Research Using LLMs on cicada3301
Research status report
Cicada 3301: Verified Structure, Open Payloads, and the p54 Evidence Boundary
A disciplined account of what the project archive establishes, what the p54 work constrains, what repeated tests have ruled out, and what remains unresolved.
Publication note: this article contains research findings only. Personal information, account data, private locations, execution-environment details, source-system identifiers, and file metadata are intentionally excluded.
Executive summary
The project has produced a reproducible structural result on Liber Primus page 54, but it has not decrypted the page’s second-layer payloads. The strongest defensible claim is that a first-layer control scaffold can be reconstructed from the normalized rune transcription and that this scaffold separates two payload families. Later work further identifies a highly constrained local object and a narrow routing model. Neither result is equivalent to plaintext.
First-layer p54 scaffold
The public verifier reproduces the page length, control-marker positions, frozen A/B streams, payload sizes, terminal index mapping, and a complete compact scaffold score.
Schedule-coordinate fit
Full control-coordinate coverage survives some ablations, but two terminal values depend on a frozen SSSS formula ledger whose primary chronology has not been independently established.
No payload plaintext
Short-period Vigenère, generic Liber Primus running-key reuse, and several window-optimized candidates do not provide a reproducible page-wide decrypt.
Global mechanism
The A-family and B-family payloads remain unread. The relationship between local p54 structure and any page-wide cipher is still unknown.
Background
Cicada 3301 is the name attached to a sequence of public cryptographic puzzles that combined classical ciphers, steganography, signed messages, software artifacts, audio, imagery, and a runic writing system known as Gematria Primus. The project archive preserves material from the major puzzle rounds, authenticated communications, community tools, and Liber Primus research.
Liber Primus is the central unresolved artifact: a book written in a 29-rune alphabet. The archive’s own index describes a 75-page corpus and reports that only a minority of pages have accepted solutions. The present project therefore treats every new result as one of three things: a reproducible fact, a constrained interpretation, or an unresolved hypothesis.
Claim discipline
A structure that scores well, aligns with external numbers, or supports plausible words is not automatically a decryption. Plaintext status requires an independently reproducible transformation that explains the full target region without post-hoc tuning.
Terminology and notation
This report uses both established Cicada 3301 terminology and project-specific analytical labels. The definitions below state how each term is used here.
Important distinction. Terms such as scaffold, router, front superwindow, and transduction describe analytical models created during this research. They are not words recovered from Cicada plaintext and are not claimed to be the puzzle authors’ own terminology.
Corpus and text
- Cicada 3301
- The name associated with a series of public cryptographic puzzles and their authenticated signed communications. It also serves as a convenient name for the preserved puzzle corpus.
- Liber Primus
- The runic book released through the Cicada 3301 puzzle sequence. Some pages have accepted solutions, while much of the book remains unresolved.
- Gematria Primus
- The 29-symbol runic alphabet and numerical system used by Liber Primus. Each rune has a transliteration and an associated numerical value.
- Rune
- One symbol in the Gematria Primus alphabet. In computational work, a rune is normally represented by a normalized text token.
- Token
- One normalized unit read from the transcription. Token counts are used to verify page boundaries and to make positional tests reproducible.
- Transcription
- A machine-readable representation of the runes and markers visible on the page images. It is the input to the project’s verifiers and cryptanalytic tests.
- p54 / p55
- Short forms for Liber Primus page 54 and page 55 in the project’s transcription and page-numbering convention.
- Plaintext
- Human-readable text produced by a reproducible decryption rule. A plausible word, local alignment, or structural label is not considered plaintext by itself.
p54 structure
- First layer
- The reproducible structural parse performed before any proposed second-layer decryption. It identifies markers, separates payload families, and records positional relationships.
- Control scaffold
- The stable first-layer arrangement of markers, boundaries, payload partitions, and index relationships on p54. “Scaffold” describes organization, not decoded prose.
- EA marker
- The project’s label for eight distinguished marker tokens on p54. The report retains EA as an identifier and does not invent an expansion that the evidence does not establish.
- Source position / source0
- A position in the normalized p54 token stream. source0 specifically means zero-based indexing, so the first token has position 0.
- pidx
- A derived page-index coordinate used by the control-scaffold model. It must not be confused with the source position from which it was calculated.
- A/B-family payloads
- The two stable streams isolated by the first-layer parse. Their boundaries and lengths are reproducible; their second-layer plaintext is not known.
- Payload quarantine
- The discipline of keeping the A- and B-family streams separate from control markers and from unverified plaintext assumptions during analysis.
- Terminal band
- The final structured region of p54 examined as two eight-rune cells. Its segmentation is useful, but it has not yielded accepted plaintext.
- Front superwindow
- The project’s name for the highly constrained local region around positions 134–167. It is treated as a local relation object rather than a solved sentence.
Evidence and testing
- SSSS
- The project label for a seven-row offset dataset extracted from preserved puzzle material. The abbreviation is retained as a dataset name; this report does not assert an unsupported expansion.
- Residue
- The numerical result of applying a declared modular or offset formula to a raw value. Every evidentiary residue should retain its source row and generating formula.
- Formula family
- A set of transforms declared before target scoring. Predeclaration limits the risk of choosing a formula only because it reaches a desired coordinate.
- Strict source0 target
- A control position that must be matched directly in the zero-based p54 source coordinate system.
- Coordinate graph
- A broader analytical model connecting source positions, derived coordinates, external numeric anchors, and proposed route relationships.
- Frozen ledger
- A recorded set of input rows, formulas, and derived values treated as fixed for later tests. “Frozen” means unchanged during those tests; it does not by itself prove that the formulas were selected independently or early enough.
- Ablation
- A test that removes one evidence unit or input class and measures which findings survive. It helps identify hidden dependencies.
- Null control
- A randomized or deliberately non-informative comparison used to estimate how often a score or coverage level could arise without the proposed structure.
- Holdout test
- An evaluation on positions or evidence not used to tune the candidate. Failure on holdout data is a strong warning of overfitting.
- Entry router
- A node in the project’s route model that can receive an upstream selection and direct it into a constrained downstream path. It is an analytical role, not decoded text.
- Transduction law
- The still-missing rule that would justify converting the selected page7 state into the page27 entry-router state without choosing the target after inspection.
Methodology
The research combines archival verification with controlled cryptanalytic experiments. The working discipline is intentionally conservative:
- Ground the corpus. Compare the project index, original puzzle assets, rune transcriptions, archive inventories, and solved-page references before treating a file or number as novel.
- Freeze indexing conventions. Declare source indexing, page indexing, rune normalization, marker handling, and formula families before scoring a candidate.
- Separate layers. Keep first-layer control structure, candidate payload streams, local geometric objects, and proposed plaintext in distinct evidence classes.
- Use ablations and null controls. Remove suspect evidence units, shuffle inputs, and compare candidate scores against randomized baselines.
- Audit provenance. Record which raw value and which predeclared transform produce every derived coordinate.
- Preserve negative results. Failed cipher families and non-generalizing local hits are retained as constraints rather than discarded.
Research basis. The article synthesizes the project archive overview, the Liber Primus package inventory, the p54 public-verifier specification, the p54/167/SSSS audit, the SSSS provenance and formula-chronology audits, the global/local reconciliation, and the later p54 routing audits. Source-system identifiers and file metadata are not reproduced.
Verified findings
-
Verified
Normalized page sizes. The project verifier reads 232 tokens on p54 and 76 tokens on p55 from the master transcription.
-
Verified
p54 control markers. The eight EA markers occur at source positions 48, 52, 54, 73, 135, 151, 211, 228 under the frozen indexing convention.
-
Verified
Payload quarantine. The first-layer parse yields stable A- and B-family streams with lengths 91 and 57. Their stability is a structural result; their contents remain undecoded.
-
Verified
Terminal mapping. The terminal page index at source position 219 maps to 320 in the frozen scaffold.
-
Verified
Known identity of 167. The archive traces 167.jpg to a known 107 / 167 / 229 image triad and to a solved Liber Primus range associated with the key phrase FIRFUMFERENFE. It is a fixed provenance anchor, not a newly discovered plaintext source.
-
Constrained
Local p54 object. Positions 134–167 form the strongest validated local relation object on the page. The object has stable internal geometry and phase behavior, but its former English anchor labels are not independently established as plaintext.
Negative results
Negative evidence materially narrows the search space. The following results should be treated as active constraints:
| Tested line | Result | Consequence |
|---|---|---|
| Short-period Vigenère families | No reproducible page-wide solution | Do not promote local word-like hits as a global key. |
| Running-key reuse from other Liber Primus material | Null at the page level | Generic internal-text reuse is not supported. |
| Window-optimized candidates | Many hits fail holdout or transfer tests | Treat earlier high-scoring windows as overfit unless independently reproduced. |
| Page-37 running-key signal | Statistically unusual but fails to reproduce the front anchors | Interesting anomaly; not a recovered key. |
| v9 terminal-band parsing | Two clean eight-rune cells, but no direct plaintext | Retain the segmentation; freeze further route expansion pending provenance work. |
| A1/A2/B1 payload attacks | No accepted plaintext | The central cryptanalytic problem remains open. |
p54 and SSSS findings
What the first-layer verifier establishes
The minimal verifier reconstructs a complete compact first-layer scaffold from the transcription and passes a deterministic shuffle sanity check. It confirms the control-marker layout, frozen A/B streams, payload sizes, and terminal mapping. This is the project’s strongest directly reproducible p54 result.
The external-coordinate claim and its caveat
An external-coordinate audit reported coverage of all 10 strict p54 control targets and all 17 nodes in a broader coordinate graph. In its random-replacement experiment, no random trial matched the observed full coverage. This supports the view that the p54 scaffold contains meaningful schedule-like structure.
However, the result is not cleanly “external-only.” The imported SSSS panel was:
[53, 53, 91, 153, 229, 217, 226]When the seven raw SSSS offsets were recomputed under the formula family visible in the audit record—modulo 232, neighboring offsets by one and 104, and the 320 complement—the strict p54 targets reproduced only 53; the broader graph intersections were 53, 62, 153, 167. The complete seven-value panel therefore does not follow from that visible formula family alone.
Current evidence boundary
Full schedule coverage can survive removal of one disputed SSSS row, but the remaining terminal values 217 and 226 depend on two formulas preserved in a later frozen ledger. The project has not yet established from the primary earlier artifact that those formulas were fixed before the target values were evaluated. The fair description is frozen-ledger-dependent schedule coverage, not independently verified external-only prediction.
Terminal-band and routing model
The terminal band contains two eight-rune cells at 212–219 and 220–227 under the current parse. Markers at 216 and 226 are better modeled as operations applied after phase parsing than as runes deleted before parsing. This is useful structure, but it has not produced plaintext.
Later graph audits narrow the routing model further. Under the tested constraints, page 27 is the only coherent entry-router target among the principal rivals, and the downstream closure through pages 18 and 22 is fixed within that model. Page 7 is already selected by the OR-side surface and already points to page 27 in the relevant read order. The unresolved item is the transduction law that authorizes that promotion. This is a constrained model, not a historical fact about the cipher’s design.
Liber Primus and archive status
The project archive is broad: its index describes more than five thousand files organized across puzzle rounds, authenticated messages, original assets, community solver collections, reference material, and multiple representations of Liber Primus. The archive reports 75 original Liber Primus page images and approximately 17 solved pages. Those figures are archive-level status statements, not a claim that this report independently revalidated every page solution.
The supplied Liber Primus package inventory
The separate package inventory contains numbered page images from 0 through 57, together with cover, title, chapter, and key images plus an audio track. It is therefore a useful, internally coherent package, but it should not be mistaken for the complete 75-page research corpus described by the main archive.
Numbered package sequence
The listing provides a continuous numbered image run from 0 through 57.
Not the canonical full set
The package’s numbered sequence is narrower than the archive’s 75-page Liber Primus corpus.
The archive’s last known authenticated communication is reported as occurring in 2017. No later message should be treated as authentic without successful verification against the preserved Cicada signing key.
Interpretation
The evidence favors a layered reading of p54. A control or schedule layer appears to organize the page before any second-layer payload decryption. The reproducible first-layer scaffold, marker placement, payload separation, terminal mapping, and non-random local geometry all point in that direction.
At the same time, the project’s strongest correction is epistemic: local structure does not imply global plaintext. The front superwindow can be real as a relation object while the proposed English anchors remain unverified. Likewise, a coordinate graph can be informative while still depending on a formula ledger whose chronology needs auditing.
The best current model is therefore:
- p54 has a reproducible first-layer control scaffold.
- The scaffold separates stable but unread A- and B-family payloads.
- A constrained local object and route graph provide additional structure.
- The global cipher family and the page7-to-page27 transduction rule remain unknown.
Limitations
- The archive combines primary artifacts, community reconstructions, research notes, and generated outputs. Their evidentiary weight is not uniform.
- The master transcription and indexing conventions are necessary inputs; transcription or normalization errors could propagate into downstream claims.
- Randomized baselines test the declared search space, not every possible source of selection bias.
- The chronology of two SSSS formulas has not been verified from the primary earlier package.
- The p54 routing graph is a constrained analytical model. Its nodes and edges should not be described as decoded instructions without an independent cipher mechanism.
- The archive-reported solved-page count may change as community standards or accepted solutions change.
Reproducibility
A clean reproduction should be possible without access to personal data or private environment details. The minimum protocol is:
- Obtain the normalized master rune transcription from the research archive.
- Declare the rune normalization and source-position convention before extraction.
- Assert the p54 and p55 token counts.
- Extract the eight p54 EA positions and rebuild the frozen A/B first-layer streams.
- Assert the A and B payload lengths, the terminal source position, the mapped terminal index, and the compact scaffold score.
- Run a deterministic shuffle control to confirm that the observed scaffold is not routinely reproduced by reordered input.
- For the SSSS claim, begin only with the seven raw offsets and a predeclared formula registry. Emit every derived value together with its source row and formula.
- Report strict p54 coverage, broader graph coverage, all ablations, and all missing targets. Do not import the seven-value panel as an unexplained input.
Reproduction is successful only if the first-layer scaffold is recovered without hand-edited target alignment. Reproducing the scaffold does not count as reproducing payload plaintext.
Next research priorities
Close the SSSS derivation ledger
Recompute every panel value from the seven raw rows using a frozen formula registry. Identify exactly which additional formulas are required and when they first entered the analysis.
Verify formula chronology
Inspect the primary earlier p54 package to determine whether the formulas producing 217 and 226 were declared before those targets were scored.
Test the page7 transduction
Search for a source-side rule that turns the selected page7 state into the page27 entry-router state without choosing page27 post hoc.
Return to payloads only after provenance
Resume A/B payload attacks with models that preserve the verified scaffold and local constraints. Require holdout tests and page-level generalization.
Conclusion
The project has moved p54 from an undifferentiated ciphertext page to a reproducible layered object. Its first-layer scaffold, control positions, payload separation, terminal mapping, and local geometry are substantive results. The archive also resolves the identity of the 167 image reference and clarifies the scope of the supplied Liber Primus package.
What has not been achieved is equally clear: there is no accepted A- or B-family plaintext, no validated page-wide key, no independently complete derivation of the SSSS panel, and no proven rule connecting the selected page7 state to the page27 router. The most useful next step is not broader speculative search, but tighter provenance: freeze the formulas, verify their chronology, and require every future plaintext claim to survive reproducible, page-level tests.