The Madsen cryptogram: An unsolved encrypted text from a book about the CIA

Blog reader Brent Lakes kindly informed me about an interesting unsolved crypto mystery. It appears on the final page of a book about the CIA.

The cryptogram

In 2016, investigative journalist and former NSA contractor Wayne Madsen self-published a book entitled The Almost Classified Guide to CIA Front Companies, Proprietaries & Contractors. The book is an encyclopedic compilation of alleged CIA front companies, proprietaries, and contractors, ranging alphabetically from Air America to Zapata Offshore. It has 424 pages.

On the last printed page, the reader encounters a ciphertext consisting of 112 letters, divided into 25 word-like groups.

Here is a transcript:

Gqow Exlgrnn ydd Dpfecp Odhct cwrbc qjft gemm tnlvss lhmjsttbv wyllz vrrei kzyykf. Yokr to, cpv ytc Mwufs zoha anie nbd Ozaaz vcfb hxhy eo.

Seven of the groups begin with an uppercase letter. Their initials are: G E D O Y M O. According to Brent, Madsen has confirmed that the tenth group begins with a lowercase l, not an uppercase I. Brent received some additional information from the author:

  • “The cipher a is simple one based on letter substitution.”
  • “I believe the plaintext is something not complementary to the U.S. intelligence community.”
  • “It’s been so long ago, I forgot what I used but I know it was something the NSA could break. It may have been the Hagelin or Jefferson cipher.”

Brent’s analysis

Brent carried out an extensive analysis of the message. A monoalphabetic substitution cipher (MASC) can be ruled out, as the index of coincidence of the ciphertext is approximately 0.0357. This is even slightly below the random-text value of about 0.0385 for a 26-letter alphabet and far below the value of roughly 0.066 expected for ordinary English.

Brent also examined periodic polyalphabetic ciphers, running-key and autokey systems, transposition methods, fractionation ciphers, and the two machine-cipher families mentioned by Madsen. None produced a convincing solution.

The ciphertext contains eleven occurrences of identical adjacent letters:

NN, DD, DD, MM, SS, TT, LL, RR, YY, AA, AA

This is a surprisingly large number. In random text of this length, we would expect about 4.27 doubles. A genuine M-209 ciphertext, a Jefferson-disk ciphertext, or the output of a conventional long-key polyalphabetic cipher should behave approximately like random text in this respect. Such systems do not normally preserve double letters from the plaintext. Eleven doubles would therefore be an unlikely, although not impossible, accident.

The following pages contain some more analysis Brent provided me:

If you have an idea on how to break this cryptogram, please leave a comment.

Back to Cipherbrain Blog