OpenAI GPT–6 Astra breaks Enigma message that has resisted solution since 2005
cryptocellar.org499 points by sohkamyung 8 hours ago
499 points by sohkamyung 8 hours ago
For anybody interested, the actual encrypted message:
BTTE UM ANGABE DES MARSQWEGES X BEFINDE MIQ IN X ROSENOW ROSENOW X SOFORT FUNKANTWORT X WASCHBBSCH
which, given misspellings, translates approximately to: Please specify the route of march. I am in Rosenow, Rosenow. Immediate reply by radio. Waschbusch. I am in Rosenow, Rosenow.
From the article: After trying many different approaches, GPT–6
Astra focused on using the repeated place name
ROSENOW ROSENOW as a crib.
This feels extremely underexplained! Why would Astra think to use that as a "crib"? Was it common to repeat the place name in these messages?(Is it possible that this is a misreported detail? It feels like a singular ROSENOW would be an equally effective crib)
This was explained in the article right there:
> it suspected that the plaintext of Nr. 173, SIPVX, might be related to the plaintext of the unbroken MVUEH message
It makes sense that Nr. 172 and Nr. 173 might be related since they were sent at around the same time.
In Nr. 173, "ROSENOW ROSENOW" was also present.
It also makes sense that a longer crib would generally be more effective than a shorter one.
It was partially explained by the article. It was not stated that ROSENOW was repeated in 173, and it was not obvious from the article text why ROSENOW would ever be repeated. Thus my curiosity.
A sibling commenter explained it - Rosenow is both a municipal name and a district name, so naturally it would be repeated. (Like "New York, New York")
It also makes sense that a longer crib
would generally be more effective than a
shorter one.
It would seem to me that the odds of looking for even a single ROSENOW in the decrypted message would be plenty. The odds of a single ROSENOW randomly occurring in incorrectly decrypted output are vanishingly small. So it seems to me that looking for ROSENOW is a safer bet vs. looking for ROSENOW ROSENOW -- a single ROSENOW is a great sign you've got the correct key, whereas looking for ROSENOW ROSENOW seems like it would deliver false negatives (think of all the times we say "New York" rather than "New York, New York")I'm a novice at crypto though, so, maybe I've got that totally wrong.
The reason a crib is useful is because the enigma can't route a letter back to itself. So, you can slide the crib along the message until no letters line up, and that's possibly where it is. If your crib is "the", that's not terribly useful, because it could exist anywhere. The longer the better.
I ONLY know this because https://www.youtube.com/watch?v=JsBZOcqZerk, btw.
Rosenow is a municipal (around 32km²) and in there is a district also called Rosenow. So the sender just specified his current position a bit more.
Maybe naive of me, but could it simply just be the overfitting of the same tokens being sent on the input twice because of repetition rather than some unknown implied intelligence.
Out of interest, what was the ciphertext?
Edit: Found it from here: https://mvueh-enigma-solved.carterl.chatgpt.site/
ICRVSORMCCWQTATYEVFXDBZGGSNXWLPSYWZYTCBSWULRTBZCVGODVJUSLSOOMJQJZSXSEBZPEYMDNXJYTCDo we have any kind of transcript as to how the message was cracked, and whether this was cheaper or more expensive than simply Bombe-style trying all the combinations?
As the article states, the LLM built code for both an enigma simulator and a bombe simulator.
Breaking enigma is often about using lucky or educated guesses to heuristically reject large chunks of keyspace to leave the remaining keyspace computationally tractable.
Note that the key (lol) complication with this message seems to be that it had a wheel rollover that most messages do not have to deal with, and that rollover drastically reduces how much you can reduce the potential keyspace using all the techniques noticed by the original crackers.
The wheel rollover I think just requires more brute force. Unfortunately, this might be an example of OpenAI the company having vastly more compute time and effort than your average enigma nerd. For example, modern compute clusters like supercomputers can tractably brute force enigma with no cleverness in like a day or less, while home computers would still take thousands of years to compute that. It's very scalable. Did astra have access to significant compute?
However, even considering that, the inferences made by the LLM are good, and picking this specific message to attack, precisely because it should be soluble but might have had an extra wheel rollover that made it more computationally intractable for hobbyists but not a large company is a clever thing to do for the LLM.
This was done by an OpenAI subscriber, not an employee, so Astra would not have had access to OpenAI's massive compute for brute forcing. The scripts it wrote presumably ran on the computer of the customer. (ChatGPT can run scripts on OpenAI's servers, but it has a 45 second execution limit.)
> Unfortunately, this might be an example of OpenAI the company having vastly more compute time and effort than your average enigma nerd.
I don't think this applies, isn't this just the researcher using ChatGPT Codex on their machine?
> Unfortunately, this might be an example of OpenAI the company having vastly more compute time and effort than your average enigma nerd.
It seems like a lot of the recent "breakthroughs" come down to this: spending millions of dollars in compute to solve problems that essentially amount to recreational math problems
Interesting. Do we know the reason why those specific messages were sent with different keys? I would imagine that there were separate keys for special high-security messages or something like that, but the almost identical content and the way the key was changed here (first only part of the configuration, then suddenly everything) makes it look more like an error or a test.
That's crazy. Can someone share context of the message.
Slopped up site https://mvueh-enigma-solved.carterl.chatgpt.site/ seems to indicate it's due to:
The SS-Totenkopf Division was advancing east during the opening weeks of Operation Barbarossa, the German invasion of the Soviet Union. 10 July 1941, the division had just fought its way through the Soviet border defenses around Sebezh. It had moved through Lithuania and Latvia, crossed the Dvina area, and advanced through Dagda toward a place German records called "Rosenow." The division moved out of the Rosenow area around 6 July, fought around Sebezh on 8-9 July, and then continued east/northeast toward Opochka and eventually Porkhov.was the misspellings deliberate?
i would assume yes, to throw off decyphering. even more impressive that they managed to crack it
I'm surprised "Bitte" --> "btte" was a hurdle. "Bitte," or "please," is ubiquitous in German. The more common the term, them more likely you'd be to see some contractions. Dropping the "i" is pretty logical- anyone looking at it would see immediately what it meant.
> i would assume yes, to throw off decyphering. even more impressive that they managed to crack it
Were operators of enigma machines aware enough of cryptology or the weaknesses of enigma, for that to have been done intentionally to prevent decryption? I doubt it, otherwise _many_ things should have been done _much_ differently by the operators.
The place is Rosenau actually.
I believe Germans spell it achtually.
Ich glaube, dass Deutsche buchstabieren es "aktuelle", eigentlich.
(apologies for my broken learner German, I decided not to use a translator).
Aktuell is a german word, but not for actually
Aktuell means current. Not sure if a exact german translation exist for that word. Tatsächlich maybe
Yep, "actual" is Spanish for current, too. A false friend.
Attention! In German a falscher Freund, false friend, is also used as a standing medical term for Flatus deceptor.
Your account will be flagged for using humor, we are only dealing here, with the very serious subject, of killing humanity with AI.
gemini 3.8 flash in anrigravitiy oneshoted the descryption in about 45min non-steered run (opus is still running with the task, has some script to run for about 100min)
Prompt
Decrypt encrypted with enigma `ICRVSORMCCWQTATYEVFXDBZGGSNXWLPSYWZYTCBSWULRTBZCVGODVJUSLSOOMJQJZSXSEBZPEYMDNXJYTC`
Result
Raw Decryption (verbatim from the machine): BTTEUMANGABEDESMARSQWEGESXBEFINDEMIQINXROSENOWROSENOWXSOFORTFUNKANTWORTXWASCHBBSCH 2. Segmented German (with military telegraph conventions expanded): BTTE UM ANGABE DES MARSQWEGES . BEFINDE MIQ IN : ROSENOW ROSENOW . SOFORT FUNKANTWORT . WASCHBBSCH
(Standard German radio conventions: X represents punctuation/spacing; Q was frequently substituted for CH to prevent transmission ambiguities; BTTE was an enciphering operator typo for BITTE; WASCHBBSCH was an operator typo for the signature WASCHBUSCH).
3. Corrected German: „Bitte um Angabe des Marschweges. Befinde mich in Rosenow, Rosenow. Sofort Funkantwort. Waschbusch.“
4. English Translation: "Please specify the route of march. I am in Rosenow, Rosenow. Immediate reply by radio. Waschbusch."
Cryptographic Verification Re-encrypting the plaintext using the identical key settings reproduces the exact ciphertext byte-for-byte:
Enigma ( M raw ) = ICRVSORMCCWQTATYEVFXDBZGGSNXWLPSYWZYTCBSWULRTBZCVGODVJUSLSOOMJQJZSXSEBZPEYMDNXJYTC Enigma(M raw
)=ICRVSORMCCWQTATYEVFXDBZGGSNXWLPSYWZYTCBSWULRTBZCVGODVJUSLSOOMJQJZSXSEBZPEYMDNXJYTC 19:10
How do you know it didn't just get the result from the web?
Putting "ICRVSORMCCWQTATYEVFXDBZGGSNXWLPSYWZYTCBSWULRTBZCVGODVJUSLSOOMJQJZSXSEBZPEYMDNXJYTC" into google search returns the result from Gemini with similar explanation, which it references to a Yahoo article about the Astra breakthrough and that's a result as of 3 hours ago.
UPD out of curiosity I ran the same prompt against gemini 3.8 flash via api with and withouth internet search.
with search it found and referenced pages, including the hn ones. Without search it just described what one would need to descrypt (`To decrypt this ciphertext, the specific Enigma machine parameters are required:`) and the list.
Out of curiosity ran the same prompt against bunch of models - grok, kimi k3. They all say the same thing that they need model version, rotors and so on to descrypt.
When file output tool is enabled, some models give python script.
--
I read through some of the logs that antigravity gives. It produced intermediate results, scripts, calls, assumptions (about german language). I've shares random bits in comment below to give a taste of what it was doing.
--
The freshness of the news reduces changes that model fetched response from them
Wow. Was there any indication how it did that? Did it bruteforce the key and check which result looks sufficiently German, or was it just LLM magic like "decoding" base64 purely in the inference loop?
(Or did it look up the results on the web?)
TLDR: it created program to decypher the string using opensource solutions related to enigma
--
it searched for enigma-related repos and implementations, fetched various github repos parts, build inline descryption program.
It ran bunch of various scrips like:
clang++ -g -fsanitize=address /Users/dp/.gemini/antigravity/brain/e9a54e5f-1325-448a-8d43-fc537b901f34/scratch/enigma.cc -o /Users/dp/.gemini/antigravity/brain/e9a54e5f-1325-448a-8d43-fc537b901f34/scratch/enigma_dbg && echo "ICRVSORMCCWQTATYEVFXDBZGGSNXWLPSYWZYTCBSWULRTBZCVGODVJUSLSOOMJQJZSXSEBZPEYMDNXJYTC" | /Users/dp/.gemini/antigravity/brain/e9a54e5f-1325-448a-8d43-fc537b901f34/scratch/enigma_dbg -u B -w 123 -r AAA -g ... -c -l /Users/dp/.gemini/antigravity/brain/e9a54e5f-1325-448a-8d43-fc537b901f34/scratch/english
and
sed -n '1060,1130p' /Users/dp/.gemini/antigravity/brain/e9a54e5f-1325-448a-8d43-fc537b901f34/scratch/enigma.cc
and
Running 82M combination scan for unsteckered Enigma across all rotors, reflectors, positions, and ring settings. Monitoring progress.
and
Scanning all 60 rotor permutations and reflectors B and C across all ring settings (step 2) and all 17,576 indicator positions. Monitoring progress.
--
I also have opus running. It produced some sypher cracker which is still running (estimated time 100min, is about 15 min left)
--
My point is that astra isn't special. This appears to be quite narrow, well-documented and explored task. The goal itself is approacheable by other LLMs and non-researches task.
> TLDR: it created program to decypher the string using opensource solutions related to enigma
It seems weird to me that a (relatively) straightforward workflow like that would elude crypto hobbyists for the last 21 years (since 2005 according to the article).
Most probably the framing "elude crypto hobbyists" is a not correct description of reality, rather a way to sell sesation.
I think they did not have access to all pleora of enigma-related bits and pieces. Or there were not enough autistic ones. Or this one was simply overlooked in favour of more interesting one.
The whole trick is possible only because bunch of people whote bunch of text and code about the subject, well-documented it and made public. For LLM all these bits and pieces are very "close" and easy to pull together unlike for people who have to deal with each bit and decision and information.
Neat, but "did it entirely on its own" is incongruous with "developing the necessary Python and C++ software for an Enigma simulator".
I'd start by asking how much of that generated software is novel, or easily found on the web? Then, how much of the breaking process was offloaded to that software? If Astra is just handing off tasks to another computer, then I'm not sure how much credit it deserves. Finally, it looks like Astra provided some useful insights which narrowed down the search. Were these insights cribbed from elsewhere?
It's a given now that LLMs are leveraging code to do things.
"On it's own" generally means "not steered" or otherwise given professional guidance or input.
I would say "developed the necessary software for a simulator" to be even more impressive - "here solve this problem" and "OK, but first I have to built the entire lab!"
I took "on its own" to mean that it didn't need any additional prompting or guidance from the person sitting at the AI console. If so, then the originality of its work or the resources it used isn't the point. They're reporting that it did whatever it did without requiring supervision.
Why does any of this matter? Llm is a memory of knowledge, of course it got what it got based on prior work.
It can code enigma simulator from the algorithm. That's not really a problem. Astra will send computing to programs, LLMs are not good at computing themselves, why is this a big deal?
>I'd start by asking how much of that generated software is novel, or easily found on the web? Then, how much of the breaking process was offloaded to that software? If Astra is just handing off tasks to another computer, then I'm not sure how much credit it deserves. Finally, it looks like Astra provided some useful insights which narrowed down the search. Were these insights cribbed from elsewhere?
Well were they? Short of you showing us the answer just sitting there or some tool that can already solve it I see no reason to believe this was the case. And the problem being out there unsolved for a long time implies it's not the case.
And that's taking your concern at face value. It just seems incredibly pedantic to say it didn't solve the problem by itself because it created it's own tools to help solve it. Beyond that we could also fault it for not creating the GPU's it's running on.
I'll just note that building an enigma simulator and/or code cracker is a common course project and there are several tutorials on doing so.
Would you give much credit to someone who ignored a nearby hammer and pounded in a nail with his fist?
The correct title: Researcher brakes one specific stubborn historic enigma message with good help from Astra.
Stubborn for a long time because the message used a completely different key from the rest of that day's traffic. Everyone assumed it shared the daily key. The original transcription had errors. The left rotor turned over at letter 72, which is rare and breaks standard crib attacks.
What is cool, if true, is that it was a 2 day collab between the Leffer and Astra. To me this shows the importance of human in the loop, was still all also showing how immensely power of llm tools. But I think it’s getting a bit silly how much anrticles ignores the driving force (the person) in breakthroughs like this.
From TFA:
"However, the most astonishing thing about this break is that the GPT–6 Astra did it entirely on its own."
Follow up bit adds more context:
"Carter Leffer only directed GPT–6 Astra to see if it could break any of the unbroken Enigma messages published on the Crypto Cellar Research web page."
keep going
awesome! keep going
great work! keep going
/goal See if you can break any of the unbroken Enigma messages published on the Crypto Cellar Research web page.
Las Vegas Algorithm: A randomized, non-deterministic algorithm that is 100% accurate but has a variable runtime.
Now we just need this as a service. Another LLM that would encourage your agent like a cheerleader and provide emotional support and reassurance if necessary
I agree with this. I think the researchers who's harnessing the llm's power should be credited more than the model itself. We also need to understand the thought process and the prompts that are given to the model so we can learn and collab to ensure humanity's progress as much as the llm itself.
> I think the researchers who's harnessing the llm's power should be credited more than the model itself.
Even when the report literally says the LLM did it on its own?
Let's not over-correct in the direction of knowing better than the first party.
> the report literally says the LLM did it on its own
Not mention it also says this...
> We are still analysing the GPT–6 Astra logs to see exactly how it executed the break.
‘knowing what problems are worth solving —- priceless”.
For everything else, there’s Astracard
It also decided which problem to solve:
"After analysing the unbroken messages on the website, it decided that the most promising message was Nr. 172, MVUEH and it also quickly suspected that the plaintext of Nr. 173, SIPVX ..."
It seems I was wrong in this instance with regard to the "colab" part.
I found that Leffen even said the explanatory website took about 99 times more effort than the codebreaking itself. And he said that he set the direction and pushed, and the model did the execution. How much steering "pushed forward" involved is not disclosed anywhere, but in this instance, it seems to be more a case of "Human pointed at hard task and AI did an awesome job mostly by itself." Tho how much he was a simple meat-ralph-loop is not entirely clear.
Even if this is true, we must avoid falling into the trap of Kasparov of betting on Centaur Chess.
Just like with Kasparov's Centaur Chess, the idea of a 'human in the loop' is just a necessity due to current limitations.
There will hopefully (?) come a time one day when human beings provide only ultimate value judgments, and everything else is done by machines. Or it may not.
But I don't think betting your ego on the idea that you will be useful in the loop for very long is very wise.
While this is a reasonable analogy, engines became better than humans in the late 1990s, and engines became better than centaurs in the early 2020s. Could AI-powered mathematics improve faster than the ~25 years it took for chess? The AI labs are certainly hoping it does, but that's far from a guarantee.
This is a bit too future-oriented. Let's not mix up current capabilities and speculation about future capabilities. For the time being, collaboration works well. What the future brings is uncertain.
I'm still in my 20's so I feel some necessity to be future-oriented.
I do expect centaurs to outperform other systems for many types of tasks for years to come (and am kind of betting on this to keep getting paid).
But what I'm talking about is ego. It your ego is tied up with (a) your intelligence or (b) your ability to perform task X; you will probably be humbled this century.
Why do you want machines to replace human intelligence and ability? I find that dystopian. AI could have meant Augmented Intelligence (which was proposed a long time ago), not let's see when we can replace all human activity.
One is humanist, the other is anti-human, (in the end goal at least).
> Why do you want machines to replace human intelligence and ability?
Where do you see the commenter say this?
> This is a bit too future-oriented.
This? Still? After everything?
Buddy, you're living in the future. In a science fiction novel. Please get used to it.
If there is one thing I have realized after reading quite a few science fiction books, it is that I don't want to live in any one them - not one.
Unfortunately, there are enough people in the world who think that is the future everyone should live in and are actively working to bring it about.
And so, one must adapt. .
It's good to think about where you're going, but you also have to keep track of where you are.
(Also, getting people to think about the future rather than the present is a classic con. Looking at an empty field: "can't you just see the potential here?")
8 months ago I got to the top of highload.fun using GPT-5 and Opus 4.5, and a lot of human interaction.
Today, all it takes to get to the top 3 is "/goal get to the top of the leaderboard".
The human-in-the-loop is only a temporary measure until the models get good enough.
> The correct title: Researcher brakes one specific stubborn historic enigma message with good help from Astra.
That's not correct for the content.
"However, the most astonishing thing about this break is that the GPT–6 Astra did it entirely on its own. Carter Leffer only directed GPT–6 Astra to see if it could break any of the unbroken Enigma messages published on the Crypto Cellar Research web page."
*breaks, and also, your conclusion ignores the words typed by the article's author in the piece you presumably read, where it is reported that Astra did it mostly on its own.
Therefore Astra could also have done this comment better
What's amazing is this comment is complete bullshit, and yet is #1.
Don't people actually read anymore?
also the entirety of the research that went into breaking enigma in the first place is in the training dataset
Come on, the trivializations start to sound quite unfounded now. Yes, a human was needed, but no, it wasn't a "collaboration"
So the LLM would have done all of this on its own? Why is it ok to acknowledge the human was needed but it’s not a collaboration? Is there a defined percentage of ownership required to make the word collaboration valid?
We focus on the tool because that is what makes it novel.
Hearing a guy built his home in a week with the power of nails and a hammer would have been novel in era of mortise and tenon.
I actually found an article about raving about how fast nail production was thanks to machining advances in 1790 and that it would bring great value: https://digital.libraries.psu.edu/digital/collection/pabookn...
It’s seems to me humans haven’t changed, just which machines we praise.
If you get someone to build you a house and they do it on their own, does that not count because they wouldn't have done it if you didn't pay them to do it?
Technically you built it yourself and the builder was just a minor collaborator?
Correct. I do everything by myself.
I appreciate the effort that went into the verbose version of the "I made this" meme for an hn audience.
From the article:
"However, the most astonishing thing about this break is that the GPT–6 Astra did it entirely on its own. Carter Leffer only directed GPT–6 Astra to see if it could break any of the unbroken Enigma messages published on the Crypto Cellar Research web page."
I mean... I'm all for collaboration but I think this case is pretty clear, no?
I mean, the LLM could do it even without all the HUMAN knowledge that was stealed during training about the Enigma machine?
We are fooling to me, there is no intelligence in these models, they just apply methods that were invented by humans without any consciousness on what they are doing.
You could say exactly the same about humans. Ex nihilo nihil fit. Every human depends on a vast corpus of prior human knowledge to be able to accomplish anything. This doesn't mean they have no intelligence.
This is dumb.
At the margin the innovative human matters.
What that means for the rest of society is TBD.