The Zodiac · an archive

Original cryptanalysis · Z13 and Z32

What the ciphers can and cannot tell us

Every figure below was produced by code in this repository and can be reproduced. Where a result contradicts a popular claim, it says so.


An arithmetic result that closes a door

Z32 uses 29 distinct symbols. The English alphabet has 26 letters. There is therefore no way to assign a distinct letter to each distinct symbol, and Z32 cannot be a one-to-one substitution cipher. If it is a substitution cipher at all it must be homophonic, with several symbols sharing a letter.

This is not a heuristic or a probability. It is pigeonhole arithmetic, and it invalidates any proposed Z32 solution presented as a straight letter-for-letter substitution.

How far below solvability these ciphers sit

The usual claim is that they are “too short.” We measured how short. Sliding a window across 6,325,505 letters of English prose and counting passages that satisfy each cipher's constraints exactly gives the number of perfect solutions ordinary text throws off by accident.

CipherPerfect fits foundRate per window
Z13, all constraints57.9 × 10-7
Z13, also requiring 8 distinct letters23.2 × 10-7
Z32, all constraints1,7612.8 × 10-4

For Z32 that is roughly one perfect solution in every 3,600 letters of ordinary English. Three examples, lifted from public-domain novels that have nothing to do with the case, each a flawless fit to the ciphertext:

TOTHEHEARTOFTHECONCOURSEATTHESTO
TENTOFTHEIRINFORMATIONTHETRAINSE
OGETHERANDHAVETHEINITIATIONTONIG Each satisfies every constraint Z32 imposes. None has anything to do with a bomb.

Any Z32 “solution” — including the ones we offer below — is a hypothesis chosen using outside context, never a decryption compelled by the ciphertext.

Zodiac's letter-shaped symbols do not stand for themselves

Many cipher symbols are recognisable letters, because Zodiac drew them that way. Did an A mean A? Across both solved ciphers: Z408 has 37 letter-shaped symbols of which 2 self-map; Z340 has 36 of which 2 self-map. Four out of seventy-three, about 5 per cent.

This bears directly on Z13, whose transcription reads A E N … N A M and whose fame rests partly on that visual. On his own demonstrated behaviour, the odds that any one of those glyphs means its own letter are roughly one in twenty.

Key reuse is dead, and now exhaustively so

Twenty-five of Z32's twenty-nine symbols appear in the Z408 alphabet and twenty-seven in Z340's, so key reuse is a natural thought. Applying the solved keys directly gives gibberish; that much was known. We tested the weaker and far more plausible version: that he re-drew a key from the same habits, making each symbol's historical letters much likelier than a random letter.

Constraining every Z32 symbol to only the letters it actually represented in the solved ciphers shrinks the key space from about 1041 to 253,755,392 — small enough to search hard. The best English score reachable anywhere in that space is −147.7, against −118.8 for genuine English of the same length.

Result

The entire habit-constrained space contains no English. Zodiac built a fresh key for Z32, unrelated to his earlier symbol assignments. This closes off key reuse as an attack, including the approach underlying several published claims.

The test that changes how these two should be read

We rebuilt Zodiac's encipherment process from the solved pairs — how many homophones he gave each letter, and the fact that he rotated through them rather than picking at random — then ran that process over thousands of real English passages and counted how many repeated symbols came out.

Z32 behaves exactly like his own work

ModelPredicted repeatsP(repeats ≤ 3)
Z408-style key, rotating3.290.57
Z340-style key, rotating2.890.67

Z32 has exactly 3 repeats. That lands dead centre of the prediction. Z32's structure is what Zodiac's own method produces when enciphering ordinary English — positive evidence that it is a genuine encipherment of a real message, not a hoax and not random marks. It is simply too short to read.

Z13 does not

ModelPredicted repeatsP(repeats ≤ 5)
Z408-style key, rotating0.341.0000
Z340-style key, rotating0.421.0000
Merged repertoire0.911.0000

Z13 has 5 repeat events, far outside anything his homophonic method generates. Z13 was not enciphered with a large homophonic key; he used a small alphabet, close to one symbol per letter. That matters, because it means the near-one-to-one hypothesis is the right frame — and those answer sets are small enough to write down in full.


Z13 as a name: the complete answer sets

Corpora: 25,897 given names from Social Security registrations 1900–1955, the plausible birth window for a man active in 1968–70, and 175,880 surnames from the 1990 and 2010 censuses. Each hypothesis yields its own complete set, not a sample.

HypothesisNames that fit
Simple substitution, first + last49
Simple substitution, first + middle initial + last420
Homophonic, first + last379
Homophonic, first + middle initial + last4,210
Three full names, male given name5,787
Any of the above, one error allowed3,668,004

The pattern fights male names

Of the 49 names in the strictest set, nearly all are female-typed: IMOGENE DEVOID, BURLENE YEARBY, ATHLENE MECHAM, CHIYONO KOSICK. We tested whether that is an artifact.

Statistical test

Base rate across all 13-character first-plus-last combinations in the same corpora: 38.9 per cent carry a male-typed given name. Among Z13-fitting names: 8.5 per cent under simple substitution, 13.8 per cent under a homophonic key. Monte Carlo over 20,000 resamples gives p = 0.0001.

Z13's repeat pattern structurally disfavours male names, because the tripled letter at positions 5, 7 and 9 and the two mirrored pairs are far easier to satisfy with vowel-heavy morphology — the -ENE, -INE and -ETHA endings. The sender was, on all available evidence, a man naming himself. His own cipher's shape argues against the message being a typical male American name of the period.

Why the one-error defence fails

Zodiac made mistakes. The Z340 solution only works if you accept errors in his transposition. So “he slipped once” is a legitimate hypothesis, and it is exactly what the two most famous Z13 proposals need:

  • ALFRED E NEUMAN (proposed by Craig Bauer) breaks exactly one group: positions 3 and 11 would need one symbol to serve both F and M.
  • DR EAT A TORPEDO (proposed by Ryan Garlick) breaks exactly one group: positions 5, 7 and 9 would need T, T, R.

But allowing a single error moves the answer set from 49 to 3,668,004, of which 1,194,416 carry male-typed given names. Ranked by real-world commonness, that set contains CHARLES K BLACK, LESTER E NELSON, WOODROW N BROWN, SAMUEL E NEWMAN, ANDREW E NEWMAN — and ALFRED E NEWMAN with the ordinary spelling.

Consequence

Once one error is permitted, no proposal is distinguishable from a million others. This does not prove any of them wrong. It shows they carry no evidential weight.

The one key-reuse hypothesis chronology allows

Z340 was mailed five months before Z13, so its author could have reused that key — unlike claims built on the 2020 solution, which no contemporary could have had. Applying the genuine Z340 key resolves eleven of thirteen positions and leaves two symbols unknown, giving only 676 completions. We enumerated all of them.

1. DREATATOTHEDO
2. DREANANONCEDO
3. DREADADODGEDO

108. DREATATOTPEDO ← Garlick's proposal All 676 completions ranked by quadgram plus word-segmentation score.

Garlick's reading is a valid completion — it satisfies all four equalities — but it ranks 108th of 676, and the top-ranked completion is meaningless. The Z340-key route does not produce a compelling Z13 reading.

The two 1970 ciphers do not share a key

Z13 and Z32 both contain an anchor symbol that appears in neither solved cipher, which invites the idea of one 1970-era working key. If true, five symbols occur in both ciphers, and a candidate Z13 name would fix five specific letters inside Z32 — a real crib. We tested it twice.

  • Cross-checking every fitting Z13 name against every candidate Z32 message: 0 survivors from 509,379 combinations.
  • Using each Z13 name as a five-letter crib and hill-climbing the rest of Z32: no cribbed reading beats an uncribbed search.

The shared-key hypothesis should be considered refuted.


Z32 and the map

Gareth Penn's long-standing claim is that radian geometry from Mount Diablo connects the attack sites. We measured it: bearing and distance from the summit to each site, corrected for the 1970 magnetic declination of about 17 degrees east, expressed under both readings of “radian.”

SiteMagnetic bearing MilesTrue radians30° units
Blue Rock Springs301.4°23.05.26010.045
Presidio Heights (Stine)240.9°30.04.2058.031
Lake Herman Road305.4°20.55.33010.180
Lake Berryessa323.3°47.85.64310.778

Near-integer hits across ten tested locations: 3 under the true-radian reading, 4 under the 30-degree reading. Expected by chance: 3.0. As a claim about the crime scenes, the radian theory is not supported by measurement.

The caveat, stated because it cuts against our own conclusion: two canonical murder sites — Blue Rock Springs and the Stine scene — land within 0.05 of exact 30-degree spokes. That pairing alone has roughly a 5 per cent chance of arising randomly. It is suggestive and it is not significant.

Was Z32 transposed, the way Z340 was?

The 340 defeated everyone for half a century because it was not a pure substitution: the text was written into a grid and read out diagonally before encipherment. Z32 followed seven months later, so the question asks itself.

Transposition only moves positions around — it cannot change which symbols repeat, only where the repeats land. So what it really changes is which plaintext positions the three equalities bind. We generated the plausible reading orders of a 32-cell layout and counted English fits for each.

SchemeFits in 6.3M letters
Columns, 4 by 8913
Columns, 8 by 41,143
Diagonal, 4 by 81,659
No transposition1,761
Columns, 2 by 161,843

Everything lands between roughly 900 and 1,800 — a spread of under two, against a baseline that is already hopeless. No scheme meaningfully out-constrains the plain reading, so none can be preferred on the evidence. Whether Zodiac transposed Z32 is simply not decidable from thirty-two characters.

That forecloses the most natural remaining hope, the one that says we just have not found the right scheme yet. For the 340 that hope was correct, and a search over roughly 650,000 candidate schemes paid off. At thirty-two characters the same search cannot pay off, because the ciphertext does not carry enough constraint to tell a right scheme from a wrong one.

The two ciphers fail for opposite reasons

The cleanest statement of how weak these are as evidence comes from the classical crib attack. Guess a word, slide it along the ciphertext, discard every position where it would force one symbol to stand for two letters. The attack's power is how many positions get discarded — and on a healthy cipher, nearly all of them do.

CipherPlacements testedLegalEliminated
Z322372188.0%
Z13623051.6%

Z32 eliminates eight per cent. With three repeated symbols across thirty-two positions, a guessed word fits almost anywhere you slide it, so guessing correctly tells you almost nothing about where it goes and the attack cannot converge. RADIANS, INCHES, BOMB, BURIED, NORTH and MAGNETIC are each legal at every offset.

Z13 eliminates half. Eight symbols repeating across thirteen positions is comparatively dense — the same fact that makes its answer sets small enough to write out.

The shape of the problem

Z13 is too short to have a unique answer. Z32 is too unconstrained to be attacked. Any strategy that works on one is the wrong strategy for the other.

Two placement results stand on their own. TORPEDO cannot be placed anywhere in Z13 — none of its seven possible offsets is legal — which independently explains why Garlick's reading needs the misspelling TOTPEDO rather than the word. And MY NAME IS cannot be placed either, so the cipher does not open by repeating the phrase the letter already says in plain handwriting.

The Z32 candidate set, bounded and mapped

Z32 cannot be uniquely solved, but the space is not unbounded once you take the sender at his word. Enumerating every grammatical bearing-and-distance instruction of exactly 32 letters that satisfies the three equalities:

Constraint appliedCandidates
Grammar and ciphertext, abbreviations allowed20,530
Requiring the full words RADIANS and INCHES403
Plus physical possibility: 1–12 inches, 0–12 units60

The physical filter comes from the objects, not from taste. A distance has to fit on a torn road-map panel, a sheet about a foot across; a bearing cannot exceed twelve units, because the compass rose he drew is marked 0, 3, 6, 9 and so has twelve to the circle.

Projecting the 60 survivors from the summit puts every one in the real Bay Area — Concord, Danville, Pleasanton, Oakley, Brentwood, Dublin, Oakland, Benicia. That the filter yields geography rather than open ocean is a modest check that the reading is coherent. The full set with coordinates is in data/z32_candidates.json.

A near-miss we talked ourselves out of

One survivor lands 2.3 miles from Lake Herman Road, another 2.6 miles from Blue Rock Springs. Counting candidate-site pairs within five miles gives four hits, and a Monte Carlo over the same distances with random bearings returns p = 0.031. That looks like a finding.

It is not. The Zodiac sites are themselves clustered around Vallejo, so one candidate landing there scores several hits when you count pairs. Counting distinct candidates instead, and across several radii:

RadiusCandidates near a siteExpectedp
3 miles20.590.114
5 miles21.590.487
8 miles74.010.083
10 miles96.620.187

Nothing is significant, and the answer swings with the threshold, which is the signature of no effect. The candidate locations do not preferentially land near Zodiac sites. We record it because the double-counted version is exactly the kind of result this case attracts, and the correction is worth more than the claim would have been.

Sixty-two solutions, all of them consistent

We recovered the exact claimed plaintext of every published Z13 and Z32 solution we could find and tested each one. The results are on the Claimed Solutions page in full.

CipherDistinct readingsConsistentRefutedNot judgeable
Z1398622216
Z3221797
The demonstration

Sixty-two mutually incompatible readings satisfy Z13 perfectly. They cannot all be right, and the ciphertext contains no test that separates them. Everything else on this page is an argument that these ciphers sit below unicity distance; this is that argument made concrete by other people's work.

The verdicts on the well-known proposals: ALFRED E NEUMAN is refuted by one constraint, MARVIN MERRILL and EARL VAN BEST JR by all four, and Garlick's reading is consistent in the spelling DREATATOTPEDO but refuted in DREATATORPEDO. Claims that are not symbol-by-symbol readings at all — Floe Foxon's polar-coordinate treatment of Z32, Ziraoui's numeric pipeline, anagram proposals — are marked not judgeable rather than refuted, because this test is the wrong instrument for them.

The eighteen characters at the end of Z408

Z408's message ends cleanly at “…my afterlife” and is then followed by EBEORIETEMETHHPITI, the third piece of unsolved Zodiac plaintext.

That these are filler is the mainstream reading and has been for decades — it is not our idea. It is also contested. The sharpest published objection asks why a man who could adjust a word to land on any length he liked would spend eighteen characters, more than a full line, on nothing. What follows is the evidence that argument has lacked, and an answer to that objection.

The anagram theory cannot be right

The long-circulating reading is that it anagrams to ROBERT EMMET THE HIPPIE. That phrase has twenty letters. The tail has eighteen. It cannot be an anagram of it, before any question of meaning arises. The variant spelling has nineteen. Both fail on counting.

Neither random nor language

The tail reads better than 97.2% of random padding drawn from his own alphabet — but only 0.8% of genuine English of the same length reads as badly. It is in a strange middle position, and that position has a specific cause.

He copied it from his own ciphertext

The tail contains a four-symbol run that also appears at position 128 of the body. In both places it decodes to the same four letters:

tail, positions 10–13   q E H M   →   M E T H
body, positions 128–131   q E H M   →   M E T H The body occurrence falls inside “to kill SOMETHing gives me the most thrilling experence”.

Monte Carlo over random eighteen-symbol tails from the same alphabet: P(sharing any four-symbol run with the body) = 0.0008.

How he padded

He copied a fragment of his own earlier ciphertext. That explains the statistics exactly: better than random because he was copying real enciphered English, worse than English because he took it from the middle of a word.

Why exactly eighteen

Z408 is written seventeen symbols wide and was mailed as three equal pieces, so the total must be a whole number of rows and the row count must divide by three.

TotalRowsSplits in 3?Filler needed
39123no1
40824yes18
42525no35
45927yes69
Why 18

From a 390-character message, eighteen is the unique minimum. Any smaller padding leaves a grid that cannot be cut into three equal whole-row parts. He did not waste eighteen characters — a 17-wide rectangle in three 8-row pieces charged him exactly eighteen.

The tail is not a signature, a name, or a hidden message. It is a man who had finished writing, needed eighteen more boxes to close the grid, and filled them from what he had already drawn.


What we actually think

Z13 is most likely a taunt, not a name moderate confidence

  1. The pattern fights male names at p = 0.0001. If he encoded his real name he chose a letter pattern only 8.5 per cent of male-named candidates can produce, against a 38.9 per cent base rate.
  2. He had just been dared. Z13 answers Dr. Marsh of the American Cryptogram Association, who challenged him to send a cipher that really did contain his name. A taunt is the in-character reply.
  3. Thirteen characters cannot be verified even if guessed, and he knew it — his 408 had been broken in a week. An unverifiable “name” is a joke at the solver's expense; a verifiable one would have been suicidal.
  4. He lied constantly about victim counts, the bus bomb, and the television caller.

If forced to name a plaintext, the Garlick-family reading through the genuine Z340 key is the least bad: it uses a key its author actually possessed and lands on an insult aimed at the man who provoked the letter. We rate it possible and unproven — 108th of 676 completions, and it needs a misspelling.

If Z13 is a name, it has a middle initial moderate, conditional

The simple-substitution first-plus-last set is 91.5 per cent female-typed and holds no plausible male candidate. Male names live in the first-plus-initial-plus-last set. Conditional on Z13 being a real male name enciphered without error, the answer is among those 420, whose most ordinary male entries are:

OATHER E NEWTON   ELIJAH A RAPIER   ANDREW E LEIDAL
EDISON O ROZIER   ISRAEL E NEGRIN   CASPER E HENSCH
ASHLEY E MECHAM   AUTHOR O KONTAK   CLEMON O KOPECK We attach no belief to any individual entry. None matches a known suspect.

Z32 is a real message about a location, and unrecoverable from the ciphertext alone high confidence

  1. It is a genuine cipher. Its repeat structure matches his own encipherment process on English almost exactly.
  2. It cannot be uniquely solved. 1,761 perfect fits in 6.3 million letters of unrelated prose.
  3. Its content is almost certainly a bearing and a distance from the Mount Diablo crosshair, following his own hint and the map he enclosed. Our best-supported candidate family reads in the form THE [number] INCHES [number] RADIANS TO NORTH.
  4. Key reuse is dead, which retires a family of published claims.

What would actually solve Z32 is not more computation. The ciphertext is information-theoretically exhausted. Only external evidence can settle it: a worksheet, a confession, a physical find, or a document in an unreleased file. That is why the FBI files matter more here than another million processor-hours.


For whoever picks this up next

The lasting contribution is not a solution. It is a set of hard constraints any future claim must satisfy, and a set of doors that are now shut.

Closed

  • Z32 as a one-to-one substitution — pigeonhole arithmetic.
  • Z32 by key reuse or by Zodiac's symbol habits — exhaustive search.
  • Any Z13 claim resting on a single encoding error — 3.67 million rivals.
  • A shared key between the two 1970 ciphers — two independent tests.
  • The radian theory as a claim about the crime scenes — measurement.
  • Solving Z32 by finding its transposition, as was done for the 340 — undecidable at this length.

Open, and worth a future model's time

  • The 420-name conditional answer set, cross-referenced against 1960s Bay Area records — motor vehicle, military, employment — rather than against national name frequencies. That is a records problem, not a cipher problem.
  • Z32 candidate locations tested physically, in the corridor defined by the 30-degree spokes on which two canonical murder sites happen to sit.
  • The unreleased portions of the case files. The ciphertext has no more to give; the archives might.

Every transcription, key, answer set and score behind this page is in data/ and research/ in this repository, so the next person starts here instead of from scratch.