# A coded sculpture at CIA headquarters hides a message no one has cracked

**No verdict.** Not a conspiracy but a genuine unsolved cipher. Three of the sculpture's four encrypted passages (K1-K3) were broken decades ago; the fourth, K4's 97 characters, has resisted every public attempt for more than 30 years. In 2025 the artist's own solution turned up in his archived papers and was sold at auction, but the winning bidder and the researchers who saw it agreed to keep it secret, so the cipher itself remains unbroken and the message unknown.

Category: Government & Intelligence · Era: Installed 1990; K4 still open in 2026 · First circulated: Dedicated November 3, 1990, on the grounds of CIA headquarters in Langley, Virginia · Believed by: Professional cryptanalysts, NSA and CIA codebreakers, and a large community of amateur solvers coordinated through Elonka Dunin's long-running Kryptos site
URL: https://theconspiratory.com/theory/kryptos

## Summary
Kryptos is a curved copper screen, sculpted by artist Jim Sanborn and installed in 1990 in a courtyard at CIA headquarters, whose surface is punched with roughly 865 characters of ciphertext in four sections. Three were solved by the mid-to-late 1990s and reveal poetic and archaeological passages. The fourth, 97 characters beginning OBKR, has never been publicly cracked. Over the years Sanborn has released a handful of plaintext clues, and in 2025 he auctioned the solution itself, yet the message remains one of the world's most famous unsolved codes.

## The claim
That the fourth and final section of the Kryptos sculpture, K4, encodes a specific, meaningful message that has withstood more than three decades of attack by the world's best cryptanalysts, and that the artist's released clues (BERLIN, CLOCK, and EAST NORTHEAST) narrow the answer without giving it away.

## Origin and timeline
- 1988: Sculptor Jim Sanborn wins the commission for an artwork at the new CIA headquarters building. He works with Ed Scheidt, the recently retired chairman of the CIA's cryptographic center, who teaches him the cipher systems Sanborn will adapt for the piece.
- 1990-11-03: Kryptos is dedicated in a courtyard of the George Bush Center for Intelligence in Langley, Virginia. Its S-shaped copper screen carries four encrypted passages, labeled K1 through K4, alongside a Vigenere tableau.
- 1992: A small team inside the NSA, later identified as including Ken Miller and Dennis McDaniels, quietly solves passages K1, K2, and K3. The work stays classified and is not disclosed for years.
- 1998: CIA analyst David Stein solves the same three passages by hand, using pencil-and-paper cryptanalysis over many months. His account circulates only within the intelligence community at the time.
- 1999: Computer scientist Jim Gillogly announces publicly that he has cracked K1, K2, and K3 using a computer, making him the first person to reveal the solutions outside government. The CIA then confirms Stein's earlier internal break.
- 2010-11: Frustrated by slow progress, Sanborn gives The New York Times his first K4 clue: the ciphertext letters NYPVTT at positions 64-69 decrypt to BERLIN.
- 2014-11: Sanborn releases a second clue, reported in Wired and the Times: positions 70-74 (MZFPK) decrypt to CLOCK, so the passage contains the phrase BERLIN CLOCK.
- 2020-01: A third clue: positions 26-34 decrypt to NORTHEAST (with EAST at 22-25), giving the fragment EAST NORTHEAST. Sanborn also warns that even a full decryption of K4 will only reveal a further riddle.
- 2025-11-20: After his 80th-birthday announcement that he would sell the answer, Sanborn's Kryptos archive - including the K4 solution - is auctioned by RR Auction for $962,500 to an anonymous buyer. Weeks earlier, researchers had found the plaintext among his donated papers rather than by breaking the cipher; all parties agreed to keep it secret, and K4 stays unsolved as a cryptographic challenge.

## The evidence, claim by claim
- Claim: K4 is a real, solvable cipher with a definite message, not decorative gibberish - the first three sections prove Sanborn embeds genuine plaintext.
  Evidence: This is well supported. K1, K2, and K3 all decrypt to coherent English and were independently broken by the NSA (1992), CIA analyst David Stein (1998), and Jim Gillogly (1999). Sanborn has repeatedly confirmed K4 contains a message, and in 2025 an actual plaintext solution existed in his papers and was sold at auction. What remains genuinely open is not whether K4 says something, but what it says and by what system it is enciphered.
- Claim: The released clues - BERLIN, CLOCK, and EAST NORTHEAST - should let solvers reconstruct the underlying cipher and finish the job.
  Evidence: The clues are confirmed by Sanborn himself: NYPVTT (64-69) equals BERLIN, MZFPK (70-74) equals CLOCK, and positions 22-34 give EAST NORTHEAST. Yet knowing four plaintext-to-ciphertext mappings has not revealed the encryption scheme. Unlike K1-K3, which used a keyed Vigenere and a columnar transposition, K4 does not yield to any published classical or masking technique tested against those cribs. The cribs constrain the answer without exposing the method, which is precisely why the passage has held.
- Claim: The deliberate misspellings in the solved sections - IQLUSION, UNDERGRUUND, DESPARATLY - are hidden signposts to the K4 method.
  Evidence: The misspellings are real and intentional. K1 ends on the misspelled IQLUSION (illusion), K2 contains UNDERGRUUND (underground), and K3's Howard Carter passage opens SLOWLY DESPARATLY (desperately). Solvers have long theorized these encode a second-layer clue. But Sanborn has never confirmed that reading, and after thirty years no proposed use of the misspellings has produced K4's plaintext. They remain a suggestive pattern, not a demonstrated key.
- Claim: K4 was finally solved in 2025, so the mystery is effectively over.
  Evidence: This overstates what happened. In 2025 two researchers, writer Jarett Kobek and journalist Richard Byrne, located the K4 plaintext among Sanborn's papers held at the Smithsonian's Archives of American Art - they read the answer, they did not break the code. The archive was sealed, and the solution was auctioned to a private buyer who pledged to keep it hidden. No one has publicly deciphered K4 from the ciphertext alone, so as an open cryptographic puzzle it is exactly where it was, minus a few people who now quietly know the answer.

## Why people believe it
- Verifiable success breeds confidence: because K1, K2, and K3 are checkably real and were broken by named people, the belief that K4 is equally solvable feels like sober extrapolation rather than wishful thinking. The puzzle has a proven track record of rewarding effort.
- The setting supplies irresistible mystique. A code that has stumped cryptanalysts sits in a courtyard at CIA headquarters, made in collaboration with a retired CIA cipher chief - the implication that a secret is hiding in plain sight at the center of American intelligence gives the puzzle a gravity no ordinary artwork would have.
- Sanborn's slow drip of clues keeps hope permanently fresh. Each new hint - BERLIN, then CLOCK, then EAST NORTHEAST - revives the community, narrows the search space just enough to feel like progress, and signals that the artist wants the puzzle solved, not merely admired.
- The prize is pure prestige. Whoever cracks K4 from the ciphertext will be remembered as the person who read the last message of the world's most famous unsolved code - an enormous status reward that guarantees a steady supply of obsessive amateur solvers even now that a private answer exists.

## Open questions
- What does K4 actually say? Ninety-seven characters beginning OBKR encode something Sanborn insists is meaningful, and his BERLIN CLOCK and EAST NORTHEAST cribs suggest a scene rooted in Cold War Berlin, but the full plaintext has never been made public and is now held privately by an anonymous buyer.
- What cipher system does K4 use? K1 and K2 used a keyed Vigenere, K3 a columnar transposition - all classical methods. K4 resists every published technique even when tested against Sanborn's confirmed cribs, implying either a masking layer, a hand modification, or a system solvers have not yet guessed.
- Do the deliberate misspellings and the sculpture's other anomalies encode a second-layer key to K4, or are they misdirection? Thirty years of theories have not turned IQLUSION, UNDERGRUUND, and DESPARATLY into a working method.
- If K4 is decrypted, is there a further puzzle? Sanborn has stated that solving K4 only produces another riddle, meaning even a correct plaintext may not end the mystery - a claim that cannot be evaluated until the message is public.

## Sources
- Kryptos, Wikipedia: https://en.wikipedia.org/wiki/Kryptos
- "Kryptos" Sculpture, Central Intelligence Agency: https://www.cia.gov/legacy/headquarters/kryptos-sculpture/
- Elonka's Kryptos Page, Elonka Dunin: https://elonka.com/kryptos/
- Finally, a New Clue to Solve the CIA's Mysterious Kryptos Sculpture, Kim Zetter, Wired (2014): https://www.wired.com/2014/11/second-kryptos-clue/
- New Clue May Be the Key to Cracking CIA Sculpture's Final Puzzling Passage, Smithsonian Magazine (2020): https://www.smithsonianmag.com/smart-news/third-and-final-clue-released-ci-sculptures-last-puzzling-passage-180974102/
- A Solution to the CIA's Kryptos Code Is Found after 35 Years, Scientific American (2025): https://www.scientificamerican.com/article/a-solution-to-the-cias-kryptos-code-is-found-after-35-years/
- Secret Code to the CIA's Enigmatic 'Kryptos' Sculpture Sells for Nearly $1 Million at Auction, Artnet News (2025): https://news.artnet.com/art-world/cia-kryptos-sculpture-code-auction-2677451

Rated by The Conspiratory, a neutral, sourced encyclopedia of conspiracy theories. Full page: https://theconspiratory.com/theory/kryptos