Evidence
Eight measurements, each with the control that makes it mean something.
The five-digit groups are packaging, not structure
Five is odd, so the alternating high/low pattern flips phase at every group boundary: group 1 reads H L H L H, group 2 reads L H L H L. The pattern belongs to the continuous stream, not to the groups. The book groups every cryptogram in fives for transmission and pads the last with nulls; that is all the fives are.
This kills the reading that first suggests itself — that 79 five-digit groups are a dictionary code, of exactly the kind the book demonstrates nine pages earlier with the groups 55381 42872 35284.
The unit is a two-digit coordinate pair
392 digits, strictly alternating {6,7,8,9} then {1,2,3,4,5}, one exception. That is a bipartite square: rows against columns, each symbol written row-then-column. Same device as Polybius' torch code on page 16 and the A–E square on page 118, with digits in place of torches and letters.
The stray zero is not a misprint — it is row five
Read the row digit as the row number plus five. Rows 1–5 then print as 6 7 8 9 10, and 10 written as a single figure is 0. That one convention explains everything at once: why row digits start at six rather than one, why the stream can be parsed without separators, and why a zero appears exactly once. It is the fifth row of the square, used once in the whole message.
The row and column totals back this up. Rows carry 40.8 · 28.6 · 20.9 · 9.2 · 0.5 per cent of the text; columns carry 23.5 · 23.0 · 21.9 · 16.8 · 14.8. Rows spread wide, columns nearly flat. That asymmetry is the fingerprint of a keyword square filled along its rows: MANCHESTER gives rows of 35.6 / 26.2 / 16.3 / 16.2 / 5.5 against columns of 26.6 / 24.4 / 19.9 / 17.8 / 11.2, and every other keyword tested behaves the same way. The last row of such a square holds the tail of the alphabet — the letters you would expect to see once, or never.
The two digits of each printed pair belong together
If a wide transposition had shuffled individual digits, the halves of each printed pair would come from unrelated letters and the two coordinates would be statistically independent. They are not: independence χ2 = 77.4 on 16 degrees of freedom. In 200,000 simulated random re-pairings of the very same digits the largest value reached was 53.2, and the fewest distinct cells was 19 where the printed text uses 18. Both statistics fall outside 200,000 draws.
This rules out wide fractionation. It does not rule out a narrow one — at width 3 or 5 the two digits of an output pair come from letters only one or two apart, which are correlated in real language. Section 4 closes that door separately, by exhaustion.
The order of the units carries no English structure at all
Hill-climbing over every assignment of the 18 units to letters, scored on English n-gram statistics: the best fit reaches −3.85. A genuine monoalphabetic cipher of the same length, through the identical solver, comes out at −3.36 and reads cleanly. The same cipher randomly shuffled scores −3.87.
The cipher is indistinguishable from its own shuffle. Whatever it is, it is not a plain substitution of English. You can reproduce this in the Workbench in about ten seconds.
The unit frequencies are odd, but not impossible
Only 18 distinct symbols where 196 letters of English typically use 22, and the top thirteen carry 95.9% against English's 86%. Measured against 21,061 real contiguous 196-letter windows of English prose rather than idealised letter frequencies, that combination occurs with probability 0.0022 — roughly one message in 450.
Unusual. Not disqualifying. An earlier version of this page put it at one in twenty thousand by drawing letters independently from a frequency table; real text repeats itself and so uses fewer distinct letters than that model expects. The correction matters, because it leaves a transposition of an ordinary English substitution fully in play — and transposition preserves frequencies.
The units have been reordered — and this one is decisive
How often a sequence repeats itself cannot be changed by any one-to-one substitution. Letters, syllables, a nomenclator of names and phrases, an invented alphabet — relabel the symbols however you like and the count of recurring pairs, triples and quadruples stays exactly the same. Only reordering moves it. So the repeat profile tests every substitution hypothesis at once.
The cipher shows 48 recurring pairs, 5 recurring triples, and no recurring quadruple. Real English of this length averages 43.3, 19.8 and 10.2. Against 21,061 real windows, P(triples this few) = 0.0036 and P(no quadruple at all) = 0.017.
Now take the same 196 units and shuffle them 20,000 times. The shuffles average 49.1 pairs, 6.0 triples, 0.4 quadruples, 0.0 five-grams. The cipher: 48, 5, 0, 0. It is not merely consistent with a random reordering of itself — it sits dead centre of it.
One loophole is worth closing explicitly, because it is the only substitution that can suppress repeats: a homophonic square, where common letters get several cells each. Spreading E across three cells does break up the repetition — but only by spreading the text over more symbols. Simulated on real English: a 36-cell homophonic grid brings recurring triples down to 5.9, matching the cipher, and in doing so uses 33 distinct symbols with only 59.5% in its top thirteen. The cipher manages 5 recurring triples while using 18 symbols with 95.9% in its top thirteen. No grid size reaches both corners at once.
Conclusion. A transposition happened, and no substitution can be the whole story — not a plain alphabet, not a syllable table however well it fitted the frequency profile, not a nomenclator, not homophones. Suppressing repetition while shrinking the alphabet is something only reordering does.
And the reordering is total — every unit moved on its own
E7 says the order was destroyed. E8 says how thoroughly, and it turns out to be the single most useful number on this page for ruling out accidents.
A reordering that moves whole blocks — two printed lines swapped by a typesetter, two five-digit groups exchanged, a chunk of the message pasted in the wrong place — leaves every n-gram inside a block completely intact. Take real English, cut it into blocks of L units, shuffle the blocks, and count what survives:
| Block size | Recurring triples | Which accident that is |
|---|---|---|
| 196 | 19.2 | nothing moved |
| 49 | 19.7 | quarters swapped |
| 25 | 18.5 | the eight printed lines reordered |
| 14 | 17.4 | |
| 5 | 13.1 | five-digit groups reordered |
| 3 | 9.4 | |
| 2 | 7.1 | |
| 1 | 5.3 | every unit moved independently |
| the cipher | 5 |
Only block size 1 gets there. Which means the disorder in this message is not an accident of printing or of handling. Swapped lines, swapped groups, a dropped unit shifting everything along — all of those leave most of the original order standing, and the measurement would see it. Whatever reordered these 196 units took them one at a time.
That is exactly what a columnar transposition does, and exactly what no typesetter's slip does.