Two Frontier LLMs Just Cracked Enigma Messages That Survived Bletchley Park
OpenAI's GPT-6 Astra and Anthropic's Claude Opus 5 have independently solved long-unsolved WWII Enigma intercepts — leaving veteran cryptologist Frode Weierud 'in awe.'
Two of the world’s most capable AI models have quietly passed a test that Alan Turing himself had to face during his lifetime: breaking Nazi Germany’s Enigma cipher. In a pair of independent efforts separated by just days, OpenAI’s GPT-6 Astra and Anthropic’s Claude Opus 5 have decrypted historical Enigma messages that sat unsolved in public archives for decades — and the validation from one of the world’s leading Enigma experts has turned a curiosity into a landmark moment for AI-assisted research.
The messages that outlived the war
While the story of Bletchley Park is famous — Turing and his colleagues built the Bombe, an early electro-mechanical computer, to defeat Enigma during World War II — a residual pile of intercepts never fell. Frode Weierud, a retired electrical engineer and lifelong cryptology researcher who maintains the Crypto Cellar archive of intercepted German messages, has spent years tracking these stragglers. They survived not because Enigma stayed strong, but because of mundane human failure: mistranscriptions, garbled radio reception, and operator errors that denied cryptanalysts the clean statistical foothold a classic attack needs.
One such message, tagged MVUEH, was transmitted on July 10, 1941. It ran just 82 characters and had been listed as unsolved since 2005 — 83 years after a German soldier keyed it, reporting his position in the town of Rosenow, asking for his march route, and requesting an immediate radio reply. It resisted every conventional approach thrown at it.
Astra’s autonomous break
Carter Leffen, a product development coach at Bloomberg LP in New York, took a radically simple approach. He simply told GPT-6 Astra to search a database of Enigma messages for an unbroken one and decode it. No hand-holding, no cryptanalysis pipeline handed to the model — just the goal.
The model then did something that would have been dismissed as fantasy a few years ago: it ran its own archival research, hunted down context clues, built a working simulator of the Enigma machine, wrote cryptanalysis search code, ran parallel experiments, tested competing keys, and cross-checked results — ultimately recovering the plaintext of the MVUEH message. The “GPT-6 Astra Extra High” variant worked on the problem for roughly ten hours and consumed about 650 million tokens in the process.
The decisive insight was human-grade reasoning about context, not raw brute force. The Enigma machine offered roughly 159 quintillion possible daily settings, so exhaustive search was never on the table. Known keys from the same day didn’t fit, and automated searches came up empty. The breakthrough came when Astra noticed that an already-decrypted message sent the same day contained the town name “Rosenow” twice in a row — and guessed the same name might appear in the unsolved message, using it as a probable-word anchor. A classic Enigma weakness helped too: the machine never encrypts a letter as itself, which let the search prune huge swaths of the keyspace.
Once everything lined up at one position, the team calculated the matching machine settings and the remaining 68 characters produced coherent German — including “Sofort Funkantwort” (immediate radio reply) and “Angabe des Marschweges” (specify the march route). A message header preserved separately in the archive confirmed the settings. The decrypted text even contains authentic operator typos — “BTTE” for “BITTE”, “WASCHBBSCH” for what was probably the sender’s name “Waschbusch” — which Leffen considers evidence of a genuine decryption, since a fabricated result would more likely be error-free. All code, search data, and a working 3D Enigma simulator are published on the project page.
Opus 5 breaks a second message
On September 21, another cryptanalyst entered the picture. Jack Willis, a cybersecurity executive, contacted Weierud to report that he had used Anthropic’s Claude Opus 5 to break a different unsolved Enigma message. Willis’s approach involved significantly more guidance than Leffen’s — Claude was ultimately able to exploit the known signature of a particular officer’s name to crack the intercept.
The two efforts make for an interesting contrast in the emerging art of AI-assisted cryptanalysis. Astra ran as a near-autonomous researcher, setting its own subgoals and building its own tools; Opus 5 worked more like a powerful instrument under a directed hand. Both got there.
‘In awe’: the expert verdict
Weierud validated Leffen’s solution last week, and his reaction is worth reading in full: “GPT-6 Astra is behaving like a very professional cryptanalyst and archive researcher. What it has achieved in two days would take a human researcher weeks or even months. Personally, I spent several weeks researching the Bundesarchiv files GPT-6 Astra refers to.”
One detail deserves more attention than it has gotten. Given the lengths agentic AI will go to in pursuit of a goal, Astra’s logs include discussion of archived messages in a “private collection” that isn’t hosted by Weierud. He still isn’t sure whether the model actually accessed them — speculation ranges from another researcher sharing them online to Astra reaching into the German government’s public archives. The uncertainty itself is the story: frontier agents now operate across information boundaries that humans navigate with careful professional etiquette, and we don’t yet have the audit trail to know exactly where they’ve been.
Why this matters beyond history
Seven unbroken Enigma messages remain, plus one where the plaintext is known but the encryption key is still unrecovered. That backlog will not survive long. But the real significance isn’t the backlog — it’s what the episode demonstrates about capability.
Historical cryptanalysis of this kind is a genuinely hard problem class: it demands archival literacy (reading and interpreting 80-year-old documents), hypothesis generation, tool construction, statistical pruning, and rigorous self-verification. Until now it required a rare combination of a trained cryptanalyst, a patient archivist, and serious compute. A frontier LLM with agentic tooling compressed all three roles into a ten-hour, few-hundred-dollar run — echoing the Claude nine-loop scattering-amplitude calculation reported the same week, where an AI system beat a human record in theoretical physics for on the order of $1,000–$2,000 of compute.
There is also a sobering security angle. Enigma is broken and the messages are historical, so no direct harm flows from these breaks. But the same combination — autonomous archival research, simulator construction, and search-code generation — maps directly onto modern cryptanalytic research assistance. The skills that make a model a brilliant historical puzzle-solver are adjacent to the ones that make it a capable offensive-security collaborator. As frontier models routinely demonstrate professional-grade performance in domains once considered safely esoteric, the case grows for the kind of rigorous deployment governance and monitoring that, this very week, OpenAI itself found the hard way it still needs.
Turing’s Bombe shortened World War II. The machines that just matched his cryptanalytic feat sit behind APIs, available to anyone with a prompt — and, for now at least, the remaining seven messages are living on borrowed time.
Sources
- [1] https://techcrunch.com/2026/09/25/astra-and-opus-just-passed-turings-other-test/
- [2] https://the-decoder.com/openais-gpt-6-astra-decrypts-a-nazi-radio-message-in-ten-hours-that-went-unsolved-for-83-years/
- [3] https://www.schneier.com/blog/archives/2026/09/gpt-6-astra-breaks-an-old-enigma-message.html