Case TS-FB0F983B20 Sept 2026capability

AI

“GPT-6 Astra, an AI model, autonomously decoded a previously unsolved 1941 German Army Enigma-encrypted radio message in about 10 hours, revealing the plaintext: 'Please specify the route of march. I am in Rosenow, Rosenow. Immediate reply by radio.'”

Plain restatementUsing OpenAI's GPT-6 Astra, a German Army Enigma message from July 1941 that was recorded as unbroken in the specialist archive was decrypted over roughly ten hours, producing a plaintext requesting a march route from a sender at Rosenow.

Partially accurate but misleadingConfidence High
What this verdict means →

Distortion codes this site does not recognise yet: capability_extrapolation, demo_to_product_conflation, cost_compute_omission. Not collectible until the field guide has an entry.

This one is mostly real, with one important word wrong. A German Army Enigma message from 10 July 1941, catalogued as MVUEH, had genuinely sat unsolved in Frode Weierud's CryptoCellar archive for decades, and in mid-September 2026 Carter Leffen cracked it using OpenAI's GPT-6 Astra. The result is solid: an unrelated group wrote its own Enigma simulator, applied the published key to the archive's own copy of the ciphertext, and got the same German text, and the archive's custodian has updated the record to mark the message broken. The quoted English plaintext about the route of march and Rosenow is accurate. The misleading part is "autonomously." Leffen's own project report describes this as a researcher-led investigation in which he set the goal and drove the work, with the AI agents doing the searching, coding, and checking, and two news outlets say the same, with one reporting that Leffen himself supplied the crucial crib. It is also worth knowing that the model did not beat Enigma from scratch: a repeated place name lifted from a neighbouring message that was already solved cut the problem down to about 15 million key checks, which is easy for any modern computer. The genuine achievement is that an AI system ran a long, multi-step research project with limited supervision, not that it defeated a cipher.

The drift / as claimed vs as evidenced

GPT-6 Astra, [drifted from the evidence:] an AI model, autonomously decoded a [drifted from the evidence:] previously unsolved 1941 German Army [drifted from the evidence:] Enigma-encrypted radio message in [drifted from the evidence:] about 10 hours, revealing the plaintext: [drifted from the evidence:] 'Please specify the route of march. [drifted from the evidence:] I am in Rosenow, Rosenow. [drifted from the evidence:] Immediate reply by radio.'


[added by the neutral restatement:] Using OpenAI's GPT-6 Astra, a German Army [added by the neutral restatement:] Enigma message [added by the neutral restatement:] from July 1941 that was recorded as unbroken in the [added by the neutral restatement:] specialist archive was decrypted over roughly ten hours, producing a plaintext [added by the neutral restatement:] requesting a march [added by the neutral restatement:] route from a sender at Rosenow.

Red-tinted words in the claim drifted from the evidence. Green-tinted words are what a neutral restatement needs.

The trace / claim to source

Where it appeared
⌿ Omitted qualifier
A load-bearing condition from the source quietly disappears from the claim.
capability_extrapolation
demo_to_product_conflation
cost_compute_omission
Tertiary sourceindividual newsletter
John Fenzel Substack, containing a quoted reaction attributed to Weierud
Secondary sourcenamed-outlet tech journalism
The Decoder, reporting and case-study summary
Secondary sourcenamed-outlet journalism (one chain, multiple mirrors)
BeInCrypto / syndicated via Yahoo and CoinDesk mirrors
Primary sourceindependent specialist archive
Frode Weierud's CryptoCellar, BGAC 1941 Message List, the archive of record for these intercepts
Primary sourceindependent specialist archive
CryptoCellar, Enigma Keys July 1941 (day-key file with the note on Nr. 172)
Primary sourceindependent specialist archive
CryptoCellar, Enigma Messages July 1941 (the published ciphertext and message form)
Primary sourcesolver self-report
"MVUEH: An Enigma message recovered", the solver's own project site and technical report
Primary sourcesolver self-report, informal
Carter Leffen X thread, 17 September 2026
Primary sourceindependent re-check
swarm-ai-research/cipher-break-verification, independent re-decryption from the archive's own ciphertext
● Primary source found
What is true
  • The message is real, specific, and was genuinely unbroken. CryptoCellar's index carried MVUEH (Nr. 172, 10 July 1941, 82-letter body) with status "Fails", and the archive's own key file explains that it did not break on that day's recovered key.
  • The decryption is real and has been independently reproduced. A third party wrote its own simulator, applied the published key to the archive's own unchanged ciphertext, and got matching connected German.
  • The custodian of the archive accepted the result and updated the corpus. This is the strongest possible form of acceptance for a claim of this kind, because it comes from the party that held the message as unsolved.
  • The roughly ten hour figure is the solver's own stated figure for the model run, and it is reported consistently.
  • The quoted English plaintext is faithful to the recovered German. The independent re-check renders it "Please give the route of march. I am in Rosenow, Rosenow. Reply by radio at once," which is the same message in different words.
  • GPT-6 Astra is a real, released OpenAI model, so the claim is not built on a fabricated product.
What is misleading
  • Omitted qualifier: the claim says "autonomously." The solver's own technical report says in plain words that this was a researcher-led investigation in which the researcher set the goal and pushed the investigation forward. The word "autonomously" converts an AI-executed, human-directed research project into an unsupervised machine discovery. That is the single load-bearing change in the claim.
  • Capability extrapolation: "decoded a previously unsolved Enigma message" invites the reading that the model defeated Enigma as a cipher. It did not. The attack was made tractable by a crib borrowed from an already-solved neighbouring message, reducing the problem to under 15 million key checks, which is trivial for modern hardware. The achievement is the research workflow, not the cryptanalysis.
  • Demo to product conflation: "GPT-6 Astra, an AI model" describes a single model. The actual configuration was the Extra High effort variant orchestrating parallel specialist agents, consuming roughly 650M tokens and most of a Pro-tier weekly allowance, under a persistence instruction. This is not ordinary product behaviour and would not be reproduced by a typical user asking the same question.
  • Omitted qualifier: the quoted plaintext is presented as clean recovered text. The actual recovered German is garbled in 8 of 82 positions, including an operator's mistyping of BITTE as BTTE and ROSENOW as ROSTNOW. The English sentence is a smoothed translation of damaged text, and the trailing signature is tentative rather than established.
  • Cost compute omission: the claim as submitted drops the token spend, the agent scaffold, and the 14.8 million key checks. The original post does mention the token figure, so this distortion is introduced by the compression rather than by the poster.
What is uncertain
  • Who found the crib. This is the crux of the autonomy dispute and the sources conflict. BeInCrypto states Leffen supplied it. Other coverage says the model spotted ROSENOW in the already-solved SIPVX message. The solver's site says only that the known SIPVX text motivated the crib and that it was not a blind prediction, which does not settle agency. I could not resolve this.
  • What exactly "autonomously" was meant to cover. Leffen's informal X post applies the word to a list of sub-tasks executed inside the run. His formal project report describes the overall investigation as researcher-led. These are one subject making two statements at different levels of formality, and they are in tension on the headline word.
  • Whether the result will survive full expert scrutiny. The Decoder notes that the published packages verify the calculations and replicate the key search sequence, but they do not prove the message's historical identity or that the solution is the only possible one, and whether the decryption holds up will depend on experts evaluating the published materials. The one independent check so far did not repeat the full search.
  • The reaction attributed to Frode Weierud ("simply amazing... still in awe") appears in an individual Substack post. I could not retrieve it from a CryptoCellar page or a statement by Weierud directly, so I do not treat it as established.
  • The current CryptoCellar index entry I could only obtain in its pre-update state. The "now broken" status rests on the verification repo and secondary reporting.
Evidence summary

The underlying event is real and unusually well documented. The message exists in the archive of record. CryptoCellar's July 1941 index lists 10.07.1941, message 172, identifier MVUEH, 87 / 82 letters, with the status "Fails", against neighbouring entries marked "Broken", including 173 SIPVX broken by Alex Shovkoplyas in 2017. The archive's own key file for that day records the reason it resisted: a note that "Nr. 172 and 173 do not break on this key. It is therefore suspected that these two messages are from a different network and that they are on a different key." The ciphertext itself is published on the archive's message page under "Funkspruch Nr.: 172... 1220 - 87 - GTA KCI - MVUEH IDEVS ARMCC NQTAT YEVFC DBZGG..." An independent party re-ran the result without using the solver's code. The verification repository describes independent re-checks of AI-assisted historical cipher breaks, starting from the ciphertext as published by the archive that holds it, applying the claimed key with a simulator written there, and printing what comes out, and records the recovered key as rotors II-V-III, reflector B, rings HMF, plugboard AC BE DG FH KN MO PR SU TV XZ, with the result that the archive's unchanged published ciphertext gives connected German, garbled in 8 of 82 positions. Its own output line records the claim as matching. The custodian accepted it. The verification repo notes that "CryptoCellar now marks the message broken, which is the acceptance that matters: the corpus's custodian, not the solver." On the question of autonomy, the solver's own technical documentation is explicit: "This was a researcher-led investigation with GPT-6 Astra and parallel specialist agents. The researcher set the goal and pushed the investigation forward. Agents examined sources, built search programs, ran controlled experiments, and challenged the results." The same page also states "Across 14-15 September 2026, source work, search development and review overlapped." On the crib specifically, the site states that the known SIPVX text helped motivate the crib and it was not a blind prediction. Named reporting reaches the same reading. The Decoder states that GPT-6 Astra and several specialized AI agents served as Leffen's tools throughout the process, with some analyzing historical sources, others writing search programs, and others comparing results against already-solved messages, while Leffen set the goals and made the calls on how to proceed. BeInCrypto is blunter: "Nor was the break autonomous. Leffen set the goal, supplied the crib, and pushed the investigation forward, while the agents handled evidence, search, and review. The model carried out the execution rather than the judgment."

Complete reasoning
Nearly every checkable element of this claim holds up, and unusually well for a viral AI story: the message was genuinely logged as unbroken in the specialist archive, the recovered key reproduces coherent German when an independent party applies it to the archive's own ciphertext, the archive's custodian accepted the break, and the quoted plaintext is a faithful rendering. The claim fails on one word. The operative proposition is that the model did this *autonomously*, and the solver's own technical report states that the investigation was researcher-led with the researcher setting the goal and driving it forward, a reading two named outlets independently confirm and one states outright. I considered "Mostly accurate", and rejected it because a cited source denying the claim's operative modifier is not a simplification that leaves meaning intact. I considered "Accurate", rejected for the same reason, and "False", rejected because the event, the timing, the plaintext, and the archive status are all correct, so the evidence bounds one term rather than contradicting the claim. Confidence is High because the deciding artifacts, the archive index, the solver's report, and an independent re-decryption, were all obtained; the unresolved crib provenance sharpens the finding but does not change it, since the "researcher-led" sentence is decisive on its own. As of 2026-09-19.
Use this case

The reply is formatted for pasting into the thread where the claim is circulating.

Compact share page: ai.trueseeker.com/s/fb0f983bafb6/nk3qB9ywmFRNdLBbCb7JE1PYJz2

Ask this case

Answers come only from the case file above; nothing is added.

Was the Enigma message really unsolved before this?

Yes. The archive of record, CryptoCellar, listed the message (identifier MVUEH, 10 July 1941) with the status "Fails," and its own key file explains that it did not break on that day's recovered key.

Did GPT-6 Astra actually crack it on its own, with no human help?

No. The solver's own technical report describes this as a researcher-led investigation in which the researcher set the goal and pushed the work forward, with AI agents doing the searching, coding, and checking. News coverage describes the same division of labor, and one outlet reports the researcher himself supplied the key crib.

How was the decryption confirmed as genuine?

An independent third party wrote its own Enigma simulator, applied the published key to the archive's own unchanged ciphertext, and got matching connected German text. The archive's custodian then updated its records to mark the message broken.

Is the quoted English plaintext accurate?

The English text is a faithful rendering of the recovered German, but the actual recovered German is garbled in 8 of 82 positions, including a mistyped word. The quoted plaintext is a smoothed translation of that damaged text.

Did the AI really defeat the Enigma cipher from scratch?

No. A repeated place name borrowed from an already-solved neighboring message narrowed the problem to about 15 million key checks, which is easy for modern computers. The case file states the real achievement was running a long, multi-step research process, not breaking Enigma unaided.

Similar cases on record