← Case page: The Beale CiphersHistorical MysteriesFull report · 14 September 2026Researched and written by Claude, an AI system, from the sources each case cites. Claude also drew the maps and charts marked "made for this report" from the data named in their captions.

Lynchburg, Virginia · a pamphlet of 1885

The Beale Ciphers

An 1885 Lynchburg pamphlet says three pages of numbers written by Thomas J. Beale in 1822 point to gold and silver buried in Bedford County, Virginia. Only one page has ever been read. Cryptanalysts built the case that all three pages are a hoax between 1979 and 2013. Here that case is re-run from the pamphlet's own text, with statistical, stylistic and archival checks added.

The story the pamphlet tells

In 1885 a printer in Lynchburg, a town in central Virginia, issued a pamphlet called The Beale Papers, price fifty cents, with the copyright in the name of J. B. Ward. Its author, who gives no name and is called the narrator below, tells this story. In January 1820 a stranger named Thomas J. Beale came to Lynchburg and took rooms at the Washington Hotel, kept by Robert Morriss, a merchant of the town. Morriss remembered him as "about six feet in height, with jet black eyes and hair of the same color", a popular guest. He stayed until spring, and came back for the winter of 1822. Before leaving that spring he handed Morriss a locked iron box and asked him to keep it. A letter from St. Louis dated 9 May 1822 told Morriss to open it if no one called for it within ten years, and said that a key to the papers inside, left with a friend in St. Louis, would be delivered to him in June 1832. Morriss heard nothing more from Beale, and the key was never delivered. Morriss opened the box in 1845 and found three pages of numbers and letters signed T. J. B. The letters tell of thirty Virginians who went west in 1817 to hunt buffalo, found gold and silver in a ravine some 250 or 300 miles north of Santa Fe, then a Spanish town, mined it for years, carried it home and buried it in Bedford County, Virginia, the next county west of Lynchburg. Paper 1 gave the location of the vault, paper 2 its contents, paper 3 the names of the party and of their heirs. The pamphlet calls the three pages papers 1, 2 and 3; later writers call them ciphers 1, 2 and 3, and this page does the same.

In 1862 Morriss, by then in his eighties, handed the papers to a friend, and that friend says he read cipher 2 by accident. Each page is a list of numbers, and he found that if the words of the Declaration of Independence are numbered from 1 upwards, each number in cipher 2 stands for the first letter of the word with that number (a book cipher, in the language of code-breaking; the text whose words are numbered is its key). Read that way, cipher 2 becomes a message describing 2,921 pounds of gold, 5,100 pounds of silver and jewels in a vault four miles from Buford's, a tavern in Bedford County, six feet down. He could not read ciphers 1 and 3. After more than twenty years he published everything and invited the public to try.

Why it is still argued

Ciphers 1 and 3 have never been read. No record of a Thomas J. Beale, of his party or of the box has ever been produced. Nobody knows who wrote the pamphlet: the narrator gives no name, and Ward, who held the copyright, called himself the author's agent. The question stays open because of the page that does read. Cipher 2 is a working cipher: it has a key, and the key produces a coherent message. So either Beale's party existed or someone wrote a treasure story and enciphered part of it.

Those who take the story as true point to that message and to the numbers themselves. Carl Hammer, a computer scientist with the Univac company, ran the ciphers through a computer in 1971 and found that the unread pages were not random numbers; he and the Beale Cypher Association, a society of enthusiasts formed to work on the ciphers, concluded that they encoded something. By January 1893 the Roanoke Times, a newspaper in the next city west, could report that "the inhabitants of Bedford county have hunted for this treasure but so far in vain"; in 1972 a group of believers calling itself the Beale Cypher Study Committee was still paying for searches of the archives.

The sceptics' case was made between 1980 and 1993. Jim Gillogly, a cryptanalyst, tried the Declaration key on cipher 1 in 1980 and found that, although the result was not English, one stretch of it spelled the alphabet in order, which he took to show that a hoaxer had written that part of the cipher from the numbered key. Joe Nickell, an investigator of hoaxes and forgeries, showed in 1982 that Morriss did not keep the Washington Hotel before 1823 and that the "Beale" letters and the narrator's own account read like one hand. John C. King, a cryptanalyst, worked out in 1993 exactly how the Declaration had to be numbered for cipher 2 to decode cleanly, and reported longer alphabetical runs in cipher 1 under that numbering. That work appeared in Cryptologia, a specialist journal of code-breaking, and in the enthusiasts' newsletter, and the popular accounts barely mention it, so the ciphers are still presented as an unsolved treasure puzzle.

How the case was judged

The evidence used here is the pamphlet's own text, transcribed from the Library of Congress copy: its three ciphers, the Declaration exactly as it prints and numbers it, its printed translation of cipher 2, the three letters and the narrator's account. To that are added the Lynchburg newspapers of the 1820s, the records of Spanish New Mexico as searched in 1972, the files on the ciphers that the National Security Agency, the United States code-breaking agency, released from its archives, and 115 samples of writing by 27 American authors of the period, used for comparison. The methods are these: decode cipher 2 with the pamphlet's own numbering and see where that numbering goes wrong; calculate how likely an alphabet in cipher 1 is by chance; compare the three ciphers as sequences of numbers; measure the letters and the narrative against the comparison authors; date the letters' vocabulary against the printed record of the time; and check the story's dates and places against the newspapers and archives.

What came out is a verdict that the pamphlet is a hoax: about 95 percent, as a judgement that combines several lines of evidence. The case has two halves. The first is about the ciphers. The pamphlet prints the Declaration with a number after every tenth word, and that count is wrong in five places; each error is one that the person who turned the message into numbers (the encoder, from here on) made, so the simpler reading is that whoever prepared the pamphlet had the encoder's own working key, although the story says that no key ever arrived (section 1). Cipher 1, decoded with that same miscounted key, contains three stretches of alphabet in order, seventeen letters at the longest, and the chance of that arising by accident in a book cipher keyed to the Declaration is about one in twenty million by exact calculation under the most generous model of chance tested (section 2). Cipher 3's numbers drift and climb in a way that enciphering a list letter by letter does not produce, and its 618 numbers cannot hold the thirty names with heirs and residences it is said to contain (section 3).

The second half is about the story and its author. The three "Beale" letters and the narrator's own prose share the involuntary habits of one writer: on the measures used, the closeness between them is 3 to 25 times more likely if one person wrote both than if two did, depending on the measure (section 4). The letters use words that came into use decades after 1822 (section 4). The story's one checkable date is also wrong: Morriss's own newspaper notices show that he rented the Washington Hotel in September 1823, more than three years after the January 1820 of the story, and every documented American party that reached Spanish New Mexico between 1812 and 1819 was arrested (section 5).

In outline, none of this is new: Gillogly, Nickell and King made the case between 1980 and 1993. This page re-runs it from the pamphlet's own text, puts numbers on the parts that had none, adds Morriss's newspaper notices and the 1972 archive search, and states how much weight each line of evidence can carry.

The page goes through the evidence in that order. Section 1 shows that the printed key carries the encoder's miscounts. Section 2 examines the alphabet in cipher 1 and computes how unlikely it is by chance. Section 3 compares how the three ciphers behave as sequences of numbers and tests whether cipher 3 could hold what it is said to hold. Section 4 asks whether the letters and the narrative were written by one hand, and which of the letters' words belong to 1885. Section 5 checks the story against the Lynchburg newspapers, the records of Spanish New Mexico and the pamphlet's own copyright line. Section 6 puts the strongest objections and answers them. Section 7 says what evidence would overturn the verdict. Section 8 separates what earlier writers established from what is added here. Section 9 lists the sources and the code. Before those sections come the verdict, claim by claim, and a table of the six lines of evidence.

Verdict: a hoax.strong evidence · about 95 percent, as a composite judgement

The evidence for a hoax is strong: it leaves little room for another answer. The verdict is still a reading of the documents, and a new document could change it (section 7 says which). Each claim in the table carries its own confidence. The percentages are judgements rather than measurements, except where a probability was computed and is labelled as one.

ClaimConfidence and what it rests on
The three alphabetical strings in cipher 1 were put there deliberately rather than arising by chance.Beyond reasonable doubt under every model of chance tested: a probability of 4.9 × 10⁻⁸, about one in twenty million, by exact calculation under the most generous of them, and no such run in a million random reorderings of the cipher's own numbers. Gillogly (1980) found the passage; King (1993) reported the longer strings under the reconstructed key, and J. A. Hill, in an unpublished paper of 1989, had found them independently. The probabilities are computed here.
Cipher 1, as printed, is not an ordinary book-cipher encipherment of a message.About 99 percent, as a judgement. King left one alternative open: that the Declaration is the true key and a further layer of encoding hides the text. Statistics cannot exclude it, and nothing supports it.
The pamphlet's printed key and instructions cannot produce its printed translation, and its word-numbering matches the cipher-2 encoder's count at each of his five miscounts.Established by counting, and anyone can repeat it from the pamphlet's text (section 1). Whether the narrator had the encoder's working key (the simpler reading) or reconstructed the miscounts himself (possible in principle, section 6) is a judgement, and it feeds the line below.
The story is a fiction: no Beale party, no vault.About 95 percent, a composite judgement. It combines the two claims above and the simpler reading of the printed key with the Morriss hotel dates, the Santa Fe record and the language of the letters. Each line has an alternative explanation; for the story to be true, every one of them would have to hold at once.
The anonymous narrator wrote the "Beale" letters.About 90 percent, as a judgement. Stylometry, the statistical comparison of writing habits, calibrated here on 27 authors with the texts cut to equal length, gives likelihood ratios of 3 to 25 depending on the measure (25 for cosine Delta without pronouns and for character 4-grams, 6.6 for function words, 2.7 for Burrows Delta; section 4 explains the measures), which with even prior odds is 73 to 96 percent; the reflexive-pronoun habit adds to that. The alternative is a narrator imitating letters he says he memorised.
The narrator was James B. Ward.This is not established. Ward held the copyright and called himself the author's "agent"; no record names the author.

The statistics do not show that no further encoding exists in cipher 1, who wrote the pamphlet, or that every part of the story is invented. Those conclusions rest on the other lines of evidence and on judgement, and the table says which.

The evidence at a glance

Line of inquiryFindingWeightStatus
The printed keyThe pamphlet's word-numbering reproduces the encoder's five miscounts and decodes cipher 2 correctly at 740 of its 762 numbers; a plain count of the same text gets 161 wrong. The numbers appear to have been transferred from a copy other than the one the printer set. Decisive if the narrator had the encoder's key, which is the simpler reading; not on its own (section 6).●●●○ strongRepeats what Matyas (1979), Hammer (1979), Holst (1987), King (1993) and Love found (all five are introduced in section 1); new here: the offsets fitted from the cipher alone and matched to the printed numbers, and the typesetting argument
Alphabet in cipher 117-letter run A to O under the encoder's key, plus two 11-letter runs; probability below 5 × 10⁻⁸ for the run by calculation, and none in a million reorderings. Six of its twenty numbers are the first word in the Declaration with that initial.●●●● decisiveGillogly (1980) found the passage and drew the inference; King (1993) reported the three longer strings under the reconstructed key, and Hill (1989) had found them independently; reproduced here, with exact probabilities and a test of which of the available words the writer chose for each letter added
Behaviour of ciphers 1 and 3Neither decodes to English-like letters with the Declaration. Cipher 3 has drift and rising runs no letter-by-letter encoder produces, and 618 signs cannot hold the promised list of thirty names, heirs and residences (minimum 792 ± 19 letters).●●●○ strongThe objection that 618 numbers cannot hold the list, made in 1927 (Crossen) and by the cryptologic historian Louis Kruh in 1982, is quantified here; the tests of how cipher 3's numbers run in sequence appear in none of the accounts that could be read
Authorship of the lettersLetters and narrative closer to each other than 95 to 100 percent of pairs of texts by different authors, depending on the measure; reflexive pronouns with nothing to refer back to ("like myself") at six to ten times the rate in other writers. Edgar Allan Poe, sometimes proposed as the author, excluded.●●●○ strongPuts a number on the common-authorship claim of Nickell and the linguist Jean Pival (1982) and of Kruh (1988)
Language datingWords that came into use after 1822 make up 0.85 percent of the distinct content words in the letters, against 0.19 percent in genuine texts of 1805 to 1843 (a gap of 4.1 standard deviations). "Stampede" is not the anachronism Nickell thought; "objective point" and "grizzlies" are the strong items.●●○○ moderateCorrects Nickell's dates; two new candidates
The historical recordMorriss's own newspaper notices show he rented the Washington Hotel in September 1823 and left it at the end of 1825; the pamphlet has him keeping it in January 1820 and January 1822. No record that could be read names a Thomas J. Beale; thirty Americans wintering openly in Spanish Santa Fe in 1817 to 1818 contradicts every documented party of those years.●●●○ strongNickell (1982) confirmed from the primary notices, with exact dates; the Santa Fe objection and the declassified 1972 archive search appear in none of the accounts that could be read

Weight is a judgement of how much each line moves the genuine-or-hoax question on its own. The first two lines carry the verdict on the ciphers; earlier cryptanalysts established both, and they are reproduced here. The other four bear on who wrote the pamphlet and when.

1. The printed key carries the encoder's own miscounts

The pamphlet prints the Declaration of Independence "by the assistance of which its hidden meaning was made plain", with a number in parentheses after every tenth word, and tells the reader to compare cipher 2 "with the corresponding numbers of the initial letters of the consecutive words". The key used here is rebuilt from the pamphlet's own text and numbering (the Library of Congress copy, as transcribed on Wikisource, the volunteer transcription site, pages 17 to 20), and cipher 2 is decoded with it.

The printed count is wrong in five places, and each error matches a miscount made by whoever enciphered cipher 2.

Printed labelsWords between themWhat happenedOffset the encoder used from here
(240) … (250)11one word of "invariably the same object evinces a design" counted as nothing+1
(480) … (480)10the label printed twice: the whole line "he has refused for a long time after such dissolutions" numbered as if absent+11
(500) … (510)9"mean time" counted as two words although the pamphlet prints "meantime"+10
(630) … (640)11one word skipped in "of peace standing armies without the consent of our legislature"+11
(670) … (680)11one word skipped in "unacknowledged by our laws giving his assent to their acts of"+12

Decoded with the printed numbering, cipher 2 gives the printed message at 740 of its 762 numbers. The 22 misses are all of one kind: nine uses of 811 where the message needs a y, four of 1005 where it needs an x, three of 95 where it needs a u, and six adjacent-number slips (84 for 85 twice, 53 for 54, 108 for "10, 8", 440 for 40, 96 for 95). No word in the Declaration begins with x or y; the encoder used the last letter of "fundamentally" (811) for y, a number beyond the printed numbering (1005) for x, and "unalienable" for u, which the pamphlet prints as "inalienable". Decoded instead with a plain count of the same printed text, 161 numbers come out wrong, one in five. A plain count of the standard text, as transcribed by the National Archives, gets 139 wrong, and Gillogly's 1980 numbering 140.

A second check leaves the printed labels out of it. A computer search (a dynamic programme) finds the best division of cipher 2 into stretches, each with its own constant offset from a plain word count, and it is told nothing about where the labels fall. It returns offsets 0, +1, +11, +10, +11, +12, with the changes falling between cipher numbers 241 and 246, 466 and 485, 505 and 511, 620 and 643, and 666 and 807. Those five change points coincide with the five places where the printed count goes wrong (Figure 1).

Offset between the cipher-2 encoder's word numbers and a plain word count, by cipher number, with the pamphlet's printed numbering anomalies +0 +4 +8 +12 0 250 500 750 1000 cipher-2 number (word number in the encoder's Declaration) (250) (480) twice (510) (640) (680) 1 = When (offset +0) 2 = in (offset +0) 3 = the (offset +0) 4 = course (offset +0) 5 = of (offset +0) 6 = human (offset +0) 7 = events (offset +0) 8 = it (offset +0) 9 = becomes (offset +0) 10 = necessary (offset +0) 11 = for (offset +0) 12 = one (offset +0) 14 = to (offset +0) 15 = dissolve (offset +0) 16 = the (offset +0) 17 = political (offset +0) 18 = bands (offset +0) 19 = which (offset +0) 20 = have (offset +0) 21 = connected (offset +0) 22 = them (offset +0) 24 = another (offset +0) 25 = and (offset +0) 26 = to (offset +0) 27 = assume (offset +0) 28 = among (offset +0) 29 = the (offset +0) 30 = powers (offset +0) 31 = of (offset +0) 32 = the (offset +0) 33 = earth (offset +0) 34 = the (offset +0) 35 = separate (offset +0) 36 = and (offset +0) 37 = equal (offset +0) 38 = station (offset +0) 39 = to (offset +0) 40 = which (offset +0) 41 = the (offset +0) 42 = laws (offset +0) 43 = of (offset +0) 44 = nature (offset +0) 45 = and (offset +0) 46 = of (offset +0) 47 = nature's (offset +0) 48 = God (offset +0) 49 = entitle (offset +0) 50 = them (offset +0) 51 = a (offset +0) 52 = decent (offset +0) 53 = respect (offset +0) 56 = opinions (offset +0) 57 = of (offset +0) 58 = mankind (offset +0) 59 = requires (offset +0) 60 = that (offset +0) 61 = they (offset +0) 62 = should (offset +0) 63 = declare (offset +0) 64 = the (offset +0) 65 = causes (offset +0) 66 = which (offset +0) 67 = impel (offset +0) 71 = separation (offset +0) 72 = We (offset +0) 73 = hold (offset +0) 77 = be (offset +0) 78 = self (offset +0) 79 = evident (offset +0) 81 = all (offset +0) 82 = men (offset +0) 83 = are (offset +0) 84 = created (offset +0) 85 = equal (offset +0) 92 = Creator (offset +0) 94 = certain (offset +0) 96 = rights (offset +0) 98 = among (offset +0) 101 = life (offset +0) 102 = liberty (offset +0) 105 = pursuit (offset +0) 106 = of (offset +0) 107 = happiness (offset +0) 108 = that (offset +0) 110 = secure (offset +0) 112 = rights (offset +0) 113 = governments (offset +0) 115 = instituted (offset +0) 117 = men (offset +0) 118 = deriving (offset +0) 120 = just (offset +0) 121 = powers (offset +0) 122 = from (offset +0) 125 = of (offset +0) 131 = form (offset +0) 133 = government (offset +0) 134 = becomes (offset +0) 135 = destructive (offset +0) 136 = of (offset +0) 138 = ends (offset +0) 140 = is (offset +0) 143 = of (offset +0) 147 = alter (offset +0) 150 = abolish (offset +0) 152 = and (offset +0) 154 = institute (offset +0) 158 = laying (offset +0) 159 = its (offset +0) 160 = foundation (offset +0) 177 = likely (offset +0) 185 = indeed (offset +0) 191 = established (offset +0) 194 = be (offset +0) 196 = for (offset +0) 197 = light (offset +0) 200 = causes (offset +0) 205 = hath (offset +0) 208 = mankind (offset +0) 211 = disposed (offset +0) 217 = sufferable (offset +0) 220 = right (offset +0) 230 = accustomed (offset +0) 234 = long (offset +0) 239 = usurpations (offset +0) 241 = invariably (offset +0) 246 = design (offset +1) 248 = reduce (offset +1) 250 = under (offset +1) 252 = despotism (offset +1) 270 = guards (offset +1) 273 = future (offset +1) 275 = Such (offset +1) 284 = and (offset +1) 285 = such (offset +1) 287 = now (offset +1) 288 = the (offset +1) 290 = which (offset +1) 297 = systems (offset +1) 301 = history (offset +1) 302 = of (offset +1) 305 = King (offset +1) 308 = Britain (offset +1) 314 = injuries (offset +1) 316 = usurpations (offset +1) 320 = direct (offset +1) 344 = refused (offset +1) 353 = necessary (offset +1) 360 = forbidden (offset +1) 370 = importance (offset +1) 371 = unless (offset +1) 388 = utterly (offset +1) 394 = He (offset +1) 400 = laws (offset +1) 405 = large (offset +1) 406 = districts (offset +1) 409 = unless (offset +1) 420 = legislature (offset +1) 440 = uncomfortable (offset +1) 466 = houses (offset +1) 485 = be (offset +11) 486 = elected (offset +11) 505 = State (offset +11) 511 = exposed (offset +10) 540 = naturalization (offset +10) 548 = encourage (offset +10) 554 = the (offset +10) 557 = new (offset +10) 575 = establishing (offset +10) 581 = judges (offset +10) 582 = dependent (offset +10) 600 = salaries (offset +10) 603 = erected (offset +10) 607 = new (offset +10) 620 = eat (offset +10) 643 = to (offset +11) 647 = independent (offset +11) 666 = foreign (offset +11) 807 = valuable (offset +12) 811 = y 1005 = x
Figure 1. The encoder's offset from a plain count of the Declaration, along cipher 2. Cipher 2 has 762 numbers, 181 of them distinct. Three of the distinct numbers, 95, 811 and 1005, stand for the single letters described above rather than for words of the count; 811 and 1005 are marked with hollow rings and 95 is left out. Each of the other 178 distinct numbers is one point, plotted once however often the cipher repeats it. A point's height is the difference between the word number the encoder used and a plain count of the Declaration as printed. The dashed lines mark the five places where the pamphlet's printed count misnumbers the text, and every step in the offset falls at one of them. Made for this report from the numbers of cipher 2 and the Declaration as the pamphlet prints and numbers it.

Two details show that the numbers were transferred from a copy other than the one the printer set. The numbering counts "mean time" as two words and needs "unalienable" at 95; the print has "meantime" and "inalienable". And the pamphlet numbers six words individually, "fundamentally, (811) the (812) powers (813) of (814) our (815) governments; (816)", then stops numbering altogether. 811 is the number the encoder used nine times for y; it is the largest number the cipher needs apart from the x. The numbering was carried exactly as far as cipher 2 needed it and no further, which is what one would expect if it was copied from the encoder's key.

The pamphlet does not mention any of this. A reader who follows its instruction obtains "foir miles", "ehcavation", "sih feet", "countf", "jointlf" and "thirtf"; the printed "translation" supplies, without comment, the letters that the printed key cannot produce.

"It would be difficult to portray the delight he experienced when accident revealed to him the explanation of the paper marked '2.'"The Beale Papers (1885), p. 4

Two readings are possible. Either the anonymous author solved cipher 2 without a key, worked out the encoder's five slips from the redundancy of the message, and then printed the slips as if they were a plain count, typesetting a text that his own numbers contradict, without explaining the discrepancy. The other possibility is that he had the encoder's working key. The second is the simpler reading. It means the person who prepared the pamphlet is the person who enciphered cipher 2, and that the narrative's central claim, that "the promised explanation has never been received", is false. In either case the procedure the pamphlet prints does not produce the translation it prints.

Others reached these results first. Carl Hammer analysed the encoder's errors in 1979; Stephen Matyas, a cryptographer, worked out in the same year how the Declaration must be renumbered for cipher 2 to decode cleanly, once a copy of the pamphlet came to light; Peter Holst, writing in the Beale Cypher Association's newsletter in 1987, reached the same by seven changes to the text; John C. King published the reconstructed key in Cryptologia in 1993, with the positions that cannot be settled marked and the seven errors listed; George Love, an enthusiast who published his analysis on the web in the 2000s, observed that cipher 2 works only with the pamphlet's counts; Todd Mateer, writing in Cryptologia in 2013, concluded from the encoding process that the ciphers are likely a hoax. King's paper is behind a paywall and could be read only in the fragments that the full-text search of the Internet Archive, the digital library, returns; the papers by Matyas, Holst and J. A. Hill (an unpublished study of 1989) could not be read at all. As far as those fragments show, three points are new here: the offsets fitted from the cipher alone and matched segment by segment to the pamphlet's printed parenthetical numbers, the "meantime / inalienable" typesetting argument, and the observation that the printed numbering stops at 816.

2. The alphabet inside cipher 1

In 1980 Jim Gillogly decoded cipher 1 with a standard text of the Declaration (that is, he replaced each number with the first letter of the word it points to), found the string ABFDEFGHIIJKLMMNOHPP at positions 188 to 207, computed how unlikely such a run is by chance, and said his inclination was that cipher 1 was a hoax, adding that his observations "do not constitute an unequivocal proof". He read the string as fourteen letters in order with an F and an H out of place, both attributable to the encoder's habit of choosing an adjacent number. King (1993) then decoded cipher 1 with the key reconstructed from cipher 2 and reported longer strings, which Hill (1989) had found independently; Holst (1987), who reconstructed the key, read Gillogly's string as evidence of a hoax but reported no decryption of cipher 1. King's Table 5 lists AAABBCDEFF at position 44, ABBBCCCCDDE at 84, BCDDE at 113 and ABCDEFGHIIJKLMMNOHPP at 188. Those readings come out the same from the pamphlet's own printed numbering (Table 1).

Cipher 1, positions 184 to 210, decoded with a plain count of the Declaration and with the encoder's miscounted numbering position number plain count encoder's key 184 30 P P 185 44 N N 186 112 R R 187 18 B B 188 147 A A 189 436 L B 190 195 C C 191 320 I D 192 37 E E 193 122 F F 194 113 G G 195 6 H H 196 140 I I 197 8 I I 198 120 J J 199 305 P K 200 42 L L 201 58 M M 202 461 H M 203 44 N N 204 106 O O 205 301 T H 206 13 P P 207 408 O P 208 680 C O 209 93 W W 210 86 T T Seventeen letters in alphabetical order (A to O, position 188 to 204), then H for 301 where 302 would give O, then P, P.
Table 1. The alphabet inside cipher 1. Positions 184 to 210 of cipher 1, decoded with a plain count of the printed Declaration (grey row) and with the encoder's miscounted numbering (bold row). The shaded stretch reads ABCDEFGHIIJKLMMNO: seventeen letters in alphabetical order, followed by H (301, where 302 would give O) and P, P. Made for this report from the numbers of cipher 1 and the Declaration as the pamphlet prints and numbers it, decoded with the numbering worked out in section 1.

Gillogly's F was an artefact of counting a standard text: the pamphlet's extra "a" at word 155 makes 195 "changed", a C, where a standard text gives "for". Only the H remains as a slip. Two further alphabetical runs of eleven letters, the strings King reported, sit at positions 44 to 54 (AAABBCDEFFI) and 84 to 94 (ABBBCCCCDDE). They are invisible with a standard text because they depend on numbers such as 200, 211, 225, 251, 284, 485 and 486, which mean different words under the miscounted numbering. Under a plain count of the printed text the main string collapses to eight letters. Whoever wrote these stretches of cipher 1 was reading from the same numbered, miscounted Declaration that produced cipher 2.

The table gives the probability of such a run under several models of what chance would produce (null models, in statistical terms): letters drawn at random with the frequencies that the Declaration's initial letters actually have, cipher 1's own numbers shuffled, and numbers drawn at random from the whole key. Two rows are exact calculations, one reproduces Gillogly's arithmetic, and the rest are simulations.

Null model (520 letters)Probability of a run ≥ 14Probability of a run ≥ 17Method
Letters drawn with the Declaration's initial-letter frequencies, non-decreasing run7.2 × 10⁻⁶4.9 × 10⁻⁸exact Markov chain
Same, Gillogly's stricter rule (each letter equal to or the successor of the last)6.3 × 10⁻⁸4.0 × 10⁻¹⁰exact Markov chain
Gillogly's own arithmetic (26 equiprobable letters)1.2 × 10⁻¹²reproduced
Cipher 1's own numbers shuffled, decoded with the encoder's key4 to 7 per 10⁶0 in 10⁶permutation
Numbers drawn uniformly from 1 to 1322≈ 5 per 10⁶0 in 10⁶Monte Carlo
Three runs of ten or more in one sequence (as observed)never in 2 × 10⁵ shufflespermutation

Gillogly's rough figure of one in 10¹² assumed that all letters were equally likely, which they are not (T alone begins 19 percent of the Declaration's words), so the true probabilities are larger; they remain small enough for his conclusion to stand. Cipher 3 shows nothing of the kind; its longest alphabetical run is seven letters, which is what a random sequence of that length typically has.

Which of the available words the writer chose

Of the twenty numbers in the string, six are the first word in the Declaration beginning with that letter (human, just, King, laws, mankind, people). The Declaration offers many words for each letter (homophones, in cipher terms), and a writer choosing among them at random would hit the first word 0.76 times in twenty on average, against the six observed (the probability of six or more is 2.7 × 10⁻⁵); measured instead against cipher 1's own numbers, of which nine percent are first occurrences, the probability of drawing six such numbers by chance (a hypergeometric test) is 0.006. On average the string's numbers sit a tenth of the way down the list of words available for each letter (a normalised rank of 0.10), the same habit as the cipher-2 encoder (0.12) and far from random choice (0.5). The writer of the run took each successive letter from the front of the numbered Declaration, as Gillogly imagined: an encipherer "occasionally growing bored and picking entries from the numbered Declaration of Independence in front of him".

The probabilities settle only that the strings were put there deliberately; they do not say why. King, who found the same strings, listed three explanations: a hoax, which is how Gillogly and Holst read them; alterations by the pamphlet's author "to flush out the keytext without giving away the entire solution"; or the Declaration being the true key with a further layer of encoding that no one has stripped. He added that "one would hope that such an elaborate hoax would be revealed by something more interesting". The second and third explanations still require whoever wrote cipher 1 to have worked from the encoder's numbered Declaration, which is the finding of section 1, and cipher 2 has no second layer. The first explanation is the best supported, at about 99 percent, as the table at the top says.

3. How ciphers 1 and 3 behave

Cipher 2 is the reference: a genuine book cipher, carelessly made, with many numbers available for each letter (a homophonic cipher). It uses 181 distinct numbers for 762 letters, prefers the front of the key (54 percent of its numbers are 100 or below, though only 8 percent of the key's words are), never reuses a number on a doubled letter, and always writes v as 807. Its encoder also has a mild serial habit, taking the next suitable word in the key about one time in ten, which gives cipher 2 a small correlation between each number and the next (a lag-one autocorrelation). Tests of the unsolved ciphers are read against cipher 2's behaviour. Figure 2 sets the three ciphers' numbers side by side.

Histograms of the numbers in the three ciphers, bins of fifty Cipher 1 (520 numbers, largest 2906) 44% at or below 100 1-50: 125 numbers 51-100: 102 numbers 101-150: 61 numbers 151-200: 19 numbers 201-250: 47 numbers 251-300: 15 numbers 301-350: 22 numbers 351-400: 8 numbers 401-450: 19 numbers 451-500: 13 numbers 501-550: 8 numbers 551-600: 4 numbers 601-650: 11 numbers 651-700: 6 numbers 701-750: 3 numbers 751-800: 3 numbers 801-850: 12 numbers 851-900: 9 numbers 901-950: 6 numbers 951-1000: 9 numbers 1001-1050: 0 numbers above 1050: 18 numbers 273 0 Cipher 2 (762 numbers, largest 1005) 53% at or below 100 1-50: 273 numbers 51-100: 132 numbers 101-150: 138 numbers 151-200: 30 numbers 201-250: 43 numbers 251-300: 20 numbers 301-350: 20 numbers 351-400: 20 numbers 401-450: 8 numbers 451-500: 5 numbers 501-550: 21 numbers 551-600: 9 numbers 601-650: 11 numbers 651-700: 1 numbers 701-750: 0 numbers 751-800: 0 numbers 801-850: 27 numbers 851-900: 0 numbers 901-950: 0 numbers 951-1000: 0 numbers 1001-1050: 4 numbers above 1050: 0 numbers 273 0 Cipher 3 (618 numbers, largest 975) 54% at or below 100 1-50: 160 numbers 51-100: 173 numbers 101-150: 91 numbers 151-200: 33 numbers 201-250: 58 numbers 251-300: 19 numbers 301-350: 35 numbers 351-400: 10 numbers 401-450: 7 numbers 451-500: 3 numbers 501-550: 0 numbers 551-600: 0 numbers 601-650: 5 numbers 651-700: 3 numbers 701-750: 1 numbers 751-800: 0 numbers 801-850: 6 numbers 851-900: 4 numbers 901-950: 6 numbers 951-1000: 4 numbers 1001-1050: 0 numbers above 1050: 0 numbers 273 0 0 250 500 750 1000 >1050
Figure 2. The numbers in the three ciphers, counted in ranges of fifty. Each bar counts how many of a cipher's numbers fall in one range of fifty (1 to 50, 51 to 100, and so on). The ranges stop at 1,050, the first multiple of fifty above 1005, the largest number in cipher 2; the dashed line marks that point, and the single grey bar to its right holds every number above it. Cipher 1 has eighteen numbers above 1,050, ten of them beyond the Declaration's 1,322 words and the largest of them 2,906; ciphers 2 and 3 have none. Cipher 1 and cipher 3 share cipher 2's preference for small numbers but reuse them far less. Made for this report from the three ciphers as the pamphlet prints them.
StatisticCipher 1Cipher 2Cipher 3
Numbers520762618
Distinct values298181263
Median, largest123, 290685, 100594, 975
Share of values used once59 %24 %47 %
Decoded with the Declaration: distance of the letter frequencies from English (KL divergence; 0.27 ± 0.03 for numbers unrelated to the key)0.25 (p = 0.27)0.04 (p < 0.0003)0.25 (p = 0.20)
Correlation between each number and the next (lag-one rank autocorrelation; p from shuffling)0.20 (< 10⁻⁴)0.21 (< 10⁻⁴)0.49 (< 10⁻⁴)
Strictly rising runs of six or more numbers (expected)3 (0.7)2 (0.8)17 (0.7)
Second half minus first half, mean (p)+34 (0.29)+13 (0.35)+81 (< 10⁻⁴)
Distinct values expected if made with cipher 2's habits (any key)164 ± 6179 ± 7

Neither cipher decodes with the Declaration. Decoded with the key, the letter frequencies of ciphers 1 and 3 are what the Declaration's initials give for numbers unrelated to the key; cipher 2 decoded the same way has English letter frequencies (p < 0.0003 in the table). Cipher 1 also has ten numbers larger than the key.

Reuse cannot separate "another key" from "invented". Made with cipher 2's habits and any key, cipher 1 would have about 164 distinct numbers and cipher 3 about 179; they have 298 and 263. A homophonic encoder with a lighter reuse habit reproduces both frequency profiles, so the digit and reuse statistics on their own do not show that they are invented. Earlier claims that the unsolved ciphers are "non-random and therefore real" (Hammer, 1970s) or that the distribution of their digits shows invention (Viktor Wase in 2020 and Leonardo Campanelli in 2022, both analysing the digits statistically) both fail against cipher 2, which is non-random in the same directions, and whose token-level digit anomalies are largely an artefact of homophone reuse.

Cipher 3's numbers are ordered in a way that enciphering does not produce. Its numbers are strongly correlated from one to the next (rank autocorrelation 0.49, and still significant six steps apart), it contains seventeen strictly rising runs of six or more numbers where 0.7 are expected, its second half runs 81 higher on average than its first, and a standard test of whether a sequence rises and falls the way random numbers do (the runs-up-and-down test) gives z = −7.6, far outside chance. Cipher 2's encoder shows none of this beyond the mild lag-one effect, and no strength of the "scan forward through the key" habit fits both cipher 3's autocorrelation and its rising runs. Drift and rising runs are what one expects from a hand writing numbers meant to look like a cipher, and enciphering a list letter by letter does not produce them.

Cipher 3 is too short for the list it is said to contain. The letter of 5 January 1822 says paper 3 names "all my associates" and, opposite each, "the names and residences of the relatives and others" who inherit; the party numbered "not less than thirty". With real Virginia name lengths (1810 and 1850 census transcriptions: first names 6.1 letters, surnames 6.4) and the 78 Virginia counties and cities of 1822 (8.5 letters), the barest list, each man's name, one heir's first name and a county, needs 792 ± 19 letters. In 20,000 random draws it never fitted in 618. Only a list stripped to surnames and county names (631 ± 17 letters) comes within reach, and fits one time in four. Cipher 2, by contrast, spells everything out in full, including the phrase "in the county of bedford".

4. The language of "Beale"

The pamphlet prints three letters signed T. J. B., dated Lynchburg, 4 and 5 January 1822, and St. Louis, 9 May 1822 (2,716 words together), and 3,954 words of the narrator's own account. Joe Nickell argued in 1982, with a tabulation by the linguist Jean Pival, that the two were written by one hand, and that "stampede" and "improvise" were words no one used in 1822. Both claims were tested here against a comparison set (the controls, from here on) of 27 American authors and 115 samples of their writing: letters and journals of 1805 to 1846 (Thomas Jefferson, John Randolph of Roanoke, Andrew Jackson, John Quincy Adams, the explorer Zebulon Pike, Edwin James of the 1820 Long expedition, the frontier writer Timothy Flint, the Santa Fe trader Josiah Gregg, Washington Irving and others), Virginian and Southern prose of 1858 to 1904 (the Virginia essayist George Bagby, the novelists John Esten Cooke, Thomas Nelson Page, George Washington Cable and George Cary Eggleston, Mark Twain, Robert E. Lee's letters, and three Lynchburg local historians), and Edgar Allan Poe, whom some have proposed as the author because of "The Gold-Bug", his 1843 story of a cipher and buried treasure.

Each measure in the table scores how alike two texts are in their use of common words or letter groups; "Delta" is the family of measures that authorship studies use, introduced by John Burrows in 2002, and function words are the grammatical words such as "the", "of" and "until". The first column of figures says how often the measure picks the right author when tested on the controls. The last is the likelihood ratio: how many times more likely the observed closeness is if the two texts share an author than if they do not.

MeasureAttribution accuracy on controlsDifferent-author pairs as close as letters vs narrativeSame-author pairs as closeLikelihood ratio, same : different
Cosine Delta, 300 most frequent words, pronouns removed, full texts60 %0.0 %5 %645
Same, both texts cut to 2,000 words60 %0.5 %22 %25
Cosine Delta, 150 function words only, 2,000 words61 %2.1 %38 %6.6
Character 4-grams, 2,000 words65 %0.2 %18 %25
Burrows Delta, 300 most frequent words, 2,000 words69 %4.9 %43 %2.7

On the cosine Delta and character 4-gram measures, the letters and the narrative are closer than 99 to 100 percent of the 6,352 pairs of samples by different authors; on the function-word measure they are closer than 98 percent, and on Burrows Delta at 2,000 words, the measure with the best control accuracy, closer than 95 percent. On all of them they are as close as ordinary pairs by the same author. The narrative is the nearest "author" to the letters by a wide margin (a distance of 0.69 against 0.90 for the runner-up, Jefferson), and the letters are the nearest text to the narrative. Nine pairs of different authors writing on the same subject, such as Gregg and Thomas James, both on the Santa Fe trade, or the three Lynchburg historians, all come out farther apart on average (0.85 to 0.99 against 0.70), though one individual pair of samples, from the Lynchburg historians Christian (1900) and Pollock (1887), comes closer (0.63). With even prior odds (a 50:50 view before the texts are compared) the length-matched results give a probability of common authorship between 0.73 (Burrows Delta) and 0.96 (cosine Delta without pronouns, character 4-grams); the full-length results give more. The prior odds are a judgement.

Pival's observation about "misuse of reflexive pronouns" turns out to be the most specific evidence. Reflexive pronouns with nothing in the sentence to refer back to ("like myself", "not so reliable as yourself", "for myself and family", "as sanguine as himself", "more fortunate than myself") occur 3.7 and 2.3 times per thousand words in the letters and the narrative; the control mean is 0.4, and one of 115 control samples reaches the lower of the two rates. The construction "not to be delivered", "never to be realized", "not to be resisted" runs at 0.4 to 0.5 per thousand in both against 0.03 in the controls. By contrast the punctuation and syntax rates that summaries of Nickell's article emphasise (semicolons, relative clauses, infinitives, sentence length) barely discriminate authors at all, and the two texts differ on semicolons (1.5 against 7.1 per thousand words).

Two controls inside the pamphlet behave as expected. Robert Morriss's quoted statement, which the author admits he "reduced to writing", is as close to the narrative as the narrative's two halves are to each other. Poe is excluded: "The Gold-Bug" and his letters sit at ordinary different-author distances from both Beale texts, as the writer William Poundstone found in 1993, when he had a stylometric comparison made for his book Biggest Secrets.

The narrator says he "read over and over again the letters ... endeavoring to impress each syllable they contained on my memory". A hoaxer imitating letters he had memorised cannot be excluded by stylometry alone. But the shared traits are the involuntary kind (rates of "until", "myself", "such", "may", "each", the reflexives, the negative infinitives), which one writer carries from text to text and an imitator is unlikely to reproduce.

Which words belong to 1885

In the lettersEarliest use that could be verifiedVerdict
"securing many and stampeding the rest""the Cavellada Stampeded" in a Texas deposition of about October 1823 concerning events of August 1822 (printed in The Austin Papers, the collected papers of the Texas colonist Stephen F. Austin, in the American Historical Association's Annual Report for 1919, vol. II, p. 699; verified in four scanned copies). "Stompado", marked as Spanish, in Timothy Flint's novel of 1826; a soldier's piece titled "A Stampedo" in the Military and Naval Magazine of December 1834 still explains the word as "a North American attempt to adopt a Spanish word into our language"; Gregg italicises "stampeded" in 1844. In newspapers "stampede" first appears in 1836 and "stampeded" and "stampeding" in 1842. Wikipedia's "1834" citation is a book of 1884 to 1887, misdated.This is not a hard anachronism. A man back from Santa Fe could have carried "estampida" home in 1822, twenty months before the earliest surviving English use; but the word is at the extreme early edge of its history, and Nickell's dates (1844; "stampeding" not before 1883) were too late.
"such tools and appliances as they had improvised"The verb is recorded from 1788 (by the Merriam-Webster dictionary) and 1808 (by Etymonline, an online etymological dictionary), in the sense of composing or performing extempore; the concrete sense "contrive from what is at hand" is later and could not be dated without the Oxford English Dictionary.The case is suggestive but unproven.
"encounter the savage grizzlies""Grizzly bear" from 1806 (Lewis and Clark); the clipped plural noun is at noise level in the Google Books record of printed usage until the 1850s (its frequency before 1822 is 2.6 percent of its 1850 to 1900 level).This is a probable anachronism, a mid-century Western colloquialism.
"our objective point being Santa Fé"Military term from the French "point objectif"; Etymonline dates it 1852. No verified newspaper use exists before 1847; the earliest are Mexican-War strategy commentary in the Richmond Daily Whig of 5 January 1847 and Washington and Virginia papers the same month. Pre-1822 Google Books frequency is 2.9 percent of its later level, with the take-off in the Civil War years.A strong candidate that Nickell did not consider. The phrase belongs to military writing of the Mexican War and Civil War years.
"reliable" (twice)Etymonline: "not common before 1850, and often execrated thereafter in Britain as an Americanism".The evidence is weak to moderate.
"everything", "in the meantime", "pretense", "honor", "favorably"Before 1822 American books print "every thing" six to one, "in the mean time" eight to one, "pretence" twenty-one to one; the letters use the later form every time.These are weak on their own, since an 1885 typesetter could have modernised them.

Put on a common footing: 0.85 percent of the distinct content words in the letters are "late" (their frequency in Google Books before 1822 is below a tenth of their 1850 to 1900 frequency), against a mean of 0.19 percent (standard deviation 0.16, maximum 0.47) in twelve same-length samples of genuine American writing of 1805 to 1843. That is 4.1 standard deviations above the genuine texts; none reaches the letters' figure. The letters also carry deliberate period colour ("&c.", "enquiring", "such an one", "punctillio", "exhilerating", "the States"), and by function-word style alone they classify as 1820s letters, nearer to Jefferson and Randolph than to Twain or Lee. A writer of 1885 could imitate the manner of 1822, but the letters contain words that were not in use in 1822, and that is the evidence for the later date.

5. The historical record

The pamphlet makes few claims that can be checked against records, and those that can be checked are contradicted by the records. The sources read for this section were the surviving Lynchburg newspapers of the 1820s, page by page in the Library of Congress's digitised newspaper collection, the two nineteenth-century histories of Lynchburg, the standard histories of the Santa Fe trade, and the Beale files that the National Security Agency released under the Freedom of Information Act (the agency had collected material on the ciphers over the years), including a 1972 archival search made on behalf of the believers.

Robert Morriss and the Washington Hotel

Morriss's statement in the pamphlet begins: "It was in the month of January, 1820, while keeping the Washington Hotel, that I first saw and became acquainted with Beale", and has Beale return to the same house in January 1822. Morriss's own newspaper advertisements give different dates. In a notice dated 20 September 1823 and printed in The Virginian, a Lynchburg newspaper, on 30 September, he announces that he "has rented the house known by the above name", the Washington, on Third Street "lately occupied by" a Mr. Moorman, and "will be prepared by the first of October, to accommodate boarders, and transient customers". A notice dated 30 December 1825 and printed from March 1826 says he "has removed from the Washington, which he has occupied for more than two years past, to the Franklin Hotel". Margaret Cabell's Sketches and Recollections of Lynchburg, a local history of 1858, agrees: "In the year 1824, Mr. Morriss took possession of the Washington House", and in 1820 he was still "a man of wealth" living in his own large dwelling. Morriss kept the Washington for twenty-seven months, from October 1823 to December 1825, and not in 1820 or 1822. Nickell reported the contradiction in 1982; Wikipedia, citing Poundstone's Biggest Secrets (1993), gives his finding as "not until at least 1823", and the notices fix the dates exactly.

One detail qualifies this. By September 1823 Morriss was already taking lodgers in his own house ("at the tavern-house of Robert Morriss"), after the business reverse that Cabell dates loosely to about 1820. A guest could have stayed "at Mr. Morriss's" before October 1823. The pamphlet's error is specific to the Washington Hotel and to the years 1820 to 1822, for which no boarding-house activity is recorded either. The rest of the Morriss portrait (wealth, reverse, hospitality, death in January 1863 in his eighty-sixth year) is accurate in outline and could have been written by anyone who knew Lynchburg. The pamphlet's date for his wife's death (1861) conflicts with Wikipedia, which gives 1863 and cites an obituary of 21 May 1865; the obituary itself could not be reached.

Thomas J. Beale

No contemporary record of a Thomas J. Beale has been produced in anything that could be read. The 1810 and 1820 censuses name only heads of household, so absence there proves little. The one documentary "Thomas Beall" that believers cite, a letter waiting at a Missouri post office in April 1820, is from Franklin rather than St. Louis, and is a common surname three hundred miles from Lynchburg. Charles Nelson, a researcher working for the Beale Cypher Study Committee in 1972, read the Richmond Enquirer for 1817 and 1820, the Missouri and Illinois papers, and rolls 18 to 22 of the microfilmed Spanish Archives of New Mexico (the records of the Spanish government there, 1815 to 1821), and reported "no Beale party references". There was a real Thomas Beale of Botetourt County, west of Lynchburg, who fought a duel around 1806, fled to New Orleans and died there; a Lynchburg author of 1885 could have known the name.

Thirty Virginians in Santa Fe, 1817 to 1818

The letter of 4 January 1822 has about thirty armed Americans reach Santa Fe in December 1817, winter there, buy "everything necessary" for two years of mining, hire Indian labour, and twice carry gold and silver east. The Spanish authorities in New Mexico did not treat American arrivals that way. Robert McKnight's trading party of 1812 was seized on arrival and held at Chihuahua for nine years; the trappers of the fur traders Auguste Chouteau and Jules de Mun were arrested on 24 May 1817, six months before Beale's party is supposed to have arrived, imprisoned for forty-eight days and stripped of their goods; David Meriwether, a young trader from Kentucky, was taken prisoner and confined at Santa Fe in 1819. The summary of the period by Hiram Chittenden, the historian of the fur trade, is "total failure on the part of American traders to gain any foothold" before Mexican independence in 1821, and the Spanish records of these years contain travel regulations for visitors and instructions on passports. Wheeled vehicles first crossed the plains route in 1822. The cargo, 2,921 pounds of gold and 5,100 pounds of silver, would have needed twenty to thirty pack mules a trip, across the same frontier on which Meriwether was arrested. The story is not impossible, but it contradicts every documented case, and the archives that have been searched contain no trace of it.

James B. Ward and the pamphlet

The title page and the copyright line are the only primary evidence of Ward: "Entered according to act of Congress, in the year 1885, by J. B. Ward". The pamphlet says its author is a friend of Morriss who received the papers in 1862 and hands them to Ward as "agent". No statement by Ward on authorship survives in anything that could be read. The nearest is a 1964 memoir by George Hart, one of two Roanoke brothers who searched for the treasure from the 1890s, released by the National Security Agency: about 1903 Ward "confirmed all that is contained in the pamphlet" to Hart's brother Clayton, his son "added his own confirmation", and Hart himself wondered "if Ward might have written his manuscript based upon some figures he found, or made up". The story that most copies burned in a printing-house fire rests on Ward's word to the Harts alone. A full-text search of the Library of Congress newspaper collection, which lacks the Lynchburg papers of those years, found no mention of the pamphlet between 1885 and 1892; the earliest press retelling found is the Roanoke Times of 20 January 1893, by which time "the inhabitants of Bedford county have hunted for this treasure but so far in vain". A genealogical claim on a treasure-hunting forum makes Ward's mother a Risqué, of the family that duelled with the Botetourt Thomas Beale; it is unverified and carries no weight here, but it is the kind of lead a records search could settle.

The following could not be consulted: Nickell's 1982 article (on JSTOR, the journal archive), Poundstone's chapter (known through Wikipedia's summary and the Internet Archive's full-text index), the Lynchburg papers of 1819 to 1821, 1862 to 1865 and 1885 to 1892 (the Library of Congress collection holds Lynchburg papers only from 1822 to the 1850s), the 1885 copyright record book, the census indexes on Ancestry, and the publisher's texts (Taylor and Francis) of the Cryptologia papers by Hammer, Kruh, King, Chan (2008), Mateer, Wase ("Benford's law in the Beale ciphers", 2021; his 2020 conference paper was read) and Campanelli. Everything relied on is captured under sources/records/ with a manifest.

6. The strongest case for the other side

"Hammer's computers showed the ciphers are not random, so they encode something." This is true but does not decide the question. Ciphers 1 and 3 are not independent random numbers, but neither is the genuine cipher 2, and it departs from randomness in the same directions. Cipher 3's non-randomness is of a kind (drift, rising runs) that enciphering text does not produce.

"Cipher 1 has a second layer, or a different key that happens to produce the alphabet." King (1993) left this possibility open, and statistics cannot exclude it. Three things can be said. Cipher 2 has no second layer; the pamphlet says all three papers work the same way; and the alphabetical runs exist specifically in the miscounted numbering of the Declaration and use the front of its homophone lists, so whoever wrote them was working from the Declaration numbered as for cipher 2. A different key would have to reproduce three alphabetical runs by coincidence; a hidden layer would have to be one that no one has found in the 140 years since the pamphlet appeared.

"The author solved cipher 2 himself and reconstructed the encoder's slips." This is possible in principle. It requires him to have printed the reconstructed slips silently as a plain count, typeset a Declaration his numbers do not fit, and stopped numbering at the last number his cipher needed. It explains neither the alphabet in cipher 1 nor the authorship of the letters.

"Stampede is no anachronism, so the linguistic case collapses." On that word the objection is right: "stampede" was Nickell's strongest example, and it is not relied on here. The linguistic case now rests on the calibrated density of late vocabulary and on "objective point" and "grizzlies". It is the weakest of the lines, which is why the verdict does not depend on it.

"Stylometry on 2,700 words is unreliable." The calibration against 27 known authors answers this. On these texts and this corpus, different authors come out this close between one time in twenty (Burrows Delta) and fewer than one in five hundred (cosine Delta without pronouns), depending on the measure. The likelihood ratio for the length-matched pair is 3 to 25, a modest figure; the reflexive-pronoun habit is the most specific trait, and one control sample in 115 reaches the letters' lower rate.

"Absence from the record proves nothing about 1822." This is right for Beale himself, whose absence from a census that names only heads of household proves little. The Morriss date, however, is a contradiction rather than an absence: the pamphlet's one checkable date for the Beale visits is wrong by more than three years, and the error cannot be Morriss's own, since he kept the Washington for only twenty-seven months and never in 1820 to 1822.

"A hoaxer would not have gone to this much trouble." The labour was small: numbering a Declaration, enciphering one real message of 762 numbers, and writing 1,138 further numbers that needed only to resemble a cipher. The pamphlet sold for fifty cents. The alphabet in cipher 1 is consistent with a writer who shortened that labour by taking successive letters from the front of the numbered key.

7. What would overturn the verdict

Four kinds of document would. The first is any document earlier than 1885, independent of the pamphlet's author, that mentions the ciphers, the letters or Beale's box: a Morriss paper, a will, a Lynchburg newspaper item of 1845 or 1862. The second is a reading of cipher 1 or cipher 3 as English, with any key, that survives the tests in section 3 and explains the three alphabetical runs as a property of the real key rather than of the Declaration. The third is a record placing Robert Morriss at the Washington Hotel in January 1820, and a Thomas J. Beale in Lynchburg in 1820 to 1822 or in Santa Fe in 1817 to 1821. The fourth is a manuscript worksheet showing that the pamphlet's numbering was reconstructed by a solver rather than copied from the encoder, together with an account of how the printed "translation" acquired its x, y and u.

Each of these would move one line of evidence. The verdict on the ciphers rests on two lines (sections 1 and 2, the second visible even with a standard text), and the verdict on the letters on two more (sections 4 and 5), so a single new document would lower the confidence without reversing the conclusion.

8. What was already in print, and what is added

The cryptanalytic core of this case was worked out between 1979 and 1993, in Cryptologia and in the Beale Cypher Association's publications, and the popular accounts (Wikipedia, Poundstone's Biggest Secrets) barely mention it, so a reader who knows only those accounts may take it for new work. The left column gives the safe attribution. The right column lists what is added, as far as the sources that could be reached show; King's paper was read only in fragments, and Matyas, Holst and Hill not at all.

Already in print

  • Gillogly (1980): the alphabetical passage in cipher 1, its improbability, the hoax inference, and the caution that it is strong evidence rather than proof.
  • Matyas (1979), Hammer (1979), Holst (1987), King (1993): the renumbering of the Declaration that decodes cipher 2, with its undeterminable positions, and the encoder's errors; King, and Hill (1989) independently: the three longer strings in cipher 1 under the reconstructed key; Holst reported no decryption of cipher 1. King also noted that the 1885 pamphlet's versions of the ciphers differ from later ones.
  • Love, Mateer (2013): cipher 2 works only with the pamphlet's counts; the encoding process points to a hoax.
  • Crossen (1927), Kruh (1982): 618 signs cannot hold thirty names with heirs and residences.
  • Nickell and Pival (1982), Kruh (1988), Poundstone (1993): common authorship of letters and narrative; Poe excluded; Morriss not at the Washington Hotel before 1823.
  • Wase (2020), Campanelli (2022): digit anomalies in ciphers 1 and 3.

Added here

The first four items are new analysis of evidence already in print; the fifth brings in documents that the accounts that could be read do not use; the sixth corrects transcriptions.

  • The encoder's offsets fitted from the cipher alone and matched to the five printed anomalies; the "meantime / inalienable" typesetting argument; the numbering that stops at 816.
  • Exact Markov-chain probabilities with the real letter frequencies, permutation tests on cipher 1's own numbers, a count-of-runs test, and the homophone-rank test (which of the available words the writer chose).
  • A fitted model of the cipher-2 encoder, used to show that ciphers 1 and 3 were not made with his habits and that cipher 3's serial structure fits no letter-by-letter encoder; the capacity bound with real Virginia names.
  • Calibrated stylometry with 27 authors and 115 samples, likelihood ratios in place of impressions; the reflexive-pronoun habit quantified; corrected dates for "stampede" and "improvise"; "objective point" and "grizzlies" as anachronism candidates; the calibrated late-vocabulary density.
  • Morriss's own notices in The Virginian fixing his tenure of the Washington Hotel to October 1823 through December 1825 (Wikipedia, citing Poundstone's Biggest Secrets, had only "not until at least 1823"); the Santa Fe story set against the documented arrests of 1812 to 1819 and against Charles Nelson's negative 1972 search of the Spanish Archives of New Mexico, released by the National Security Agency; the earliest press retelling located, the Roanoke Times of 20 January 1893; corrections to the Wikipedia account (the 1820 "Thomas Beall" letter list is from Franklin, Missouri, rather than St. Louis).
  • Transcription notes: cipher 2 as printed has 762 numbers rather than 763; Gillogly's "495 numbers" for cipher 1 should be 520; the message says "iron pots" rather than "clay pots".

9. Sources and reproducibility

Primary sources

Scholarship

Code, data and notes

The code, data and notes are published alongside this page: data/primary/ (the parsed pamphlet: ciphers, the Declaration as printed and numbered, letters, narrative), sources/ (raw captures, the parser, scans, the records manifest, the King fragments), code/ (Python 3, numpy and scipy, fixed seeds: b2_key.py, b2_decode.py, gillogly_strings.py, stats_*.py with stats_run_all.sh, stylo_*.py, lang_*.py), results/ (every table and figure as CSV, JSON or SVG, including the two figures and the table on this page, drawn by code/make_report_figures.py), and notes/ (four working notes with full tables and sources: cryptanalysis_b2_gillogly.md, statistics_b1_b3.md, stylometry_and_language.md, historical_records.md). The Monte Carlo runs take about forty minutes at full size; each script accepts smaller sizes for a quick check.

Written from the sources above.