An 83-year-old Enigma message falls to a two-day agent hunt
A German army dispatch from 1941 sat unread in the archive for 83 years, its 82 letters only solvable if someone recovered the machine settings behind it. This week the settings surfaced — and the interesting part is how the work was checked.
A researcher-led investigation using GPT-6 Astra and a set of specialist agents recovered the Enigma key for a message sent on 10 July 1941, and published the whole audit: every search batch, every uncertain letter in the archive, and two independent implementations that re-encrypt the text back to cipher. The message is a routine one — a sender reporting from the town of Rosenow, asking for a route of march and an immediate radio reply, signed with a name read tentatively as Waschbusch — and it survived in two disagreeing copies, a published received transcription and a faint outgoing facsimile. The team recorded twelve uncertain reading positions before starting the search, so a promising key could not be bent to fit a convenient spelling later.
The method is the part worth reading. The Enigma never encrypts a letter as itself, which kills whole alignments for free, and the investigators leaned on a related solved message that contained the repeated name ROSENOWROSENOW, treating those fourteen letters as a crib. The search covered about 4.29 billion combinations of rotor behaviour and crib placement, with all 43,016 batches accounted for and the winning batch rebuilt outside the research workspace, byte for byte. The key landed at ring and window settings HMF and RWD, and the recorded header — GTA with an encrypted indicator KCI — then narrowed 26 equivalent body settings down to one.
Two caveats keep this honest. The exhibit states plainly that this is not the original breaking of Enigma and claims no corpus-wide breakthrough; Polish cryptanalysts solved the military machine in 1932 and Bletchley Park industrialised it. And Carter Leffen, who ran the project, says the codebreaking was not the difficult half — he estimates he put "99 times more effort into building the website that describes the problem and the solution than into actually cracking the code." The transferable result is the paper trail: enough reproducible detail that a sceptic with Python and a C++ compiler can rerun the search rather than take a headline's word for it, which is more than most capability claims ship with.
US and Chinese security experts published nuclear-style guardrails for military AI, including a dedicated hotline for incidents involving autonomous systems, ten days before an expected 24 September Trump–Xi meeting in Washington. Melanie Sisson of the Brookings Institution and Tianjiao Jiang of Fudan University, writing out of a US–China dialogue their institutions have convened since 2019, argue humans must keep sole authority to launch AI-enabled cyberattacks against nuclear command systems or critical infrastructure, and Jiang proposes explicit bans on AI independently deciding to use nuclear weapons or autonomously attacking nuclear command. Jiang's sharpest ask is a shared definition of "meaningful human control" so Washington and Beijing cannot use identical language for different standards — the failure mode being a defensive system that reads a suspicious signal as an attack and answers faster than any official can pick up a phone.
Neither government has endorsed the recommendations, and the hotline idea has a weak track record to argue against: Carla Freeman of Johns Hopkins has noted China did not answer US calls during the February 2023 spy balloon incident, and that Beijing's chain of command makes independent responses from lower-ranking officers hard. We covered the calendar when the first dedicated US–China AI safety talks of this administration were scheduled — US, China schedule first dedicated AI safety talks of Trump's second term — and the value here is the substance that lands on the table: not a treaty, but two governments being handed the specific scenario they would have to agree to prevent.
The head of pretraining for Tencent's Hunyuan large language model has left for Mira Murati's Thinking Machines Lab, according to an exclusive from the Chinese outlet Leiphone. Yao Xingcheng departed Tencent in July and had been reported as a target for Meta; Leiphone says his Thinking Machines package clearly exceeds his Tencent pay, where his annual compensation ran into the tens of millions of yuan. He was one of the young researchers Tencent recruited over the past year and shares Tsinghua's Yao Class background with Yao Shunyu, the same pipeline that has made Chinese pretraining leads the most contested hires in the field. The hire lands as Thinking Machines Lab is reportedly raising at a $40 billion valuation — Accel is in talks to lead a $1B round for Thinking Machines at $40B — which is the actual story: a lab that has barely shipped a product is now expensive enough to buy the technical middle of a rival's flagship model team.
What to watch: whether the confirmed settings and the full search record survive independent reruns, and whether either government puts its name on anything before the 24th.
Should a cryptanalysis claim be judged by the result or by the audit behind it? Tell us in the comments.
Sources: The Decoder — OpenAI's GPT-6 Astra decrypts a Nazi radio message · Carter Leffen — MVUEH: recovering a message from 1941 · Carter Leffen on X · CryptoCellar — 1941 German Army message corpus · Reuters — US, China security experts propose nuclear-style safeguards for AI risks · Modern Diplomacy — Can US-China rules prevent military AI from triggering a crisis? · The Japan Times — U.S., China security experts propose nuclear-style safeguards · Leiphone — Former Tencent Hunyuan pretraining lead Yao Xingcheng joins Thinking Machines Lab · KuCoin News — Former Tencent Hunyuan pre-training lead joins Thinking Machines Lab