At the end of Sir Thomas Urquhart's *Logopandecteision*, a book published in London in 1653, there is a cryptogram: sixty-four numbers, arranged in two lines of thirty-two. 5.3.27.38.32.14.21.8.66.8.70.39 and so on, sixty-four integers separated by dots, followed by nothing. No key, no instructions, no hint beyond its position in the book — printed immediately after thirty-two short prose passages that Urquhart called the Proquiritations, and a poem promising that an honest reader would find in the cipher "his own heart's wishes, and the Author's minde."
The distich, as it is called, stayed unsolved for three hundred and seventy years. It was posed as an open problem in *Notes and Queries* in 1899. It passed through twentieth-century cryptography literature. It sits on Klaus Schmeh's list of the fifty most famous unsolved encrypted messages. Generations of solvers ran the standard tools against it — frequency analysis, substitution, homophonic substitution — and got nothing, because there was no substitution layer to analyze. In the late summer of 2026, an AI researcher gave the puzzle to a large language model, Claude Fable 5.1, with no instructions beyond "solve it." Forty-four minutes and 176,000 tokens later, the model returned a solution.
The rule, once stated, is almost embarrassing. For the i-th number in a line, go to the i-th Proquiritation, count to the word at that position, and take the first letter of that word. That is the entire cipher. The key was never a mapping of numbers to letters. The key was the book itself: the number is a coordinate — paragraph, word, letter — into the very text the cipher is printed inside. Apply the rule to the first line and you get O GOD UPHOLD KING CHARLS THE SECOND. Apply it to the second and you get AND MAKE HIM THE SUPREME RULER OF THIS LAND. Thirty-two letters a line, a rhyming couplet, a prayer for the exiled Charles II — written by Urquhart, a committed Royalist, in a book published while the king's return was still a hope rather than a fact.
The clues were never hidden. There are thirty-two Proquiritations and thirty-two numbers per line, and Urquhart goes out of his way to emphasize the number: "there can no number like that of two and thirty … be pitched upon." The accompanying poem promises "wishes." Every Proquiritation ends with a formula like "is the desire," "wish," or "hope of" — the very word the model needed to notice to try the rule. The solution was announced in plain sight, and it survived three hundred and seventy years of professional attention because every solver's method presupposed an external key, and the announcement was, by the light of that method, decoration.
Here is the property that matters. Once the rule is known, checking the solution takes minutes. Apply the rule, read the letters, verify the verse rhymes, scans, and matches the author's known politics. The check is mechanical, and it was mechanical in 1653: anyone with the book and the rule could verify the plaintext in an afternoon, and anyone with the rule and the plaintext could be certain the rule was right, because a wrong rule does not yield a metrically perfect thirty-two-letter couplet. The asymmetry is the entire episode in miniature: the search took three hundred and seventy years of human attention; the check takes five minutes of anyone's.
That asymmetry — hard to find, trivial to verify — is rare among intellectual claims and common in exactly two places. The first is bookkeeping. The check digit at the end of an ISBN, the Luhn digit on a credit card number: these exist for no other reason than that verification should cost one arithmetic pass, so that every keystroke, every scanner beep, can afford to run it. Society deliberately added the five-minute check to its numbers because it knew that discovery of errors is expensive and checking them is cheap, and that the cheap check, run everywhere, catches almost everything. The second place is proof-of-work consensus: the entire security of a blockchain rests on the same asymmetry, engineered rather than accidental — finding a hash below the target costs a fortune in computation, checking it costs one hash. The system is built so that millions of parties verify what one party found, precisely because verifying is the cheap operation.
The cipher is the accidental member of this family. Nobody designed the distich to be hard-to-find and easy-to-check; its construction happened to make it so. And the accidental version of the asymmetry produces an interesting failure in the institutions around it. The machinery of slow verification — peer review, replication, months of scrutiny — is sized for claims where checking costs as much as discovering. A claimed decryption is not such a claim. It is checkable in minutes, and the machinery has no fast lane: when a solve is announced, the community applies the slow ritual anyway, days of excitement and doubt, because the ritual is what it has. The delay is not caution. It is the wrong tool, applied on schedule.
The model's contribution was not cleverness. It was the ability to try candidate rules at a cost of nothing per attempt — 176,000 tokens of patient, unembarrassed trying, in forty-four minutes. The researcher who ran the experiment had spent months asking frontier models to solve unsolved ciphers; no other model had produced a verified solve. What made this one work, by the account of the people who ran it, was not cryptographic insight but persistence: it kept looking until it found the rule, and it knew when a problem was not budging. The bottleneck it removed was not computational. It was the cost of attention — the price of spending hours reading obscure seventeenth-century prose and testing ideas that mostly go nowhere. That bottleneck, for this class of problem, has just disappeared.
The five-minute check was available in 1653, and it was never run, because nobody had found a rule worth checking. That is the real lesson, and it is an economic one. The price of the solution was not cleverness; it was the cost of a candidate — the hours of reading obscure seventeenth-century prose, testing a rule against sixty-four numbers, discarding it, and starting again. Human attention prices candidates at hours each, which is why 370 years of occasional effort never finished the search. The model prices candidates at effectively zero, which is why forty-four minutes finished it. The bottleneck was never intelligence and never verification. It was the price per attempt, and the price per attempt is exactly what the new machinery collapsed. Every field whose open problems are bottlenecked by the cost of trying — not by the difficulty of the thing tried — is about to experience the same collapse, and the ones that have built a fast verification lane will absorb it; the ones still running the slow ritual will spend days doubting claims that were checkable in minutes.
The sharpest fact in the episode is what it predicts. The same researcher's model, the same day, applied the same rule to the second, much larger cryptogram Urquhart left — the Cyphral Octastich in *The Jewel* of 1652, two hundred and eighty-five numbers — and solved it too: a royalist prayer in ottava rima, dated in its own plaintext, most positions exact on the first try. The family of unsolved ciphers is full of texts that were never hard, merely unexamined, and they will now fall in bulk, each one in minutes, each checkable in five. What will remain unsolved are the ciphers where no rule exists to be found — the underdetermined, the keyless, the genuinely strong. Those are a different problem, and the cheap attention will not touch them. The five-minute check only works when there is something to check.