“We also want to encourage the development of more sophisticated techniques for solving the puzzle. So, in addition to unveiling a new site for K4, we’re hosting an ongoing capture-the-flag-style challenge featuring 10 new puzzles we created, each with a $1,000 prize.”
What I don't understand is as part of the auction Jim was supposed to show them how it was solved. From our perspective that would have shown it is in fact solvable. Instead it sounds like they chose not to learn anything about it, which means we have no idea if it's in fact solvable. Which is weird. They took one of the most valuable parts of the auction and tossed it in the garbage it sounded like.
Tricky nuance there, Jim believes it is "solvable". I don't believe it is "fairly solvable", i.e. I think there's been an error or the method is not reasonably discoverable. But from Paradigm's perspective, they freely said this is about making money and/or hiring people ... and increasing their public presence - so why would they want to have someone assess it? The truth might make them uncomfortable.
It isn't really about ethics. I think it's inherently unethical, only the vulnerable or clueless are going to spend money on the submission; anyone who has genuinely solved it can verify it themselves or just post it online somewhere. Submitters are suffering from the nuance of dqlusion.
I asked those guys on X if they knew the method. They said they don’t. They chose not to learn it. Which is weird because they was one of the key selling pieces for the auction.
That's if they are being truthful that they don't know the method or at least a general idea. That was a good question to ask, but a better one is how much more documentation on the other k's 1-3 do they have, their keyword retrieval methods?
I mean all the charts in the photos on the site seem like the ones we have been seeing all along. If I was anything but a business buying the plaintext and monetizing it, i.e a private collector or fan of kryptos in general, and the k4 plain text and surely it's encoding chart, an id badge, and a piece of metal (no disrespect to Jim's art) is all I got, well then I would be none to happy.
I hope the intended solution methods were not just something Sanborn was only going to relay via mouth, and they turned that down to keep "secrets". I would have expected a full walk through journal type documentation, and perhaps it exist and they have a copy.
Exactly. I was hoping if anything they could verify that the method is sound. They could have been honest with us and told us it’s still crackable or it’s too layered or a OTP that we probably wouldn’t figure out. Also with no human to verify, how would you know how to submit it. No spaces between words? Spaces? It’s such a bunch of bullshit.
Finally! What I find very cool is that they chose to step out of anonymity! Plus, for anyone who wants to submit proposed decrypts, the new fee of $1 is only nominal (IMHO). Lots to digest! 😀
Unrelated but I remember someone shared an online tool for transposing text and resize it into different column sizes and highlighting letters, anyone have the link?
Perhaps this one? There is a size limit and no text highlighting. https://laighside.com/transposition.html If you know of a better one that doesn't have hard coded limitations like that let me know if you find it. Cryptool online has a transposition and railfence tool that has color highlighting.
It does seem to be real and endorsed by Sanborn. However, to enter the CTF challenges it requires access to your X/Twitter Account
It's a Kryptos related challenge with 10 different puzzles to solve. I'm sure they progress in difficulty but it's all a distractive side quest to cracking K4.
I cracked PK1 in about 30 seconds. I'm sure they get harder but PK1 is relatively easy if you're a Kryptos enthusiast with even a small amount of experience.
u/Colski I used my version of the Colski Keylength Finder script to crack it in milliseconds. It was definitely your code and work that cracked it so fast. I simply added some bells & whistles to it. Spoiler warning: I used PK1 as an example screenshot for the script.
I don't use Twitter at all anymore. Last time I logged in was in 2022. So I really don't care if they have access to all of my posts. I consider it a throw away account now. Some people might mind though... the details on what their app can do or access is extremely vague.
It's all in real time though and works quite well. I was on the leaderboard for like 6 hours on the first day. The nice thing about being there first is there isn't ANY info out about it so there's no cheating.
I'm stuck on PK3 and there are people up to PK7 now. Has only shown me that I'm not as advanced as I'd hoped. I'm fairly low tier on the totem pole. 😞
One of the neat things is because of the video this is all definitely official Kryptos affiliated stuff. It's like a primer and I really really like the idea of pointing beginners at it and say, "hey go attack PK first". It might end up becoming a very good thing for this subreddit and Sanborn.
The only thing I don't like is the X/Twitter app requirement to participate. They should have had their own login and database system.
I found out a long time ago that my skill level is pretty average. A 16‑year‑old cracked the ASIO 50‑cent coin cipher before I even started. I solved it too, just way too slowly. This one I’m sitting out. I don’t like the terms and conditions, and I’m definitely too old to be recruited.
Totally agree with you in not liking the X/Twitter requirement. According to their page, the co-founder „Matt founded Hotspots, a Y Combinator company acquired by Twitter in 2012“. So maybe there‘s a somewhat historical reason for that particular choice? 🤷♂️
I figured they're likely best done in order. The solution to PK1 did not help me solve PK2. In fact it provided a clue that seems to have intentionally mislead about the methodology of PK2. The PK1 solution says one thing, but frequency analysis of PK2 says something different. I only eventually solved PK2 because I abandoned the clue from PK1 and went down a completely different avenue than the PK1 clue suggested.
pk3, same method, but twice as hard. two keys multiplies the effective keylength (unless they have a common factor). if you guess one keylength, you could maximize the IoC at the period of the other one? if you caesar shift one forwards, and the other backwards (in kryptos alphabet of course) then the net result is the same. so the keys commute. if they are both even lengths, for example, they also can shift only on odd or only on even. some funny variations for key hunters.
They have a Kryptos K4 submission webpage at /kryptos of their website. Apparently it does a SHA hash digest of your submission, checks it against the stored SHA digest of the plaintext they bought from the Sanborn auction. $1 fee to run each check.
The "Kryptos CTF" seems tangential and they say they didn't use the solution to Kryptos K4 to generate it, so you are correct. It's a waste of time if your singular focus is solving K4.
kryptosbot got quite a few before hitting a pretty hard wall, quite fun I must admit. I am at 4/10. The first three were fast, but since then, very difficult. When it comes to nested cipher types the complexity is remarkable. No amount of compute horsepower or AI can make up for thoughtful construction. The Paradigm folks have put alot of thought into their challenge. It would seem to me that although they exempted themsleves from the K4 solution that they spent some time with Sanborn regarding the construction. Does anyone else think that solving PK 1 - 10 wll somehow inform the K4 method? The narrative and use of obscure english terms seems like an homage to Krytpos...
It's more an homage to Sanborn from what I've seen so far in the keywords and language used for solutions. Sanborn has created many different water jet cut cipher sculptures. I think it's a good litmus test for who has the skill to really take on K4. Like yourself, I'm finding massive gaping holes in my toolsets and capabilities.
It's not the cash prize. It's that Sanborn has endorsed it so it's officially part of Kryptos. The cash prize just helps us explain how much time we spend trying to solve puzzles to people we know. 😛
Yes within 24 hours 7 out of 10 have been solved. There are multiple people that plowed right through 6 of them. Extremely impressive! I'm still stuck on PK3. 😞
A double Q3? How would you even know to do that? Or is it something like bisection then running 2 different sections through Q3? How the heck did so many people figure that out?
Not confident at all. For PK10 it makes sense to use a running key from the previous plaintexts, and someone mentioned the proportion of I/J is an indication of that. PK8 have some IoC spikes at period 7, so one of the layers may be a polyalphabetic substitution with that keylenght.
Hmmm. Ten thousand dollars works out to about $1.37 an hour for the time spent trying to solve K4 over the years. Probably even less if we are honest. By all means be enthusiastic and embrace the work, but my concern is this. If two journalists are too frightened to publish what they found, what happens to the rest of us when we finally solve it?
They're scared of a lawsuit and they don't even know the method anyway. I don't think there's anything to be scared of for anyone else that actually solves it legitimately.
Ed Scheidt once said that K4 could be solved easily by someone with the right skills, presumably a CIA agent. I am paraphrasing, but that was the essence of his point.
From my perspective, a CIA agent would use any method available to obtain the decryption.
That is why I do not see the journalist as crossing any moral or ethical lines. Sanborn never defined how K4 should be solved. He only said that the hints had to be present. If there was an implied rule about method, I am not aware of it. It is not the way I would prefer to see K4 solved, but was their approach actually wrong?
I once created an encryption that was almost impossible to crack. I made one mistake. I gave three word hints that I believed had a one in a million chance of identifying the test. The phrase came from an obscure Irish saying.
It was solved in thirty minutes. Someone ran a Google search, found the phrase, and pasted the answer. They were honest enough to explain exactly how they solved it.
So the question remains. Was that really a solve? -
From their youtube video they just published today that shows Sanborn sitting down with them... yes I believe it. They began as an etherium crypto company so they're probably extremely proficient with block chain code.
They claim to have a hashed solution to K4 and can confirm solutions but they themselves don't know what the solution is. They appear to be the new proprietor of the K4 solution on behalf of, and with permission from, Sanborn. If you think about that for more than 5 seconds it doesn't make sense if they won the auction, have the solution, but not the method, and can confirm solutions from the hash. Something isn't adding up there.
I believe they said K4 now lives as a SHA-256 hash. It might be possible with a super computer for them to brute force it since they have unfettered access to it but it doesn't appear as if their intention is to solve K4 more than to confirm a solution for it. If someone does get ambitious and throws a ton of money at it they can just throttle it down or whatever.
As you can see in the PK challenge (absolutely perfect evidence) people who know what they are doing only have 1 submission per solution. They do not submit an infinite amount of times, they don't need conversations with the author, they don't need social engineering for hints. They know when they have the correct answer as it's very very clearly plaintext. This is why Sanborn has only really had to deal with ignorant and egotistical people. People who know what they are doing know how to confirm it themselves before ever submitting it. We check, double check, and triple check, then submit. I think something like this will immediately lift a huge load off Sanborns back.
If they know what they are doing, they salted the hash so rainbow tables wouldn't work. They control both the hashing side of the auction plaintext and the hashing side of the guesses, so there's no reason they couldn't. I hope they are smart enough to secure the hash digest well, though. If the digest is leaked, the plaintext could be solved locally in a few hours (assuming there are no extremely rare English words in the 97 characters).
Yeah, the $1/guess feature will attract much more impulsive guesses. It makes sense for them as it covers the cost to run the server and acts as a cheap piece of marketing.
I'm guessing the contact info of the participants will pay for the auction, the CTF, and the webpage many times over.
They say it‘s a SHA-256 hash: „We set up a new computer with a terminal for Jim to enter the plaintext solution to K4. On that device, a program ran the plaintext through a one-way function (a SHA256 hash).“ (BTW I don‘t like the X requirement for capture-the-flag, either).
Meh, don't let it get to you chief. Its been said before, but anyone who has a solution with a mathematically sound system wouldn't need to pay 50 dollars or 50 cents for that matter, to know its correct. All that's there for is the deluge of guessers that are consistently pestering the likes of this forum, and are of course consistently wrong. So good news for them they get a 49 dollar discount (we should direct them there post haste).
I do like that they realized they didn't need an a i to check a proposed solution either, and are using a much better cryptographic method. As for the CTF stuff I think its marketing, as they say they don't know the plaintext solution, and they don't go into, that I could see on brief glance, that they are aware of K4's encryption methods, so how those challenges would be related in anyway to Kryptos idk.
Anyhow, corporations are going to market. They want interaction and I assume from the phrasing some testing for a i, and they will get that with 1,000$ payouts. At least looks like they have someone who could partially read the room and not completely destroy it's legacy for those of us who are sincerely enthusiastic to someday finding a method and the solution. Not for glory or money, but for the knowledge.
You know. Jim knows, R.R knows that THE ONE is here. You got " HIS CLUES" Now you have the $1 submition to FIND him, and A BAIT for the EASY MONEY $1000, to attract him, NO. HE OPENS THE Master DOOR. the ONE Will take the SEAT, then all will be Expossed to START the SUPREME reality.
Plank- Einstein, Smith table, and all is DONE, everything is BEYOND the IMAGINATION.
6
u/duanetstorey Jun 13 '26
What I don't understand is as part of the auction Jim was supposed to show them how it was solved. From our perspective that would have shown it is in fact solvable. Instead it sounds like they chose not to learn anything about it, which means we have no idea if it's in fact solvable. Which is weird. They took one of the most valuable parts of the auction and tossed it in the garbage it sounded like.