The published record
Who has looked at this, what they found, and what checks out against the primary text.
1959
David Shulman, The Cryptogram
The earliest sustained analysis, in the American Cryptogram Association's journal, in two parts thirteen years apart. Notable mainly for dating the problem: the cipher was already considered interesting and already unsolved within thirteen years of publication, and Shulman was working from the first edition while the second had already dropped it.
Wayne G. Barker, Cryptologia
The first treatment in the modern academic literature. The cipher enters the standard canon of unsolved cryptograms from here.
Nick Pelling, Cipher Mysteries
The most useful published structural analysis, and it reaches most of Section 3 independently: 196 units once the trailing zeros are dropped, a 14 × 14 grid, and the observation that the two coordinate positions draw from 67890 and 12345 respectively. He proposes a 5 × 5 keyed square combined with a 14 × 14 transposition — which is where this page ends up too.
He also flags something worth keeping: the message contains two tripled units, 75 75 75 and 63 63 63. A letter repeated three times running essentially does not occur in English. Under a transposition it is unremarkable; under any substitution-only reading it is close to disqualifying. Both are present in this transcription and both survive every check.
Klaus Schmeh, MysteryTwister challenge
Sets the cipher as a public challenge and states the mainstream position in one sentence: "D'Agapeyeff may have made a mistake during the encryption procedure, which makes it now difficult to find the cleartext."
Cipher Mysteries, after a reader called Marie — the strongest lead in the literature
Marie traced d'Agapeyeff's double-transposition section to Kerckhoffs' La Cryptographie Militaire and found that he carries the operation out in the decryption direction. Pelling's conclusion: d'Agapeyeff appears to have believed double transposition was self-inverse — that enciphering and deciphering were the same operation. His words: "his failure wasn't anything as foolish as misremembering the keyword, but instead misunderstanding one of the component ciphers."
So the man who set this challenge demonstrably could not sort a nine-letter keyword correctly, in print, in the chapter about the technique he most likely used.
His own hint about nulls
Wikipedia's article points at page 111, where d'Agapeyeff writes that inserting dummy letters "at every third, fourth, or fifth letter" makes decipherment "extremely difficult". That is a real mechanism and it would depress repeated n-grams without any transposition at all — which would have undercut most of Section 3.
Online write-ups of unverified provenance handle with care
Several recent sites present confident-sounding architectures for this cipher. The ones checked for this page offer no decrypted plaintext, no reproducible key, and in one case a claim of recovered Esperanto vocabulary with no cryptanalytic derivation shown. They are speculation, and are cited here only for two incidental observations that are checkable — and that turn out to be true.
Where the consensus sits, and where this page sits
The published view, from Schmeh explicitly and Pelling implicitly, is that d'Agapeyeff made a mistake while enciphering. This page reached the same conclusion from a different direction — E7 and E8 plus the exhaustion in Section 4 — without knowing that was the consensus. Two independent routes to the same answer is worth something.
What the 2017 finding adds is the part nobody had: a specific mechanism. Not "he forgot his keyword" but "he did not understand which direction his own transposition ran". That is a testable claim, it is corroborated by a verified bug in his own printed example, and it points at a region of the search space that this page had not touched — because every attack here assumed he ran the cipher forwards.
The single-transposition version of that idea has now been tested and fails (Section 4, last row). The double-transposition version has not, and cannot be brute-forced. That is where Section 7 starts.
Timeline
1939. Codes and Ciphers published by Oxford University Press in its Meridian series. Alexander d'Agapeyeff — a cartographer by profession, born of Russian parents, not a professional cryptologist — ends Chapter VII with the challenge on page 159.
1952. The book is reprinted and the challenge paragraph is gone. He is reported to have admitted he had forgotten how he enciphered it.
1974. Gale Research reissues the 1939 edition in facsimile. The challenge is back — and that is the edition this transcription was made from.
Since. Widely attempted, never solved. It sits on the standard lists beside the Beale papers, the Voynich manuscript and Kryptos K4. Unlike those it is short, it is certainly a cipher rather than a possible hoax, and its outer structure is completely transparent. Only the inside refuses.
Provenance of this transcription
| Source | scanned PDF of the book |
| Edition | Gale Research facsimile, Detroit 1974, of OUP London 1939 |
| Scan | Elgin Community College copy, Internet Archive |
| PDF page | 162 of 168 |
| Printed page | 159 |
| Extraction | text layer, then verified against the page image at 800–1400 dpi |
| Groups checked | 79 of 79 |
| Independent check | matches Schmeh's published text, all 395 digits |