# Kryptos K4: completed research campaign

**This campaign did not recover the intended K4 plaintext, key or method.** It produced reproducible exclusions for explicitly bounded cipher families and one verified structural fit whose undisclosed text is incoherent. That fit is not a decipherment.

The fresh campaign began on September 14, 2026 at 04:47:10 UTC with a native ceiling of **100,000,000 tokens**. It preserved research and completed evidence from the canceled goal. Search work ended at approximately 09:26 UTC, ahead of the 12:17 search cutoff and 12:47 delivery deadline. The goal expressly permitted finishing early when no useful scoped experiment remained. The independent stopping review found no further mechanism with both a specific gap in inspected prior coverage and an independent reason to prefer it. We completed the admitted finite families and moved to evidence review instead of spending to the ceiling.

The work used a main integrator and two specialist workers, with implementation checked by independently written arithmetic oracles and verifiers. Enumeration ran in local Python/C++, with at most two logical search CPU jobs, no paid API, no remote compute and no external communications or publication. Final native token usage is reported with the goal-completion message; the ceiling was not a spending target.

## What the prior-work review established

The review distinguished direct-alignment tests, named routes, keyword-selected orders, samples, heuristics and actual exhaustive bounds. At pinned revision `8c7e2d295a02376db8b2867d7419c6f3acd413c8`, the [KryptosBot source](https://github.com/jcolinpatrick/kryptos/tree/8c7e2d295a02376db8b2867d7419c6f3acd413c8) leaves specific large-width column-order cases outside its exhaustive coverage. Its inverse-columnar generator exhausts only widths through 7; that does not exclude every inverse width 18 order. Experiment-level comparisons are retained in the prior-work reviews, rather than inferred from repository headlines.

Some inspected arguments did not survive checking. One prior implementation applied incorrect transformed clue constraints and an invalid ragged mapping. A separate blanket extension of direct-alignment Bean constraints through arbitrary permutations has a literal counterexample. That counterexample uses fitted text and a fitted permutation; it invalidates that particular exclusion argument and is not a K4 candidate. Neither finding invalidates every experiment by the source authors.

The [2025 archival plaintext discovery](https://apnews.com/article/650c1253d6a96591f29b88a20299c430) and the [archive auction record](https://content.rrauction.com/jim-sanborns-complete-kryptos-archive-sells-for-962500-at-auction/) also change the historical context. Finding plaintext in an archive is distinct from independently deriving the encryption method. This campaign obtained no independently verified public method from those records.

These are bounded comparisons with inspected sources. Private, unpublished and unindexed attempts cannot be exhaustively inventoried; no literature-wide novelty guarantee is claimed.

## Verified scope

The fixed input has 97 ciphertext letters and 24 disclosed plaintext letters, indexed from zero in `manifest.json`: EAST 21–24, NORTHEAST 25–33, BERLIN 63–68 and CLOCK 69–73. AZ is the standard alphabet; KA is `KRYPTOSABCDEFGHIJLMNQUVWXZ`.

Ordinary columnar encryption fills a ragged grid row by row, then reads whole columns in any order. Inverse columnar encryption fills those physical columns with consecutive plaintext blocks and then reads rows. Both use the original 97 letters, without padding or null insertion. The two sets of permutations are distinct.

The table reports **cumulative verified evidence retained in the fresh campaign**, including preserved work. Its rows overlap; they are not independent trials or disjoint key spaces.

| Family | Exact retained scope | Outcome |
|---|---|---|
| Ordinary periodic columnar | Widths 16–20, periods 1–6; width 18, periods 7–12; AZ/KA, signs ±1, both stages | All specified models excluded; additional narrow pair certificates are deduplicated in the ordinary summary |
| Ordinary width 31 | Periods 1–5, same conventions; commuting period 1 stage aliases omitted | 36 distinct executed models excluded |
| Ordinary width 31, period 6 | AZ+, additive-before | One structural fit; stopped immediately, leaving seven planned period 6 models untested |
| Ordinary aggregate | Preceding ordinary evidence and narrow certificates | 338 excluded model labels, one structurally feasible model, no currently capped model; untested cells remain untested |
| Independent vertical column reversal | Width 18, periods 1–6, both alphabets/signs/stages | 48 negative recorded labels represent 44 distinct models after four period 1 aliases; overlaps top-down routes |
| Ciphertext-autokey before ordinary columnar | Widths 16–20, lags 1–12, two alphabets and three signed conventions | 360 models excluded |
| Plaintext-autokey before ordinary columnar | Width 18, lags 1–12, same conventions | 72 models excluded |
| Fixed mixed alphabet axes | Width 18, periods 1–3, AZ→KA and KA→AZ, both signs/stages except commuting period 1 duplicates | 20 distinct models excluded |
| Progressive cycle keys | Width 18, base lengths 1–3, cycle steps ±1, AZ/KA, both signs/stages | 48 executed models excluded; base-length 1 stages do not commute |
| Column-reset key | Width 18, restart the same key at every emitted column | Four length 4 roots excluded; an independent clue-row proof transfers each negative to every positive reset length |
| Fixed affine substitution | Ordinary width 18, one offset, AZ/KA, ten invertible multipliers other than ±1 | 20 executed models excluded; ±1 reuse existing signed-additive evidence |
| Inverse columnar, source-phase key | Width 18, periods 1–4, AZ/KA and both signs | Periods 1–3 excluded by independently verified placement certificates; four full period 4 roots excluded by the exact solver |
| Inverse columnar, destination-phase key | Width 18, periods 1, 2, 3, 4, 6, 9, 12, 18, 27, 36, 54, AZ/KA and both signs | Derived exclusions from the same local placement certificates; these are not additional executions |

The inverse certificates exploit a necessary condition: every plaintext position must be covered by some individually compatible column block. At local row periods 1–3, selected positions have no such block. Twelve certificate cases support the period transfers. For before-stage period p, the local row period is p; after-stage period p, it is `p/gcd(p,18)`. The proof establishes local constraint equivalence, not equality of complete cipher families.

The local row-period 4 AZ+ gate survived. That never established a full fit. A later exact source-phase period 4 solver enforced global key sharing and a complete arrangement, excluding all four alphabet/sign cases. It does not exclude destination-phase models merely because they have local row period 4. Their different key-sharing rules remain outside those full-solver results.

## Why the structural fit is not a solution

The frozen width 31, period 6 fit uses key `XETQGR`. An independent literal implementation verifies all 97 ciphertext letters, all 24 disclosed clues, the route, key annotations and reverse decryption. The other 73 letters are incoherent, and neither the key nor the 31-column order has an independently motivated derivation.

Nine equal-length clue-free columns permit 362,880 labeled order assignments while preserving the clues and key. We did not rearrange them to improve language. Rejecting this representative as the intended plaintext does not exclude every witness in its model. No language scorer or matched-null simulation was run, and no significance or p-value is claimed. See `width31_structural_witness_audit.md` and `width31_first_witness_gate_review.md` for the frozen evidence.

A geometry correction also prevents a duplicate search: the width 31 physical layout with four initial right-aligned letters and the ordinary final-short-row layout have the same unrestricted column-order family under a column-label rotation. Continuous absolute key phase is absorbed by rotating an unrestricted key. Earlier narrative warnings were corrected while frozen preregistrations and results were preserved. This adds no independent evidence for the fit.

## Verification and practical limits

Historical controls cover full K1, an intact 31-letter K2 prefix, and full 336-letter K3 with its published rotation recipe. The 1746 direct baseline checks are replication, not newly discovered coverage. Synthetic controls compare whole-order oracles, planted messages, arithmetic conventions, resource caps and deliberate artifact tampering. Some 97-character controls disclose more than the canonical 24 letters or fix a prefix to bound runtime; those are arithmetic controls, not demonstrations of unrestricted real-message recovery.

The final pure-family chain audit verified 18,013 negative nodes and 8,553 inherited links. It checks hashes, identities, completion and prefix coverage; it does not independently replay every solver leaf. Dedicated nonpure families are explicitly excluded from that audit and checked through their own verifiers and controls. The final inverse review ran 26 existing tests and checked 873 saved clue-pair contradictions against original letters, alongside the remaining certificate records and source/build links. No correctness issue was found within that reviewed scope.

All 256 declared filename/hash pairs in the integrity audit were recoverable, with no corrupt archives or malformed JSON. Material provenance limits remain:

- Some early runs did not record their historical full-manifest hash; current bytes are never asserted to be those missing historical bytes. One early dependency omission is documented in `REPRODUCE.md`.
- The first inverse placement gate's scope and rejection rule were declared in its task message, but its on-disk registration followed execution. Its original scan runtime was not captured. The subsequent three gates were preregistered before evaluation.
- A copied progressive preregistration sentence said base 1 although its original machine cells, purpose and executions correctly specified bases 2/3. The frozen file remains unchanged, with an explicit erratum.
- The initial inverse period 1 kernel call remains capped in its raw result. A later independent certificate closes that model; the historical unknown was not rewritten as a negative. Unsaved internal work from other capped searches can repeat during continuation, although completed certified cells are reused.

The 66 terminal result batches starting after fresh-goal activation record a sum of 9,376.27 seconds of batch wall duration. Parallel durations overlap; this is neither elapsed campaign time, CPU time, token usage nor billing. It excludes research, tests, compilation, the untimed first inverse gate and other activity outside those result records. Two older probes also lack complete timing metadata. Memory settings are conservative allocation estimates, not OS-enforced RSS limits or a continuously measured peak. Earlier live jobs were explicitly reniced when their inherited scheduling priority was discovered.

## Deliverables and next work

`REPRODUCE.md` gives build, verification and replay commands. The package retains canonical inputs, runnable source/tests, frozen specifications, raw results, the experiment ledger, independently checkable certificates, required source/binary versions, current coverage summaries and audits. `ARTIFACT_INVENTORY.md` records retained purposes and final size; disposable task-created helpers and bytecode are removed.

`NEXT_EXPERIMENTS.md` ranks three contingent reopening options: targeted adversarial differential verification of the new inverse solver; one method replay fixed by newly authenticated primary evidence; and matched-budget null calibration only after a future coherent, independently motivated candidate exists. Each has a finite pilot, decision rule and admission trigger. None is an automatic new search, and the current structural fit does not qualify for the null-calibration gate.

`FINAL_TECHNICAL_AUDIT.md` and `REQUIREMENTS_AUDIT.md` document verification and delivery checks. The outcome is a completed, reproducible research campaign with bounded negative results—not a solution to K4.
