Kryptos K4 After Plaintext Appeared Without a Decode
On this page

K4 now occupies an unusual position: its supposed destination has been authenticated, but the path to it has not been shown. That is the dividing line this article has to keep clear from the first sentence. A found plaintext can settle one question about what James Sanborn wrote, but it does not automatically settle the cryptographic question of how the 97 characters on the sculpture produce that text. The verified record lets those two facts stand together, yet the 2025 record separates the archival plaintext discovery from disclosure of the encoding method.
The official descriptions of Kryptos matter because they establish what sort of object K4 belongs to before anyone argues over whether it has been solved. The headquarters page and the museum artifact record describe a sculpture built around intelligence, materials, layout, and multiple encoded sections, but they do not present K4 as a decorative loose end. They present it as a specific fourth problem on the work itself. Once that is fixed, later claims can be tested against the sculpture's own documented structure rather than against a tempting headline. For related archive context, compare How Yale Read the Vinland and The Antikythera Mechanism's Saros Dial.
What CIA Headquarters Says Kryptos Was Built to Be
The headquarters history page begins with a concrete fact that changes the scale of the mystery: Kryptos was dedicated on November 3, 1990, and the CIA describes it as an artwork about intelligence gathering. That framing keeps the sculpture from being reduced to a puzzle board alone. It is an installation with an institutional setting and a stated theme, not merely a detached ciphertext circulating on paper. Any claim about K4 therefore begins inside a work that was created as an artwork about intelligence gathering, but the official description still keeps the cryptographic portions identifiable as separate textual problems.
The same headquarters page fixes the sculpture in material terms that matter because they belong to the documented object, not to later retellings. It lists red granite, copperplate, lodestone, petrified wood, and a compass rose among the work's components. The museum artifact record complements that by describing the copper screen as the centerpiece of a larger sculpture that also includes granite sections, a pool, and petrified wood. Those details do not decode anything, yet they establish that Kryptos is a composed environment of parts. K4 belongs to that whole installation, not to an isolated image of letters pulled free from its physical setting.
The copper screen is where the official record becomes especially precise. The headquarters page says the S-shaped screen contains 1,735 alphabetic cutouts, and it adds that the encoded side is paired with a deliberately reversed Vigenere-style tableau. That description is narrow and important. It tells us the sculpture was built with a specific visual and cryptographic arrangement rather than with an arbitrary string of characters. The museum artifact record also notes that Sanborn used several cryptographic methods. Together, those records establish complexity at the level of design, but they stop short of naming a public method for K4 itself.
What the official record refuses to blur is the status of the four sections. The headquarters page says the first three texts were cracked, while K4 is a 97-character fourth section designed to be harder. The museum artifact record agrees on the larger point by stating that cryptanalysts cracked three sections and by withholding any disclosure of K4's plaintext or encoding method. Before later discoveries enter the story, the sculpture's own institutional description already marks a boundary. Three parts belong to the category of cracked text, yet K4 is documented as the remaining deliberately harder segment.
Why the 97 Characters of K4 Stayed Apart from the First Three Texts
Once the sculpture is understood as a single artwork with multiple embedded texts, the next issue is why K4 did not simply travel with the first three solutions. The headquarters history page answers that directly by separating the three cracked texts from a fourth section of 97 characters that was designed to be harder. That wording matters because it does not describe K4 as an overlooked continuation or a missing appendix. It identifies K4 as a distinct cryptographic challenge inside the same work. The difficulty is therefore part of the recorded design, not a later myth attached to an unfinished puzzle.
The museum artifact record reinforces that separation from another angle. It says Sanborn used several cryptographic methods and notes that cryptanalysts cracked three sections, but it does not disclose K4's plaintext or its encoding method. That omission is informative precisely because the record is otherwise comfortable describing the sculpture's physical composition and institutional display. K4 is not absent because the sculpture lacks documentation; it remains apart because the official record stops where a demonstrated fourth solution would need to begin. The boundary is built into what the museum record does and does not claim.
The reversed Vigenere-style tableau on the headquarters page also sharpens the distinction without finishing it. The page documents a cryptographic environment, yet it does not say that one visible feature yields a complete explanation for K4. Readers are left with evidence of deliberate method and deliberate complication, but not with a recipe. This is an important discipline for the case. A documented tool, arrangement, or visual relation can show that the sculpture was engineered with code in mind, but it cannot be promoted into a proved solution unless the record actually states that connection for the fourth section.
So before any archival discovery enters the timeline, K4 was already standing in a category of its own: a documented 97-character section, intentionally harder than the first three, housed within a sculpture that openly mixed art and cryptography. The official pages let us say all of that with confidence, yet they do not let us say that K4 had been decoded. That leaves the next question sharply defined rather than vague. If the fourth section remained separate at the level of the official record, then the crucial issue becomes what a later archival find recovered and what it still left untouched.
| Source | Verified finding |
|---|---|
| CIA headquarters history of the Kryptos sculpture | The CIA says James Sanborn's Kryptos was dedicated on November 3, 1990, as an artwork about intelligence gathering. Its materials include red granite, copperplate, lodestone, petrified wood, and a compass rose. The S-shaped copper screen contains 1,735 alphabetic cutouts; the encoded side is paired with a deliberately reversed Vigenere-style tableau. The CIA page says the first three texts were cracked while K4 is a 97-character fourth section designed to be harder. |
| CIA Museum artifact record for Kryptos | The CIA Museum describes the copper screen as the centerpiece of a larger sculpture that includes granite sections, a pool, and petrified wood. It says Sanborn used several cryptographic methods and that cryptanalysts cracked three sections. This official record documents what the physical artwork and institutional display contain; it does not disclose K4's plaintext or encoding method. |
| NSA declassified report, The CIA KRYPTOS Sculpture: A Summary of Previous Work and New Revelations | The NSA publishes a declassified cryptanalytic report titled The CIA KRYPTOS Sculpture: A Summary of Previous Work and New Revelations. Its release documents that government cryptanalysts studied the inscription and recorded methods and intermediate work rather than treating an asserted plaintext alone as a demonstrated solve. The release draws a distinction between reproducible cryptanalysis and a bare answer while not disclosing the still-secret K4 method. |
| Scientific American report on the 2025 K4 plaintext discovery | Scientific American reported that Jarett Kobek and Richard Byrne located Sanborn's original K4 plaintext on scraps in Smithsonian archival papers and emailed it to Sanborn on September 3, 2025. Sanborn authenticated the text, but the discovery did not provide the encoding method. The report says K4 contains 97 letters and that the archived scraps included the previously released phrases BERLIN CLOCK and EAST NORTHEAST. |
| Associated Press report on the Kryptos archive auction | The Associated Press reported that Sanborn's Kryptos archive, including codes and charts, sold to an anonymous bidder for $963,000 in November 2025. The sale followed the archival plaintext discovery. Sanborn told AP that the researchers discovered the text but did not decipher it because they did not have the key or method; the purchaser was to receive a private explanation of the codes, charts, artistic intent, and the alternate passage called K5. |
The Smithsonian Scraps Jarett Kobek and Richard Byrne Found in 2025
The 2025 turn in the K4 story was not a fresh attack on the sculpture's letters but a find in paper archives. Scientific American reported that Jarett Kobek and Richard Byrne located Sanborn's original K4 plaintext on scraps preserved among Smithsonian archival papers, then emailed the text to Sanborn on September 3, 2025. That changes the case in a very specific way. It supplies a candidate destination rather than a route. For a puzzle discussed for decades as an unsolved cipher, finding the message outside the cipher immediately narrows one question while leaving the harder mechanism untouched.
The same report makes the scope of the discovery unusually precise. K4 is described there as a sequence of 97 letters, and the archival scraps are said to include the previously released phrases BERLIN CLOCK and EAST NORTHEAST. Those details matter because they tie the papers directly to a known part of the public Kryptos trail. The scraps were not a vague note about themes or imagery. They were close enough to include material already associated with Sanborn's earlier hints, which gives the archival find a defined relation to the fourth section rather than a merely suggestive resemblance.
What the papers added, then, was not a rumor that someone had guessed correctly, but a text Sanborn could recognize as his own. Scientific American reported that he authenticated what Kobek and Byrne sent him. That authentication raises the status of the plaintext beyond speculation, yet the discovery remains bounded by where it was found. The words came from archival remains, not from a public demonstration that began with the 97-letter ciphertext on the sculpture and reproduced the concealed message through a disclosed method. The plaintext appeared on surviving archival scraps without a publicly disclosed encoding method.
That distinction is why the archival breakthrough feels both decisive and incomplete. It decisively changed what could be said about the hidden message: after September 3, 2025, there was reported confirmation that a plaintext existed in Sanborn's papers and matched what he intended. But the find was only as specific as the scraps themselves. Scientific American did not report that the papers contained a step-by-step key, a full transformation path, or a public proof linking each ciphertext segment to each plaintext element. The archive opened the envelope; it did not show the lock being picked.
Sanborn's Authentication and the Missing Key to K4
Once Sanborn authenticated the text, the central puzzle changed shape rather than disappearing. Scientific American reported that he confirmed the plaintext located by Kobek and Byrne, while also making clear that the discovery did not provide the encoding method. That leaves two separate achievements on the table. One is learning what message Sanborn intended K4 to contain. The other is showing how the 97-character section on the sculpture was transformed into that message. The first can be validated by the artist's recognition. The second requires a procedure others can inspect, test, and rerun from the ciphertext itself.
The Associated Press sharpened that split after the archival discovery entered public discussion. AP reported that Sanborn said the researchers discovered the text but did not decipher it because they did not have the key or method. That statement is narrow, but it is enough. It rejects the idea that possession of the answer sheet automatically counts as a decryption. If the artist himself distinguishes between discovering the text and deciphering the code, the K4 dispute is no longer about whether the message exists. It is about whether the transformation from inscription to message has been publicly demonstrated.
AP also reported that Sanborn's Kryptos archive sold to an anonymous bidder for $963,000 in November 2025, and that the purchaser was to receive a private explanation of the codes, charts, artistic intent, and the alternate passage called K5. That detail complicates the public record instead of completing it. It suggests that explanatory material may survive in a form more explicit than the Smithsonian scraps, yet the explanation described by AP was private, not released as a public working solution. The purchaser was to receive a private explanation of the codes, charts, artistic intent, and K5, while no public K4 method was disclosed.
The NSA declassified summary becomes useful precisely at this point. The published report is titled The CIA KRYPTOS Sculpture: A Summary of Previous Work and New Revelations, and its verified importance here is procedural. It documents that government cryptanalysts studied the inscription and recorded methods and intermediate work rather than treating an asserted plaintext alone as a demonstrated solve. That does not reveal K4's still-secret method. It does, however, preserve a professional standard visible inside the case: a claimed answer gains force when the path to it is laid out, not merely when the destination is named.
Seen together, the three records create a hard boundary around what can honestly be claimed. Scientific American supplies the reported archival discovery and Sanborn's authentication. AP supplies Sanborn's own statement that the researchers lacked the key or method. The NSA summary supplies a documented model of what serious cryptanalytic work looks like when it is recorded as process, intermediate reasoning, and technique. None of those records tells the public how K4 was encoded. All three, in different ways, prevent the archival plaintext from being mistaken for a complete public solution.
So the remaining problem is not whether K4 had an intended message, nor whether papers connected to that message survived. The remaining problem is what evidence would let an outsider begin with the ciphertext on the sculpture and arrive at the authenticated plaintext through a disclosed, reproducible sequence. Until such a sequence is shown, the case contains an unusual imbalance: a message reported as genuine, hints like BERLIN CLOCK and EAST NORTHEAST embedded in the history of the puzzle, and a method that stays out of public reach like one more missing component in the copper screen's long argument with readers.
What the NSA Declassified Record Suggests About Proof
The NSA declassified summary matters because its verified finding centers on process rather than a bare outcome. The released report documents that government cryptanalysts studied the Kryptos inscription and recorded methods and intermediate work instead of treating an asserted plaintext alone as a demonstrated solve. That difference resets the standard for talking about K4. A sentence that matches an answer may satisfy curiosity, but cryptanalysis asks for a route that can be shown. It asks whether other people, starting from the inscription and the same constraints, can inspect the steps and arrive at the same result through a reproducible path.
That requirement is not a ceremonial extra added after the fact. Intermediate work preserves the chain between ciphertext and conclusion, including the points where a guess failed, a pattern narrowed, or a rule proved useful. The declassified summary therefore gives a way to measure the present K4 situation without claiming to disclose K4's secret method. Without a disclosed method, the authenticated plaintext cannot be reproduced from K4's 97-character ciphertext by a publicly testable procedure. The gap sounds technical only until one notices what it governs: the difference between possessing an answer and demonstrating how the code yields it.
The CIA headquarters history sharpens the distinction by fixing what kind of object K4 is. That page says Kryptos was dedicated on November 3, 1990, as an artwork about intelligence gathering, and it identifies K4 as a 97-character fourth section designed to be harder after the first three texts were cracked. Once that structure is fixed, the NSA record reads like more than background. It supplies a discipline for judging claims. Earlier sections became known through cryptanalytic work, while K4 now occupies a narrower category: an authenticated text without a public chain that turns the inscription into a repeatable solution.
This is where an easy shortcut becomes tempting. Once the artist authenticates a plaintext, some readers may decide the mystery has simply moved behind a closed door, solved in substance and unpublished only in detail. The NSA summary blocks that move without pretending to reveal the hidden system. Its verified finding shows that documented cryptanalysis values recoverable reasoning alongside any result. Under that standard, K4 has not returned to ignorance, because the text is no longer wholly unknown. Yet it has not crossed into a fully public solve either, because the procedure that would let strangers verify the answer remains absent from the record.
Seen from that angle, the real dispute is less about whether the plaintext is genuine than about what proof means in a code story. The declassified summary helps by separating those questions. One can accept an authenticated text and still ask what exact system carried those words into the sculpture, and how an outsider could demonstrate that system from the surviving evidence. Once proof is defined that strictly, earlier public hints stop looking like prizes collected along the way. They become fragments whose relation to the missing procedure has to be tested, because provenance alone does not explain operation.
BERLIN CLOCK and EAST NORTHEAST in the Archival Trail
The recovered archival scraps changed the status of two familiar hints by placing them beside the plaintext instead of leaving them suspended in public speculation. The 2025 report states that Jarett Kobek and Richard Byrne found Sanborn's original K4 plaintext in Smithsonian archival papers and emailed it to Sanborn on September 3, 2025. The same verified finding says those papers included the already released phrases BERLIN CLOCK and EAST NORTHEAST. That does not disclose the encoding method, but it does establish a tighter documentary relationship. The hints were present in the archival trail connected to the text rather than floating as detached curiosities.
That archival placement changes how the hints should be handled. The archived scraps included the previously released phrases BERLIN CLOCK and EAST NORTHEAST. After the discovery, their footing becomes firmer. They appear in papers tied to Sanborn's original K4 material, which narrows the room for claiming they were merely decorative distractions released around the puzzle. Even so, the narrowing has a strict limit. The recovered scraps confirm association and proximity, but they do not specify how either phrase functions inside the code's actual construction.
The CIA headquarters history gives those phrases a firmer frame by restating what the artwork already contains. Its verified finding says the encoded side of the S-shaped copper screen is paired with a deliberately reversed Vigenere-style tableau, and that K4 is the hard fourth section within that larger setup. Set beside the archival scraps, the hints look less like free-floating passwords and more like elements that must answer to a defined object. They are attached to a specific 97-character section embedded in a sculpture whose cryptographic environment is officially described, even if the final method for K4 is not publicly supplied.
Yet authentic hints do not become self-explanatory once they are anchored to an archive. A phrase can be genuine and still leave the mechanics underdetermined. BERLIN CLOCK and EAST NORTHEAST may have significance, but the frozen record does not authorize the intermediate steps needed to convert either phrase into a reproducible decryption. The 2025 report states the crucial limit plainly: the plaintext discovery did not provide the encoding method. That means the archival find improves provenance without closing the central technical distance. The words are better placed historically, while their operational role inside K4 remains unshown to the public.
The result is a puzzle that has become more disciplined rather than smaller. Readers no longer need to wonder whether those two hints were genuinely tied to K4, because the recovered scraps place them inside the same documentary trail as the authenticated text. The CIA description also keeps the target fixed by describing a deliberately harder 97-character section on a sculpture built around encoded letters and a reversed tableau. What remains open is the path from those archival fragments to a full demonstration other people can inspect step by step. The hints are steadier as artifacts, while the missing method still governs their meaning.
The CIA Museum Record and the Limits of Official Silence
The CIA Museum artifact record is useful precisely because it stays narrow. It describes the copper screen as the centerpiece of a larger sculpture that includes granite sections, a pool, and petrified wood, and it says Sanborn used several cryptographic methods while cryptanalysts cracked three sections. That establishes the physical object on display and the broad fact of layered technique. It does not disclose K4's plaintext, and it does not identify the encoding procedure for the final section. For a reader tracking what is known, that omission is not a gap in attention. It is part of the current record.
The CIA headquarters history page adds a different kind of firmness. It says Kryptos was dedicated on November 3, 1990, as an artwork about intelligence gathering, and it lists red granite, copperplate, lodestone, petrified wood, and a compass rose among the materials. It also says the S-shaped copper screen contains 1,735 alphabetic cutouts and that the encoded side is paired with a deliberately reversed Vigenere-style tableau. Those details show how much of the sculpture can be described in public without solving K4. Rich physical description and public method disclosure are not the same thing.
That distinction matters because official records can look fuller than they are. When a museum entry documents the copper screen, the pool, and the surrounding stone, those named parts do not disclose the still-secret encoding method. Yet the museum record stops before the decisive step. It confirms that several cryptographic methods were involved and that three sections were cracked, but it leaves the fourth section in a different category. The object is documented, the challenge is acknowledged, and the final transformation from ciphertext to message remains outside the public frame.
The CIA headquarters page makes the boundary even sharper by stating that K4 is a 97-character fourth section designed to be harder. That sentence does not merely preserve mystery for atmosphere. It places K4 inside the sculpture's original design, as a separate problem intentionally set apart from the three passages already cracked. Once the plaintext surfaced later, the official pages still did not become a map from inscription to message. They remained what they had been all along: records of an artwork, its materials, and its challenge, without a publicly demonstrated path through the last cipher.
After the $963,000 Auction, Where the K4 Method Stands
The line between answer and demonstration became sharper after the archive sale. The Associated Press reported that Sanborn's Kryptos archive, including codes and charts, sold to an anonymous bidder for $963,000 in November 2025, after the archival plaintext discovery had already changed the public conversation. That sale matters because it moved relevant explanatory material into private hands rather than into a public repository. A reader can now point to two different states at once: the text of K4 was authenticated, and documents said to explain codes and charts were transferred through a private auction rather than opened for universal inspection.
The Associated Press report also records Sanborn saying the researchers discovered the text but did not decipher it because they did not have the key or method. That is the central separation in the case. A plaintext can be real, even decisive, without proving the route that generated it from the visible inscription. In ordinary reading, those two achievements are often blurred together under the word solution. Here they cannot be. Sanborn's statement, as reported by AP, preserves the difference between locating the destination in archival papers and reproducing the cryptographic journey that reaches it from K4 itself.
The Scientific American report fills in how the plaintext surfaced without closing that methodological gap. It says Jarett Kobek and Richard Byrne located Sanborn's original K4 plaintext on scraps in Smithsonian archival papers and emailed it to Sanborn on September 3, 2025. Sanborn authenticated the text, but the report says the discovery did not provide the encoding method. That sequence is unusual enough to change the shape of the mystery. K4 no longer sits as a blank unknown message, yet it also does not stand as a publicly replicated decryption. The archive yielded wording, not a demonstrated procedure.
Scientific American adds another important constraint by noting that the archived scraps included the previously released phrases BERLIN CLOCK and EAST NORTHEAST. Those phrases had already been public clues, so their presence in the papers links the discovery to material already associated with K4. Even so, a clue trail is not the same as a full cipher mechanism. The report also states that K4 contains 97 letters, matching the official description of the difficult fourth section. What emerged, then, was alignment between archival fragments and the known challenge, not a public workbook showing each reversible step from sculpture to plaintext.
The auction deepens that asymmetry rather than resolving it. AP reported that the purchaser was to receive a private explanation of the codes, charts, artistic intent, and the alternate passage called K5. Private explanation is not public proof, and its privacy now matters more than ever. If the explanatory bundle remains accessible only to the buyer and those the buyer permits, outside readers cannot test the method line by line. The status of K4 therefore becomes unusually split. The plaintext has an authenticated footing, while the account of how K4 encodes that text is said to exist but is not open for communal verification.
A careful description of K4 now has to hold two confirmed developments at once. The CIA's public material still describes a deliberately difficult 97-character fourth section, later reporting says researchers found plaintext scraps that Sanborn authenticated, and AP says those researchers lacked the key or method. The subsequent sale reportedly carried a private explanation to an anonymous buyer, not to the public record. What sits before readers today is therefore sharply divided: words that can be named, and a cipher route that cannot yet be independently walked from the sculpture itself.