On 21 September 2026, I received an email from Jack Willis announcing the breaking of another Enigma message, Nr. 285 FMNGI of 31 July 1941. The news of yet another AI Enigma break, only six days after the MVUEH break, was a great surprise.
The two breaks are similar in that they both used AI, but they also differ. While the MVUEH break used OpenAI’s GPT–6 Astra, FMNGI used Anthropic’s Claude Opus 5. In the MVUEH case, GPT–6 did all the work of deciding which message to attack and developed all the cryptanalytical tools needed, while the FMNGI attack was more directed and relied on strong human guidance.
Jack Willis gave Claude a cryptanalytical workbench written in Go, the necessary historical material and set it free to investigate. Nr. 285 FMNGI of 31 July 1941 is an incoming message received by the radio station of the Quartermaster of the SS-Totenkopf Division. The message form, which you can see here Nr. 285 FMNGI does not indicate the sender. It only shows it came from a radio station with the tactical callsign tto. Because it is an incoming message, the recorded ciphertext often has errors or garbles, due to bad radio conditions or less experienced Morse code radio operators.
When Jack started his attack on FMNGI, he did not have access to the copy of the message form I have given above. I only published this copy after I learned about the break. However, in 2005 we published a transcript of the message, which was available on Crypto Cellar Research. Now, a transcript can also introduce additional errors because of difficulties in interpreting weak and foreign-looking handwriting. The German radio operators were trained to use a special and very distinct lower-case alphabet when writing out and taking down Morse code messages. However, many of the operators nevertheless had their individual writing style more or less influenced by their personal Sütterlin handwriting.
Luckily, in July 2026 I discovered a collection of ciphertext messages from the Nachschubdienst (supply service) of the SS-T Division at the German national archives, Bundesarchiv. Most of these messages were outgoing messages, and many of them were addressed to the Quartermaster. That meant that we now had copies of the messages before they were sent over the radio. One would then expect them to be without faults, but alas, in the heat of battle errors are bound to happen, and both ciphering errors and writing errors are common occurrences, as we will see with FMNGI.
When I updated the 1941 Message List in July with the new Nachschub-führer – NF messages, I also included copies of all the new message forms. So when Claude started its attack, it had access to the outgoing or originating copy of FMNGI, with message Nr. 205, which we call Nr. 205 NF. Claude transcribed the scanned message form before searching for the message key, recording ambiguous characters rather than trying to resolve them. Another already broken message, ALQFI from 28 August 1941, transmitted and received by the same two radio stations, served as a control for the transcription Claude made of FMNGI.
ALQFI’s closing signature, together with other traffic having been sent by SS-Obersturmbannführer Friedrich Hartjenstein, resulted in a 14-letter-long crib XHARTJENSTEINX. That Fritz Hartjenstein was an excellent provider of cribs we already documented in our 2005 Cryptologia article Breaking German Army Ciphers. There we listed some of the variations to his signature:
XNDXNDXHARTJENSTEINX
XGEZXHARTJENSTEINX
XHARTJENSTEINX
XHARTJENSTEIN
XHARTJENSTEINXHARTJENSTEIN
XGEZXHARTJENSTEINXHAUPTSTUFX
GEZ means gezeichnet — signed. In July 1941, Hartjenstein was an SS-Hauptsturmführer; he was promoted to SS-Obersturmbannführer in November 1944, so in 1941 he signed with HAUPTSTUF.
After the preliminary research, Claude was ready for the attack and began searching for the key. Jack Willis reported that the final search, which broke the message and found the Enigma key, happened on 20 September 2026. The key search took 13 minutes and 28 seconds on an Apple M2 host.
The plaintext that was recovered was:
KOLJNNEVONXKORPSNACHSCHUBZURUEKXHARTJENSTEINXHARTJENSTEINX
Enigma does not encipher space so the plaintext needs to be divided into words, which gives:
KOLJNNE VON X KORPSNACHSCHUB ZURUEK X HARTJENSTEIN X HARTJENSTEIN X
Here we see two errors. The first word should be KOLONNE, and the word ZURUEK should have been written ZURUEQ. The German Enigma operators were instructed to write the umlaut letters Ä and Ü as AE and UE, and to replace CH and CK with the letter Q. Hence the German word zurück becomes ZURUEQ. The last error was most likely made by the person who enciphered the message. The plaintext of the message as written by Hartjenstein can be seen here Plaintext of Nr. 205 NF. We see that the text has been divided into two-and-two letters (bigrams), which indicates that the operator originally intended to encipher the message with a manual cipher, Truppenschlüssel, a double Playfair system. In the end, it was sent as an Enigma message, and the operator probably forgot to change CK in zurück to Q.
The first error in the word Kolonne is either a ciphering error or the operator wrote down the wrong cipher letter. In any case, it shows what was mentioned earlier: that even at the transmitting end of a radio link errors occurred, as ciphering errors, operator errors or errors when sending the Morse code.
Now some will ask, if you had the plaintext, why didn’t you break it before? We could possibly have broken FMNGI using the plaintext for Nr. 205 NF, but I only found the plaintext collection at the end of July, and I went on vacation in early August. So it was only after the break was reported that I thought: Do I have the plaintext? However, using the full plaintext is a bit like cheating, so I prefer it was broken the way Jack Willis and Claude did it.
The FMNGI break was very welcome news for us at Crypto Cellar Research. Of the close to 1000 Enigma and Truppenschlüssel messages in the German Army collection, only seven Enigma messages remain unbroken, along with one puzzle, Nr. 138 WEUWY, that we know must have identical plaintext to another message from the same day, Nr. 140 WEUWY. However, still Nr. 138 has resisted all our attempts to break it.
Who is next to send me a message about a new break with or without the help of AI?
Updated: 24 September 2026 at 05:29 UTC
| Back to Crypto Cellar Research | Licensed under CC BY-NC-SA 4.0 Frode Weierud, Crypto Cellar Research © 2026 |
Breaking German Wehrmacht Ciphers |