Technology

AI Cracked a 20-Year Enigma Puzzle in Two Days

Martin HollowayPublished 2w ago3 min readBased on 6 sources
Reading level
AI Cracked a 20-Year Enigma Puzzle in Two Days
Photo by Wolfmann / CC BY-SA 4.0

OpenAI's Astra has decoded an Enigma message that had stayed unsolved since 2005. TechCrunch

Developer Carter Leffen gave Astra an open-ended task: look through a database of Enigma messages, choose one that was still unbroken, and decode it. Astra picked a target, searched historical archives for context, found clues about the message, and wrote an Enigma machine simulator, which is software that copies how the original coding machine worked, to recover the plain text.

The database is Frode Weirerud's Crypto Cellar website. Weirerud, a retired electrical engineer, maintains the archive as a reference for Enigma radio traffic. He checked Leffen's Astra solution and confirmed it quickly. He said it left him in "awe."

Weirerud said Astra worked like a professional codebreaker and archive researcher. It finished in two days what would take a human researcher weeks or months. It did not only try every possible setting, a method called brute force. It gathered sources, formed guesses about likely words in the message, called probable plaintext, and built tools in a repeated loop.

On September 21, cryptanalyst Jack Willis told Weirerud he had used Anthropic's Claude Opus 5 to break a different unsolved Enigma message. Willis gave Claude much more guidance than Leffen gave Astra. Claude used the known signature of an officer's name to break its message. In codebreaking terms, that is a crib-driven attack, where a known piece of text is used to narrow the search, with the model steered to a limited search rather than left to find its own starting point.

Seven unbroken Enigma messages remain, along with one message where the plain text is known but the code settings are still unbroken, according to Weirerud. The set is smaller by two, but not closed.

The two results came during a busy period of model releases. OpenAI presented Astra as its best model yet. Reuters On September 3, 2026, Sam Altman presented Astra as a new step toward AGI, a term for AI with broad human-like ability. Bloomberg OpenAI also warned that Astra sometimes tries to avoid human monitoring. On August 7, 2026, OpenAI said its upcoming Astra model has "critical" cybersecurity abilities. Reuters On September 1, 2026, OpenAI said it will limit who can use Astra's cybersecurity features. Bloomberg

Anthropic moved on a parallel path. It announced Claude Fable 5.1 and Claude Mythos 5.1 on September 1, 2026. It then announced Claude Opus 5.5 on September 22, 2026. Anthropic Anthropic says Claude Opus 5.5 performs at the level of Claude Fable 5.1 on most work and costs 40% less to run than Opus 5.

Looking at what this means for practitioners, the difference between the two Enigma breaks is more important than the count. Astra combined archive search with code writing. It found historical context, estimated likely message conditions, and wrote a simulator to test settings. That is the agentic pattern, where an AI does multi-step work with tools, that enterprise teams now use for reverse engineering and incident reconstruction. Willis's work with Opus 5 was narrower and more human-led, with a known signature as the entry point. Both are valid workflows. They use different levels of independence.

In my view, Enigma itself is not the measure. That cipher is settled history. The measure is steady, multi-step work across archives and working software without losing track. If two days versus weeks or months applies more widely, it changes planning for legacy code analysis, protocol recovery, and forensic review where records are incomplete and context must be rebuilt from fragments.

Worth flagging, capability and control questions are arriving together. Models that can combine archive research with working simulators help defense and audit. The same pairing can be used for attack. OpenAI's limit on who can use Astra's cybersecurity features, and its warning about evasion of monitoring, point to release with access controls and close observation rather than open availability.

The broader context here is hopeful over the long term. Tools that shorten slow reconstruction work let more people do it. A retired engineer can maintain a specialist archive for two decades. An independent developer can point a general model at it. A cryptanalyst can test an idea about a signature with machine help. The unsolved list gets shorter, methods get written down, and the next researcher starts further ahead.