Opus 5 cracks a second Enigma message — seven remain unsolved

Share
Opus 5 cracks a second Enigma message — seven remain unsolved

Frontier models are quietly finishing the work Alan Turing never lived to see done — and the count of unsolved wartime ciphers is now low enough to fit on one hand.

Claude Opus 5 has broken a second long-unsolved Enigma message — a German Army dispatch from 31 July 1941 that sat unread in the archive for 85 years — making it the second frontier-model cryptanalysis win validated in as many weeks. Cryptologist Frode Weierud published the write-up this week after Jack Willis contacted him on 21 September saying he had used Anthropic's model to break message FMNGI (Nr. 285). The catch matters: unlike OpenAI's Astra, which Weierud says solved the Rosenow dispatch in September almost entirely on its own, Willis gave Opus 5 significantly more help — a Go workbench, crib material keyed to a known officer's name, and a known plaintext signature to steer the search. Even so, the actual key search took 13 minutes and 28 seconds on an Apple M2 laptop. Weierud also spent the week validating Carter Leffen's Astra solution to the earlier message, leaving him, in his words, "in awe": "What it has achieved in two days would take a human researcher weeks or even months. Personally, I spent several weeks researching the Bundesarchiv files GPT-6 Astra refers to."

The gap between the two breaks is the real finding. One model needed a nudge toward the right crib; the other had to do its own archival research, notice that a related solved message contained the repeated name ROSENOWROSENOW, build its own Enigma simulator, and run the search unattended — and its audit trail survived expert review. Weierud counts just seven unbroken Enigma messages remaining in the German Army collection, plus one where the plaintext is known but the code is not. We covered the first break when it landed — An 83-year-old Enigma message falls to a two-day agent hunt — and the picture has sharpened since: this is no longer a one-model stunt.


UpGuard found 16,326 Supabase-hosted databases with publicly readable tables — more than half showing indicators of personal data — a scale of exposure that maps directly onto the boom in AI-generated apps. Fingerprinting roughly 300,000 domains that use Supabase, the security firm surfaced an Indian adult streaming site with 65,467 users' passport, tax ID and bank details plus 100,000 private messages, a U.S. valet service with about 78,000 license plates, an African consulate in France, a Canadian immigration service with 884 plaintext passwords, and a SIM farm intercepting one-time passcodes. The mechanics are the AI angle: tables created through the API — the way coding agents write data layers — do not enable row-level security by default, so a vibe-coded app can ship with its database wide open and its developer none the wiser. Supabase CISO Bil Harmer says projects are "secure by default" and that configuration is a shared responsibility, which is true and also the point: the person shipping a weekend app rarely knows what shared responsibility means.

What to watch: whether Opus 5's break turns out to be similarly autonomous once the crib material is discounted — and whether Supabase changes that API default rather than relying on developer education.

Which of the seven remaining Enigma messages falls next — and which model gets it? Tell us in the comments.

Sources: TechCrunch — Astra and Opus just passed Turing's other test · Crypto Cellar — the MVUEH break · Crypto Cellar — the FMNGI break · TechCrunch — Supabase customers exposing people's data · UpGuard — systemic data exposure in Supabase apps · Hacker News discussion