUB ZURUEK X HARTJENSTEIN X HARTJENSTEIN X, reports a column returning from corps supply, with operator slips in KOLONNE and ZURUEQ.
Why Weierud had not broken it himself
Weierud notes a twist. The plaintext of FMNGI was already in the Nachschubführer collection he found at the end of July, but he went on holiday in early August and only made the connection after the break was reported. “Using the full plaintext is a bit like cheating,” he wrote, “so I prefer it was broken the way Jack Willis and Claude did it.”
| Factor | MVUEH | FMNGI |
|---|---|---|
| Enigma message | Nr. 172, 10 July 1941 | Nr. 285, 31 July 1941 |
| Cipher letters | 82 | 58 |
| Model | OpenAI GPT-6 Astra | Anthropic Claude Opus 5 |
| Human role | Leffen set the goal | Willis supplied a workbench and sources |
| Crib | ROSENOWROSENOW, from SIPVX | XHARTJENSTEINX, from a known signature |
| Search tools | Written by the model in Python and C++ | A Go workbench supplied by Willis |
| Timing | Two-day investigation, about 10 hours of model time | Final key search of 13 min 28 s |
| Confirmed by | Weierud, 15 September | Weierud, after the 21 September email |
What an AI Enigma Message Break Means for Business Security
It would be easy to read this as proof that AI can now break encryption. It is not. Enigma is a 1930s electromechanical cipher that Polish mathematicians led by Marian Rejewski first solved in 1932. The case study’s 159 quintillion daily configurations is roughly 2 to the power of 67. AES-128 has 2 to the power of 128 possible keys, a gap of about 2 to the power of 61, and it has no rotor stepping and no rule that a letter never maps to itself. What made this Enigma message hard was messy evidence, not raw arithmetic.
The real skill on show
What GPT-6 Astra showed is the chain of skills a research project needs: reading difficult sources, forming a hypothesis, writing working tools, running a large search and checking its own answer. OpenAI’s launch post pitches the model on computer use, coding, science and cybersecurity, and says it meets the Critical cybersecurity threshold in OpenAI’s Preparedness Framework. A model that compresses weeks of archive work into two days changes the cost of any task built from those steps. The same capability sits behind OpenAI’s claim, covered in our report on its Math Advisory Group, that its AI has resolved more than 100 open problems.
Verification is the part to copy
The strongest lesson for businesses is how the Enigma message result was checked. Leffen did not publish on the model’s say-so. The key was reproduced by separately written simulators, the winning search batch was rebuilt byte for byte outside the research workspace, a SAT solver checked a sample of machine states, every file was hashed, and an outside expert validated the answer before the post went up. Teams using AI agents for due diligence, audit or research can adopt the same pattern: independent re-runs, a declared scope, retained evidence and a human specialist signing off.
Budget and access controls for agentic work
Two practical points follow. First, cost: one open-ended goal consumed 650 million tokens and most of a week’s allowance on a $200-a-month plan, so long-running agents need spending limits. Second, access: the model’s log mentions records it found outside the site it was pointed at, and nobody yet knows how. If an agent can reach sources you did not list, your policy should say which sources it may use and require it to log them. Our AI strategy and cybersecurity teams can help set those guardrails.
The Enigma Messages Still Unbroken
Weierud says that of the close to 1,000 Enigma and Truppenschlüssel messages in the German Army collection, only seven Enigma messages remain unbroken, plus one puzzle: Nr. 138, WEUWY, which must share its plaintext with Nr. 140 yet has resisted every attempt. His overview page, dated 19 September and so still listing FMNGI, shows what is left from June and July 1941.
| Date | No. | Indicator | Cipher letters | Note |
|---|---|---|---|---|
| 22 June 1941 | 3 | EHSTQ | 52 | Unbroken |
| 28 June 1941 | 53 | RXPSB | 99 | Unbroken |
| 3 July 1941 | 87 | KLJBO | 50 | Unbroken |
| 5 July 1941 | 100 | LXACA | 20 | Attempts marked “Fails” |
| 9 July 1941 | 138 | WEUWY | 48 | “Fails”, same plaintext as Nr. 140 |
| 11 July 1941 | 187 | AWTZK | 49 | Unbroken |
| 11 July 1941 | 189 | ZNLZT | 69 | Unbroken |
| 20 July 1941 | 242 | JBIYH | 55 | Unbroken |
How long the remaining ciphertexts are
Length matters, because a short message gives a search less text to test a key against. The chart compares the two messages just broken with the eight still standing, using the cipher-letter counts from Weierud’s list and the MVUEH case study. Each bar is the letter count divided by 99, the longest message on the list.
The two broken messages sit in the upper half of the range, so length alone did not protect them, and the longest one, RXPSB, still stands. LXACA, at 20 letters, may simply be too short for any search to confirm a key. Three longer September 1941 messages, BYQMZ, FKQLZ and XFEDT, are listed in a separate batch as part of The Ultimate Enigma Challenge.
What to expect next
Weierud ends his FMNGI page with an open invitation: “Who is next to send me a message about a new break with or without the help of AI?” With two AI-assisted breaks in six days, another Enigma message falling this year would be no surprise. Similar claims are spreading beyond Enigma. On 17 September a developer writing as Prinz said GPT-6 Astra had decrypted a 1918 German ADFGVX radio message from Klaus Schmeh’s list of unsolved ciphers, a result Tom’s Hardware reported on 19 September.
Frequently Asked Questions About the Enigma Message Break
Did ChatGPT-6 Astra break the Enigma message on its own?
It depends on whose account you read. Weierud says the model “did it entirely on its own” after Leffen pointed it at the unbroken list. Leffen’s case study calls the work researcher-led, with a human setting the goal and pushing it forward. Both agree the model built the search tools and ran the experiments.
How long did the Enigma message break take?
The investigation ran over two days, 14 and 15 September 2026. Leffen says GPT-6 Astra’s Extra High setting found the solution in roughly ten hours and used about 650 million tokens.
Does this mean AI can break modern encryption?
No. Enigma’s keyspace is around 2 to the power of 67, against 2 to the power of 128 for AES-128, and Enigma has structural weaknesses that modern ciphers lack. The break shows skill at research and tool-building, not a threat to current encryption.
What did the 1941 Enigma message say?
“Please specify the route of march. I am in Rosenow, Rosenow. Immediate reply by radio,” signed by a sender tentatively read as Waschbusch.
How many Enigma messages remain unbroken?
In the German Army collection Weierud publishes, seven Enigma messages remain unbroken, plus WEUWY, whose plaintext is known from a twin message but whose key has not been found.
Can I check the Enigma message result myself?
Yes. Leffen’s site offers a 5,257-byte key checker that runs on Python 3.10 or later with no extra packages, the recovery search with its C++ engine, and the full 134.8 MB audit archive.
References
The MVUEH Break (Crypto Cellar Research)
The FMNGI Break (Crypto Cellar Research)
MVUEH: A Cryptanalysis Case Study (Carter Leffen)
MVUEH: The Recovered Message and the Evidence for Its Key (Completion Report)
Carter Leffen on GPT-6 Astra and the MVUEH Break (X)
Overview of Still Unbroken 1941 Messages (Crypto Cellar Research)
ChatGPT-6 Astra Cracks 85-Year-Old 1941 Enigma-Coded Message in Two Days (Tom’s Hardware)
Astra and Opus Just Passed Turing’s Other Test (TechCrunch)
GPT-6 Astra Cracks a 1941 Enigma Message That Had Resisted Solution Since 2005 (MIXED)
GPT-6 Astra and Opus 5 Crack Two Enigma Messages (Notebookcheck)
GPT-6 Astra: A New Generation of Intelligence (OpenAI)
Modern Breaking of Enigma Ciphertexts (Ostwald and Weierud, Cryptologia, authors’ copy)
ChatGPT-6 Astra Cracks 108-Year-Old Unsolved WWI German Code (Tom’s Hardware)
More AI coverage: explore Progressive Robot's AI Models, Tools & Releases hub — hands-on reviews, setup guides and benchmarks in one place.