MVUEHA CRYPTANALYSIS CASE STUDY

RECOVERING A MESSAGE FROM 1941

How we recovered a 1941 Enigma message

On 10 July 1941, a German Army radio message asked for a route of march and an immediate reply. Over two days, we investigated its surviving copies, recovered the machine settings and checked the resulting text.

RECONSTRUCTED CIPHERTEXT0 / 82

Every revealed letter is calculated with the recovered key.

The key explains all 82 reconstructed body letters and the independent header. The source comparison preserves how uncertain letters were handled. See the evidence and its limits ↓

MESSAGE MVUEHCORPUS CryptoCellar / WeierudINVESTIGATION 14–15 September 2026BODY + HEADER VERIFIED

01 / SEND A SECRET

How Enigma protected messages sent over radio

Radio carried orders quickly across long distances, but an enemy could listen to the same transmissions. Operators encrypted their messages before sending them so that an intercepted signal would not reveal the orders.

Enigma transformed the message into encrypted letters, which a radio operator could transmit using Morse code. Anyone who knew Morse could write down those letters, but reading the message still required the Enigma settings.

01 / SENDER A

The sender encrypts the message

MELDUNGANGEKOMMEN

The indicator will carry an encrypted message start.

02 / ON THE AIR · ALSO HEARD BY AN INTERCEPTOR

The radio operator transmits the encrypted letters

Waiting for transmission.

0 letters sent
03 / RECEIVER B

The receiver recovers the original message

Waiting for the message.

Both ends need the same daily key.

This training exchange uses invented text and runs entirely in your browser. Replies use LAM as a new demonstration starting position.

How did both operators know the settings?

Daily key material specified the rotor order, ring settings, and plugboard. For this 1941 procedure, the sender chose a three-letter message start, encrypted it at an openly transmitted three-letter starting position, then reset the windows for the body. The receiver reversed those steps with the same daily key.

MVUEH records GTA / KCI. At GTA, the daily key turns KCI into RWD. The body then starts at RWD. The daily key itself is not sent in this header. Different periods and networks used different procedures.

Read Sullivan & Weierud’s account of the procedure ↗

02 / INSIDE ENIGMA I

How the machine transforms each letter you type

When you press a key, the wheels move and an electrical current travels through the machine to light an output letter. You can follow that process here, then use the recovered settings to read MVUEH yourself.

ENIGMA I / REFLECTOR B
01 / DECODE THE HEADER0 / 3

Recover the starting position from the header

The recorded header is GTA / KCI. Set the windows to GTA and type KCI to recover the body’s starting position.

IIG
VT
IIIA

Windows before the next keypress · rings H M F

KEY IN
LAMP OUT

The machine is ready, and its wheels will step before each letter is transformed.

Change the machine settings

Changing settings starts a new free experiment. Reflector B and the standard entry wheel remain fixed.

HEADER / CIPHERTEXT

RECOVERED START

The five-letter identifier MVUEH is not encrypted body text.

FOLLOW THE ELECTRIC CURRENT

Follow the current through the machine and back to the lamp

Press Next letter to see every substitution. Gold travels toward the reflector; blue returns to the lamp.

WHY WAS IT SO HARD TO BREAK?

Why changing a single setting changes the decoded message

The letter wheels, ring offsets, and plug pairs all shape the result. The right key must explain an entire message and its independent header.

Try changing the right ring from F to G while keeping the body start at RWD.

Our modern attack used the repeated name ROSENOWROSENOW as a guessed phrase. It constrained possible settings; the surrounding 68 letters and recorded header tested the result. This demonstration replays the recovery; it does not run the original search.

This educational 3D cutaway uses simplified dimensions and illustrative circuit routes. Substitutions, rotor stepping, ring offsets, and plugboard behavior are computed by the simulator. Gold-underlined body letters mark source uncertainty, not machine errors. Exhibit guide & validation ↗ · Wiring reference ↗

03 / BEFORE THIS MESSAGE

How Enigma developed and how cryptanalysts learned to break it

1918–1923

Scherbius and the commercial Enigma

Arthur Scherbius developed Enigma during a wider wave of independent rotor-machine inventions. Commercial Enigma machines were demonstrated in 1923; the earliest models were different from the military machine shown here.

Kruh & Deavours, The Commercial Enigma ↗
THE MILITARY MACHINE

How the military adapted Enigma to protect its messages

German military Enigma added a plugboard and used controlled key procedures. Our exhibit models Enigma I with three rotors chosen from five and reflector B. The mechanical design could be known; the changing settings were supposed to protect the traffic.

Crypto Museum, how Enigma works ↗
1932–1939

How Polish mathematicians solved military Enigma

Marian Rejewski first solved military Enigma in 1932. He, Jerzy Różycki, and Henryk Zygalski developed methods against its changing keys. In July 1939, the Polish team shared its achievements with British and French counterparts.

Enigma Cipher Centre ↗ · GCHQ, the Pyry meeting ↗
1940 ONWARD

How people and machines worked together at Bletchley Park

At Bletchley Park, Alan Turing and Gordon Welchman helped develop the British Bombe. Interception, guessed phrases, machines, operators, and analysts all contributed to recovering changing keys.

The National Museum of Computing, the Bombe ↗
2026 / THIS INVESTIGATION

Recovering one surviving dispatch

We used modern computation and the work of earlier historians and cryptanalysts to recover this one message. This is not the original breaking of Enigma, and no first-ever or corpus-wide breakthrough is claimed.

04 / THE INVESTIGATION · SOURCE

Why reading the original document was part of solving the cipher

Received message 172
Outgoing copy NF 88/61
Prepared 12:20 · Received 17:30

Before we could test machine settings, we had to account for uncertainty in the surviving handwriting.

MVUEH is an authentic 1941 message in the German Army Enigma corpus. Its 82-letter encrypted body survives in a published received transcription and a faint outgoing facsimile. The two copies disagree at some positions, and a single wrong character can make a promising key look wrong.

We chose this message for its combination of a second copy, a recorded header, nearby recovered keys, and related solved traffic. It gave us several kinds of evidence to test against one another.

The short length made language scoring fragile. Even with a trusted header, the standard machine model has approximately 159 quintillion daily configurations before applying other constraints. More brute force alone was not a useful plan.

At our 14 September 2026 check, the corpus still listed this message as “Fails.” Corpus record ↗

ARCHIVE / NF 88–6110.07.1941
Original outgoing MVUEH ciphertext: faint handwritten letters on a squared German radio message form.
01 / THE SOURCE

This detail from the outgoing facsimile is preserved in the CryptoCellar corpus, where faint strokes make several letters difficult to distinguish.

View the original archival document
RECOVERED KEYII · V · IIIHMF / RWD

ACCOUNTING FOR UNCERTAIN HANDWRITING

How we tested alternative readings of the handwriting

We recorded alternative letters before finding the key. The final reading changed just three positions from the earlier native transcription.

POSITION 27

M N

Outside the guessed phrase
POSITION 43

R L

Inside the guessed phrase
POSITION 47

T Z

Inside the guessed phrase

There are eight differences from the separately published received transcription. Every selected letter was allowed before discovery. Image enhancement aided inspection; generated strokes were never treated as source evidence. Read the full comparison.

THE RECOVERED MESSAGE

82 LETTERS RECOVERED

The message asks for a route of march and an immediate radio reply

“Please specify the route of march.
I am in Rosenow, Rosenow.
Immediate reply by radio.”

This approximate English translation is followed in the original by a signature tentatively read as Waschbusch.

The sender reports being in Rosenow and asks for instructions about where to go next.

The literal German, including its errors

BTTE UM ANGABE DES MARSQWEGES X
BEFINDE MIQ IN X ROSENOW ROSENOW X
SOFORT FUNKANTWORT X WASCHBBSCH

Spaces are added for reading. Q expands to CH in MARSQWEGES and MIQ; X is a separator. The literal text says BTTE and WASCHBBSCH. Restoring “Bitte” and “Waschbusch” is editorial interpretation, and is not part of the exact encryption check.

The recovered machine settings

ENIGMA I · REFLECTOR B
ROTOR ORDER · LEFT TO RIGHTII – V – III
RINGS · A = 01H M F08 / 13 / 06
BODY START · BEFORE FIRST PRESSR W D
PLUGBOARD PAIRS

AC  BE  DG  FH  KN  MO  PR  SU  TV  XZ

04 / THE INVESTIGATION · METHOD

How we used experiments to recover the message and its key

The breakthrough came from changing the search, while keeping the evidence fixed.

This was a researcher-led investigation with GPT-6 Astra and parallel specialist agents. The researcher set the goal and pushed the investigation forward. Agents examined sources, built search programs, ran controlled experiments, and challenged the results.

Historical context gave us hypotheses to test with search programs, and separate implementations checked the resulting key and plaintext.

Across 14–15 September 2026, source work, search development and review overlapped. These six stages show how the evidence changed our next experiment.

  1. 01

    We preserved the uncertain letters before searching

    The faint outgoing form and published received transcription differed. We adjusted the original scan’s tones and recorded twelve uncertain positions as finite alternatives before finding the key.

    Position 27M or N12 uncertain positions · 13,824 permitted readings

    What this changed: The search could choose a recorded letter, but could not insert a new one to improve a promising answer.

    Inspect the source-reading record ↗
  2. 02

    Unsuccessful experiments made us question our assumptions

    The two known same-day keys did not produce a readable message. Cable-setting hypotheses and suggested phrases also failed. Early hillclimbers missed known answers even with some correct settings supplied, so we improved the controls before trusting a larger search.

    • Known same-day keysNo accepted message
    • Cable-setting hypothesesNo accepted message
    • Early hillclimbing controlsInsufficient recovery

    What this changed: A German-looking fragment was not enough. Each method needed to recover known messages under its declared conditions.

    Read the controls and unsuccessful experiments ↗
  3. 03

    A related message supplied a phrase we could test

    The solved message SIPVX contains ROSENOWROSENOW. We treated those fourteen letters as a possible plaintext phrase, or crib, and searched its possible placements while solving for rotor behavior and an unknown plugboard. The successful discovery search did not use the recorded header.

    ROSENOWROSENOW14 letters supplied · 68 surrounding letters not imposed

    What this changed: The crib supplied constraints. It did not supply the remaining message, plugboard, physical rings or message start.

    Inspect the winning search inputs ↗
  4. 04

    One candidate explained the words around the guessed phrase

    At positions 40–53, rotor order II–V–III produced the repeated name inside a connected request for a route of march and an immediate radio reply. We retained the literal BTTE and WASCHBBSCH rather than editing them into the encryption check.

    Recovered language outside the cribSOFORT FUNKANTWORT“Immediate reply by radio”

    What this changed: The surrounding 68 letters supplied a language test beyond the phrase required by the search.

    Compare literal output and editorial reading ↗
  5. 05

    The recorded header identified the physical settings

    Twenty-six ring and starting settings preserve the recovered body behavior. Only HMF / RWD also agrees with the recorded GTA / KCI header within that family. Separate scalar and Py-Enigma implementations then reproduced the full body and header in both directions.

    26 body-equivalent settingsGTA: KCI ⇄ RWDHMF / RWD

    What this changed: The header settled a body ambiguity. Across the complete declared domain, 923 physical keys match the header, so the header alone does not prove a unique historical answer.

    Inspect the physical-setting comparison ↗
  6. 06

    We retained the competitors and checked the complete declared search

    All 43,016 batches in the repeated-name search were accounted for, including candidate families needing extra enumeration. The recovered message ranked first when scoring excluded the crib. A clean rebuild reproduced all 49 records from the winning batch.

    43,016 declared batches97,337 distinct body keys retained923 physical keys matching the header

    What this changed: The code and competing candidates are available for independent inspection. Completion applies to the stated model, source alternatives and crib.

    Read the completed search and audit ↗

TRY THE INVESTIGATOR’S CONSTRAINTS

Explore how source readings and a guessed phrase constrain the search

Because an Enigma letter can never encrypt to itself, some alignments can be rejected immediately. Surviving this test is only a necessary condition; the original search also had to satisfy all rotor and plugboard constraints. Here the test uses the preferred reconstructed ciphertext.

What was guessed, and what was recovered?

14 letters imposed: ROSENOWROSENOW at positions 40–53.

68 surrounding letters not imposed:

The surrounding message supplied a stronger language test than the guessed phrase itself. The separately recorded header then selected HMF / RWD from 26 equivalent body settings.

THE WORK BEHIND THE INVESTIGATION

The investigation took place over two days

On 14 and 15 September 2026, the researcher and agents worked through source comparison, machine reconstruction, unsuccessful experiments, key recovery and independent verification. The investigation combined historical research with parallel computer searches and a full review of the candidates those searches produced.

2 daysFrom source investigation through recovery and verification
43,016Search batches completed within the declared scope
97,337Distinct candidate body keys retained for review
14.8mPhysical keys independently checked against the recorded header

The completed search covered about 4.29 billion combinations of rotor behavior and guessed-phrase placement within the stated assumptions. Every batch and candidate family was accounted for, including the additional checks needed to distinguish the recovered key from competing settings.

The two days describe the span of the investigation. Search processes ran in parallel, and the logs do not provide a complete total for human or model reasoning hours. The reports below retain the detailed experiment timings, search boundaries and verification records.

Complete search and audit report ↗ · Search experiment records ↗ · Alternative-key experiments ↗ · Parallel controls and benchmark ↗

05 / CHECK THE ANSWER

How we checked the recovered key against the message and its header

Re-encryption checks the calculation, while the surrounding language, recorded header and source comparisons help establish that the recovered message is credible.

Any key can decrypt ciphertext into some output and encrypt it back again. Our result combines connected language outside the crib, an independently recorded header, and source-letter alternatives fixed before discovery.

Separate scalar and Py-Enigma implementations reproduced the complete preferred body and the header in both directions. The original winning search batch was rebuilt outside the research workspace, reproducing all 49 output records byte for byte. The complete evidence bundle also passed an independent check from a fresh directory, covering all 43,016 search batches, every retained candidate and the two candidate families that required additional enumeration.

COMPARE THE LETTERS WITH THEIR SOURCE

See how a recorded reading changes the plaintext

The received transcription and the outgoing sheet are separate records. Select one of the twelve search-variable positions to inspect the recorded choices under the recovered key.

Original outgoing ciphertext, with a guide indicating the row of the selected letter.
Open the source image at full size ↗
Recorded search alternatives

The row guide locates context, not a certain glyph reading. These finite choices were recorded before discovery; two selected letters, 37T and 44R, came from an existing transcription branch rather than the fresh visual reader’s sets. Selecting a letter changes the calculation, never the archival image.

See all literal output and the phrase supplied to the search

The colored, bracketed phrase is the fourteen-letter crib. The other 68 characters were not imposed by the discovery equations. Q represents CH and X separates phrases; BTTE and WASCHBBSCH remain the literal output.

The incoming No.172 facsimile became publicly available after our initial source review. The comparison above preserves the typed received transcription used in the original search.

TRY THE RECOVERED KEY

Check all 82 body letters and the recorded header

This page runs a small Enigma implementation with the published key. It checks the reconstructed ciphertext against the literal German, then reverses the operation. Editorial corrections are excluded.

BODY82 lettersDecrypt and re-encrypt
HEADERGTA / KCIKCI decodes to RWD at GTA
REFERENCE TESTAAAAA → BDZGOStandard Enigma test vector

The verification runs entirely in your browser when you select the button above.

14.8m14,829,646 distinct physical keys independently checked against the header
923header-compatible keys retained for full reading review
42 / 42sampled states agree with an independent SAT model

A separate search of the unchanged transcription recovered the same key

A separate experiment searched the published ciphertext without changing any letter. It used SOFORTFUNKANTWORT at positions 55–71, a phrase learned after discovery. All 1,080 batches completed: 24 body candidates gave 4,056 physical keys, and exactly one matched the original header—the recovered key.

This is an after-discovery check, with its inputs and limits disclosed. The full report retains competing keys, all permitted reading lattices, language rankings with the related SIPVX training message removed, and the independent SAT sample.

What the evidence establishes and which questions remain open

The key and reconstructed message are verified. The received scan was unavailable during the initial investigation and is now publicly linked by the corpus. The preferred body is a reconstruction within documented alternatives, rather than a claim that every faint stroke is visually certain.

The search is complete within its stated assumptions. All 43,016 batches and both candidate families requiring additional enumeration have been checked. Its assumptions remain: three distinct I–V rotors, reflector B, ten plugboard pairs, twelve finite source-letter sets, and the literal ROSENOWROSENOW crib. This does not exhaust messages or machine configurations outside those assumptions.

Some historical details remain open. “Waschbusch” is tentative, the precise Rosenow has not been established, and a particular retransmission relationship with SIPVX is unproved. The known SIPVX text helped motivate the crib; it was not a blind prediction. The public corpus has ambiguous status wording, so no world-first claim is made. Local input hashes do not establish an externally authenticated discovery timestamp.

06 / EXAMINE AND REPRODUCE THE WORK

Choose the files for what you want to check

Start with the report, verify the recovered key, rerun the original search, or explore the working exhibit. The research archives preserve their original bytes; later source updates are documented separately.

READ THE FINDINGS

Understand the result and its limits

The report explains the recovered message, the evidence supporting its key, the completed search and the remaining uncertainties.

Read or save the report
Size and format
13.7 kB · Markdown
Start with
completion-report.md
You need
A text editor or Markdown viewer

Source comparison · Later archival-source update

CHECK THE KEY

Verify the answer on your own computer

A small standalone checker tests every literal body letter and the header in both directions, along with reference examples and the recorded letter alternatives.

Download the key checker
Size and format
5,257 bytes · ZIP
Start with
README.md, then verify.py
You need
Python 3.10+; no extra packages
python3 -I verify.py

Expected result: PASS. This checks the calculation; it does not prove historical identity or unrestricted uniqueness.

RERUN THE RECOVERY SEARCH

Run the code that recovered the message

The original package contains the C++ search engine, language table, recorded inputs and all 49 results from the winning batch.

Download the recovery search
Size and format
8.6 MB · ZIP
Start with
search-reproduction/README.md
You need
Python 3 and a C++17 compiler
cd search-reproduction
python3 reproduce.py --output replay-local
python3 verification/verify.py

This replays the selected winning batch. It adds no new search coverage. The original package is the dated discovery record; the completion report accounts for the later full audit.

INSPECT THE INTERACTIVE EXHIBIT

Explore the simulator and website source

Download the Three.js model, working Enigma simulator, page source, guide and checks. The recovery search itself is in the research package beside this one.

Download the exhibit source
Size and format
About 21.3 MB · ZIP
Start with
mvueh-exhibit/README.md
You need
Python 3 to serve the files; a WebGL browser
python3 -m http.server 4173 --directory dist

Open localhost:4173 after starting the server. No build or package installation is needed. Automated tests require Node 22+.

Exhibit guide · Browser check record

Examine every declared search batch and competing candidate

The complete audit adds all 43,016 batch records, both family supplements, competing keys, independent checkers, source evidence and measured costs. It requires Python 3 and a C++17 compiler for search replays. Start with README.md in the extracted MVUEH-completion-audit folder.

134.8 MB · Code, raw records, reports and checksums

The download joins seven parts and verifies their checksums before saving.

Full reproduction instructions · Archive verification record

Manual download and checksums

Save every part, the manifest and the joining script together. Run the script with Python 3 to verify and reconstruct the ZIP.

Checksum manifest · Joining script

ENIGMA I

Follow each letter through the working Enigma

READY / THE WHEELS MOVE FIRST

Play the header or advance one letter.

KEY LAMP WINDOWS GTA

Gold shows the current traveling toward the reflector, and blue shows its return to the lamp. The routes in this educational cutaway illustrate the signal path.

Inspect & take apart