Skip to main content

Cicada 3301: The Internet's Weirdest Mystery

June 28, 202660 min read

For 11 years, I was a collectibles dealer, which is a polite way of saying I worked at a comic book store. I had never read a comic book before working there however, I was hired for my expertise with Magic: the Gathering. Whenever I told people what I did for work, they always thought it was the coolest job ever (possibly while saying “fucking nerd” under their breath).

People had this false impression that we just sat around reading comics all day, but in my 11 years there that only happened once, and only because we had to check the book to see if it belonged in one of the sealed black bags we used for adults only books. The reality is that, like most jobs, there was always a mountain of work to do. Sure, a lot of that work was more fun than your average job, and I got along well with both owners so it was usually an enjoyable time being there, but a lot of the work was also a monotonous nightmare, like having to build a database of hundreds of thousands of cards for our online store.

On the morning of January 31, 2014, I was starting my day at work as normal. I would keep an eye on various Magic internet forums throughout the day, because prices of cards could be extremely volatile, so I had to stay up to date. But while it was still January for me, in Singapore it was now February 1st, which meant that their midnight prerelease tournaments for the new set, Born of the Gods, had already begun.

Key Takeaways

  • Cicada 3301 is an enigmatic group that has run complex puzzles annually since 2012.
  • The group’s puzzles involve cryptography, steganography, and real-world coordination.
  • Winners of Cicada 3301 puzzles report underwhelming experiences and lack of clear goals.
  • The group’s manifesto emphasizes privacy, anti-censorship, and anti-oppression ideals.
  • Despite extensive efforts, the identity and true intentions of Cicada 3301 remain unknown.

At one of these tournaments, someone opened a strange card in one of their packs. It wasn’t a card anyone had seen before, but it also wasn’t a card from the new set either. It wouldn’t have been unprecedented for a sorting error like this to happen, but this time it was much more unusual.

Printed on the back of the mysterious card was a string of numbers that looked like they had been added on after the initial printing with a typewriter. The player in Singapore who opened this card posted it online, and as soon as we in the states saw it, we recognized what the string of digits was: it was a phone number with a Seattle area code, the location of Wizards of the Coast headquarters. If you didn’t know or couldn’t tell from context clues, they’re the people responsible for the card game.

I and many others called the phone number, and we were greeted with a robotic voice reading off a string of numbers. It was one of those really bad, old school robot voices from the early 90s that could barely pronounce words, so it took a lot of phone calls to get all the numbers right. Immediately we searched for websites that could automate the process of decoding the cipher, and discovered that the coded message was the text of another unknown Magic card. Two weeks later on February 13th, Wizards of the Coast released another cipher.

We went through the same process, and it was the official announcement for a new upcoming set called Conspiracy. As much I enjoyed seeing Youtube ads featuring Danny Trejo playing Magic, this puzzle was by far their most clever marketing campaign. It was a lot of fun, and it played right into the Conspiracy theme.

Were my forum viewings not so centered around my job/hobby, however, perhaps I would have noticed that there was a similar puzzle going on over at 4chan. A complex series of puzzles that, unlike the previous two years, would remain unsolved to this day. After all, today we are talking about the granddaddy of them all, the biggest mystery the internet has ever seen, or at least ever had seen until the mystery of “why the fuck do people buy NFTs?” This is the story of Cicada 3301.

Cicada 3301 – 2012

“Hello. We are looking for highly intelligent individuals. To find them, we have devised a test. There is a message hidden in this image. Find it and it will lead you on the road to finding us. We look forward to meeting the few who will make it all the way through. Good Luck. 3301”

On January 4, 2012, this message appeared as an image of white text on a plain, black background on the /x/ message board of 4chan. While the section of 4chan you are most likely familiar with is /b/ (aka “random”) because it is the part that is synonymous with Anonymous, 4chan is obviously more than just /b/, and it uses a whole host of other letters for its various boards! And since Simon is unlikely a longtime reader of 4chan, apologies for not prefacing this by telling you to ignore the slashes and just say the letter when pronouncing them.

Anyway, /x/ is the paranormal section of 4chan. It features a lot of people who think they are mythical beings or have seen ghosts, as well as being the original home of the “THEN WHO WAS PHONE” creepypasta meme.

People immediately latched onto this post, thinking it was either an Alternate Reality Game or a recruitment tool for some clandestine organization like the NSA. I’m going to be doing a bit of a tightrope walk as we move forward. This was a very elaborate series of puzzles, and I want to do them justice by describing them as completely and accurately as possible.

At the same time, I don’t want you to get bored and stop listening; you don’t want to know what Simon does to writers that hurt his precious watch time. So I’m going to do my best to fully explain these puzzles and the solutions we know, without going into extreme depth of listing the full sequence of ciphered digits and the corresponding string of characters used as a key and such nonsense. If you want that level of detail then you can find walkthroughs online, but this is neither the time nor the place.

As I said people, people immediately took notice of this post and got to work. After all, who wouldn’t want to be deemed a “highly intelligent individual” by a random internet stranger? The obvious first step was to just open the image inside a text editor. Indeed, at the end of the file was the message “Tiberivs Clavdivs Caeser says ‘random gibbberish’”.

Whether you know your various types of ciphers or not, and I think it’s pretty safe to say that we all do, a quick search would reveal that there one called a Caeser cipher. So far, this puzzle doesn’t seem any more complex than the marketing campaign used to promote a children’s card game. A Caeser cipher is very basic, and there are tools online to do the grunt work for you so this should have taken mere seconds to decode.

The decoded message was an Imgur link to this adorable hunting decoy: Had I decrypted the first clue only to discover this image, I’d have admittedly been a bit saddened. My first thought would have been that there was another clue hidden deeper in the message, and this was just a red herring. Fortunately, my second thought would have been that everyone on the internet is a lying asshole, so of course this was the real next clue and not just a decoy. I mean, look at the bird’s wing!

There clearly seems to be a message hidden in this image that we need to somehow guess how to get out.

The first time I read that message though, the syntax really bothered me. It’s not just that the creators of a puzzle designed only for the most intelligent people ended a sentence with a preposition, or the fact that they seem to be implying that brute force guessing was ever meant to be an intended or viable solution to the puzzle. Maybe Simon will disagree, but the sentence just feels weird and bad when I say it. Which of course means that it must be another clue!

This is another puzzle that could have been solved relatively easily in a few minutes on Google. If you searched for steganography programs, you would have immediately found that one of them was named “OutGuess”. If you were unfamiliar with the word “steganography”, hopefully not to be confused with the word “stenography”, it is the process of hiding messages in text or data.

So far so simple, right? Well it’s going to get a bit more complicated now. Opening the duck image in OutGuess revealed the message “Here is a book code. To find the book, and more information, go to (random gibberish looking subreddit)”.

This was followed by a series of numbers. A book code is pretty simple. You get a bunch of number pairs read as “line:letter”, and just use that to pull a bunch of letters off of a page of a book to form a message. It’s like cutting letters out of a magazine to write your ransom note.

The only question was, what book?

Our intrepid puzzle solvers traveled to the subreddit, where they found two images and a bunch more lines of gibberish text that looked like encrypted information. The first image was of a welcome mat, and the second was a stereogram image (aka a Magic Eye picture) that looked like an image of the Holy Grail. Running both of these images through OutGuess unsurprisingly revealed two more hidden messages.

The message in the welcome mat image stated “From here on out, we will cryptographically sign all messages with this key” and then gave the PGP key they would be signing the messages with. PGP stands for the ironically named “Pretty Good Privacy”, an encryption program that allows users to include a unique and anonymous digital signature. Including indisputable identification in incoming information is indeed instrumental in isolating insipid impostors.

I should have chosen a different letter than “i” to do that with this episode, vowels are way too easy.

Regardless, this was one of the most important messages 3301 would ever send. A major point of confusion and contention in internet mysteries is the inability to authenticate supposed messages from anonymous sources. Copycats and trolls are in no short supply, but this would prevent such scoundrels from muddying the waters for the treasure hunters. The OutGuess message hidden inside the Magic Eye of the Holy Grail read: “The key has always been right in front of your eyes.

This isn’t the quest for the Holy Grail. Stop making it more difficult than it is.”

So a welcome/introduction message hidden in the welcome mat image, a comment about the Holy Grail hidden inside the Holy Grail image…it’s a bit on the nose, but I guess they were trying to be cute. But the message was completely honest, and the key was right in from of their eyes the whole time. The header image was a series of lines and circles that I’m sure our listeners would all immediately have identified as Mayan numerals.

The Mayans used a vigesimal number system which uses base 20, instead of the base 10 decimal number system that you’re used to. The subreddit name appeared to be a mixture of letters and numbers, but if it was treated entirely as vigesimal numbers then the Mayan numerals in the header corresponded to the first several characters of the name of the subreddit. If that sounds confusing, it’s just A=10, B=11, up to J=19.

This string of numbers in the subreddit name was the key needed to decrypt the rest of the gibberish text throughout the page. Once decrypted, the text was revealed to be a passage from Thomas Bulfinch’s Mythology about King Arthur. The book cipher had already been given, so now that the book was found all that was left to do was to cut out the letters the key said and see what it spelled out.

The message this gave was “Call us at tele phone numBer two one four three nine oh nine six oh eight.” I swear to God if I call and it’s a fucking Dominos… The number has long since been disconnected, but if you called the number back in 2012, you would have been greeted by a robotic voice with the following clue: “Very good. You have done well. There are three prime numbers associated with the original final.jpg image. 3301 is one of them.

You will have to find the other two. Multiply all three of these numbers together and add a .com to find the next step. Good luck. Goodbye.”

Such a polite robot, and so encouraging!

This clue was actually a bit easier than the others. The only number that appeared in the original message was the 3301 that was already given. You could try all sorts of steganography tools or search for hidden layers in photoshop, or you could just right click on the image to view image details.

Doing so would reveal that the image was 509 pixels by 503 pixels, both of which are prime numbers. Multiplying those numbers together brought you to a website that had a countdown, and, at long last, the first image of the titular cicada. Running the cicada image through OutGuess revealed the message: “You have done well to come this far.

Patience is a virtue. Check back at 17:00 on Monday, 9 January 2012 UTC.” As someone with absolutely zero patience, this would have driven me insane.

Fortunately, we live in 2022 now so we don’t have to play the waiting game. Unfortunately, we had to live through 2016-2021 to get here.

But when the time finally came on January 9, 2012, the website updated. Two sets of GPS coordinates were posted on the website, and the hidden message inside the cicada changed to contain 14 total sets of coordinates. These locations were all over the world, which meant two things. The first was that you either needed to live in one of these 14 specific locations, or you were going to need to collaborate with people.

The second, was that shit just got real. Whoever Cicada 3301 was, either they had the money to travel all over the world on a whim, or they were a worldwide organization that could coordinate not just a captivating event online, but across the globe, and this event was going offline.

People quickly went to the locations. At each one they found a street pole, and on that street pole was a picture of a cicada with a QR code. Okay, shit’s done being real and just got virtual again. The QR codes let to two different book codes, each with a riddle hinting at what book to apply the code to.

The first riddle discovered led to a volume of Encylopedia Britannica, not coincidentally the one including the entry for cicada. It was the second riddle solved, and honestly is not very interesting. The other riddle however, read as follows: “A poem of fading death, named for a king Meant to be read only once and vanish Alas, it could not remain unseen.”

This riddle refers to the poem Agrippa (A Book of the Dead) by science fiction author William Gibson. The book was released in 1992 on 3.5” floppy disks, and it was programmed to encrypt itself after a single use. The disk was also packaged inside an artist’s book that was treated with chemicals that would cause the words and images to fade after first being exposed to light. It’s honestly a really cool idea, and I’m sure Simon could do a whole video on the poem over on the Today I Found Out channel.

While there were two different QR codes with two different riddles and sets of book ciphers, they both ended with the same message: “You’ve shared too much to this point. We want the best, not the followers. Thus, the first few there will receive the prize. Good luck.”

At this point, I was a bit perturbed. Whoever Cicada was, they seemed to want the best and brightest, those capable of navigating a complicated digital landscape. But only if those people happened to live near one of 14 very specific real world locations? I understand wanting to find the people that could solve this on their own, but putting such strict geographical restrictions on it meant that, for many, sharing information was a necessity and not something it felt fair to disparage.

It turns out, however, that the cicada website had been updated a third time and the final iteration would lead viewers to images of the street post QR codes without having to physically be there. Well played.

Rant aside, once the book cipher was applied to the Agrippa poem, the result was a string of random letters and numbers with a .onion extension. If this sort of internet mystery is your jam then you probably know what that means already, but ladies and gentlemen, that means we’re going to the dark web! Opening a Tor browser and going to the onion link gave the competitors a message to create a new e-mail address on a public, free web-based service (gmail, yahoo, etc), enter it on the page, and await a message.

They recommended doing it while still using Tor for anonymity, but if you aren’t browsing the web with Tor, you can still protect your identity by using a VPN! Or maybe all this puzzle solving has you pulling out your hair in frustration and you want to prevent future hair loss! I could keep going with these fake ad copy segues, but the joke is already getting stale, unlike those 16 free meals you could have delivered to your door!

I’m gonna be honest about the e-mail that was sent out next: I don’t understand it. It was some sort of numeric encryption thing, but I can’t really decipher what’s going on let alone explain it in a semi-palatable way. Suffice to say, it was a very straight forward and complicated cipher with nothing particularly quirky or neat about it. There were only two key parts of this message, aside from the cipher itself: one was that each participant was given a different number so as to isolate and exclude any leakers of information.

The other we will get to momentarily, as it seems to directly contradict that intention.

Everyone who solved their own numeric puzzle then received one final puzzle. This one was an e-mail containing a MIDI file, which for anyone too young to understand was like really, really basic electronic music from the 90s. Before we had mp3s, the only way to download music was in MIDI form, and it was basically a coin toss whether it would be recognizable as the song you wanted or no.

While the technology has improved since then, it is still a very barebones type of audio file. Analyzing the MIDI file showed that it had only two tracks, and each had less than 26 total combinations of pitch and tone length. It was clear that each of these combinations was supposed to present a letter.

Each participant received a different MIDI file with a slightly different message. After deciphering the code, the songs were shown to contain a congratulations, a list of words unique to each person, and complicated instructions on how to send that list of words back to Cicada. At long last, the puzzle had been completed, so then what happened?

Well not so fast, we have to reexamine the previous clue for a moment.

Second Chances

“I know I don’t deserve a second chance, but this is America! And as an American, aren’t I entitled to one?” – Dr. Robert Underdunk ‘Sideshow Bob’ Terwilliger

Being the Ivy League educated genius he is, perhaps Sideshow Bob had a hand in the foundation of Cicada. I mentioned there were two key pieces of information in the first puzzle to come from the dark web site. Here is the relevant part of that e-mail: “The encrypted message is a number. Break the decryption key, then come back to this same URL and enter the decrypted message to continue.

Each person who has come this far has received a unique message encrypted with a unique key. You are not to collaborate. Sharing your message or key will result in not receiving the next step. There is a second chance to get your own RSA message and key.

Follow the ‘Numbers dot TK’ hint to find it.”

So the message says you will be punished for sharing your message with anyone, but it also informs people of a second chance. A second chance they would not be aware of unless someone shared this message. Talk about sending mixed signals.

The second chance that this referred to goes back to the original website with the cicada image and coordinates. The website was again updated, and it seemed to be closed this time. The website was completely blank, and examining the source code showed that it just had a header with the name of the URL (the product of the three prime numbers from earlier), and a completely empty body.

People quickly noticed, however, that the body of the source code was COMPLETELY empty. It wasn’t just an empty line followed by the closing of the HTML tags, there was entirely too much empty. It couldn’t be viewed normally, but with various tools it was identified that the body of the page was a long string of spaces and tabs.

All you had to do was treat those as ones and zeros, convert the binary to ASCII, and you got a list of numbers. These numbers corresponded to the image URLs that had previously been on the site, showing pictures of the QR code locations around the world.

Okay, so now what? That feels like a lot of work to get numbers that had previously been on the site already anyway, but what was anyone supposed to do with them? An IRC chatroom, presumably full of people who didn’t get the memo about this no longer being a team exercise, were able to solve this riddle.

Some of the original QR codes pointed to the Agrippa poem, and some pointed to the Encyclopedia Britannica. By grouping the numbers by which pointed to which clue, then adding the largest number in each group together, they found that that number .tk was the location of the second chance clue. If I’m being honest, this feels like it was completely brute forced to me.

I can’t find any report or record of a clever way they deciphered this, so I feel like they just played around with the numbers they had until they found the right website. Honestly, it’s as good a method as any at this point.

The .tk site this clue led to was a painting of a woman in medieval clothing sitting alone in a boat on a river. Obviously, the next step here was to run OutGuess on the image to see what surprises this Kinder Egg had inside. The message was simple: “Miss round 1?

Care for a second chance?” Then there was an image URL and another book code. It was strange and a bit redundant for the image to openly link to another image, but here’s the second picture: This image was a PNG file instead of a JPG, so OutGuess was not going to work.

Someone would have to actually know what this picture was to identify the book it was from. And by someone, I mean Google reverse image search. The image did not appear, but a very similar style one did in a book called The Marriage of Heaven and Hell by William Blake.

Looking further into the book, they did find this image inside so they now had the book and the page needed.

If you are unfamiliar with The Marriage of Heaven and Hell, it’s probably because there are only 9 copies of it known to exist. So to solve the 2012 edition of Cicada 3301, you were intended to have access to either a poem, every copy of which was intended to self destruct, or a book from the 1790’s with only nine copies in the world. Even though the internet has managed to preserve digital copies of these works, there is still only one way to describe this: dick move.

Further confusing the collaboration matter, however, was the MIDI file I mentioned. As I said before, the file had two audio tracks. The second track was their congratulations message, but the first was from the poem A Song of Liberty, which is one of the parts of William Blake’s The Marriage of Heaven and Hell.

Perhaps the creators of the puzzle thought people would need a hint as to where to find the obscure image, and wanted to reward further collaboration despite explicitly forbidding it. From here, the puzzle for the second chance puzzle was the same as the others.

A month after this had all begun, a new post was made on the subreddit. This time was an image of white text on a black background, just like the image that started it all on 4chan. “Hello. Thus our month-long journey ends. For now. Thank you for your dedication and effort. If you were unable to complete the test, or did not receive an email, do not despair. There will be more opportunities like this one. Thank you all. 3301”

So what of the winners? What was their ultimate prize? I’m afraid you’ll have to be a little patient, because Cicada promised more opportunities like this one, and they delivered on that promise.

Cicada 3301 – 2013: The Obligatory Sequel

Exactly 366 days later on January 4, 2013, user 3301 once again posted an image on 4chan. This year it was posted 3 times, once to /x/ again, and this time twice to /b/, each posting 24 hours apart. Much like the beginning and end of the last year’s puzzle, it began with an image of simple white text on a black background: “Hello again. Our search for intelligent individuals now continues.

The first clue is hidden within this image. Find it, and it will lead you on the road to finding us. We look forward to meeting the few that will make it all the way through. Good luck 3301”

It was once again time to open up OutGuess and pull the mask off this Scooby-Doo villain. I sure hope they stop reusing this one same tactic before I run out of goofy analogies to amuse myself with. Inside the image was found yet another book code! I guess a whole year wasn’t long enough for them to come up with new tricks. Along with the code was this riddle to identify the book: “A book whose study is forbidden Once dictated to a beast; To be read once and then destroyed Or you shall have no peace.”

I had no idea what book this was hinting towards, but it would seem 4chan figured it out very quickly. I know Simon retains 100% of the information he reads in his scripts, so I’m sure he can tell you which subject of a Biographics episode wrote the book in question. Now that Simon has identified that this obviously is pointing towards Aleister Crowley’s The Book of the Law, all that was left to do was to apply the book code.

The code led to a dropbox with a single file, a 130 megabyte ISO file. An ISO file is an image of a CD or DVD, and is easily readable. Participants could either burn a copy of the file onto a disc, or load it into a virtual disk drive.

Simply popping the disc or image into a drive would initiate boot sequence where the program would display every prime number from 2 to 3301, making pauses at both 1033 and 3301 (adorable), then finally display the message ”@(giant prime number) The key is all around you. Good luck.”

It didn’t take long to identify that the @ sign meant it was a twitter handle. Going to the Twitter account, the tweets were a giant dump of hexadecimal code. Initial analysis of this code resulted in nothing, so it was back to the ISO. Examining the disc showed there were four other files, an mp3, and three files that appeared to be gibberish with file extension of .00, .13, and .17.

The audio file was named 761.mp3, and it was a 167 second song. If you didn’t catch that, the song length is just the file name in reverse. And both numbers are prime. Once again, adorable.

Analyzing the song file and meta data, this message was found: “The Instar Emergence Parable 1,595,277,641 Like the instar, tunneling to the surface We must shed our own circumferences; Find the divinity within and emerged”

This did not help. It was assumed that the Twitter dump was meant to be converted to binary and was only in hex code because of character limits, but the resulting code was not usable in any way. A full day went by, and the trail had seemed to have gone cold. Then, the Twitter account posted another tweet: “Offset: 0, Skip: 0, Col: 65, Line: 988”.

This gave them the column size for the code, which was useful for…reasons, I don’t know. The first two parts, offset and skip, meant that they were intended to start at the beginning and skip nothing. I’d have thought this was obvious. If someone’s already shortening the information for the sake of Twitter, I wouldn’t think there’s room to throw random nonsense in there as well.

But still, the resulting code was useless garbage.

Watch Now

Open Video

Video Briefing

Cicada 3301: The Internet's Weirdest Mystery

The next step was to take this useless garbage and throw it at the mp3 file using every logic gate possible in the hopes that something readable came out. And it did! The XOR (pronounced ex-or) gate is commonly used in cryptography, and it was the solution here.

It just compares the files, bit by bit, and returns 0 if the bits are the same and 1 if they are different. The resulting file was was an image revealing a Gematria constructed by Cicada: If you are unfamiliar with Gematria, it is a Jewish form of numerology in which the letters of the Hebrew alphabet are substituted with corresponding numbers, and words are assigned a value based on their letters. For example, using the Hebrew spelling of Neron Caeser, we would discover a numerical value of 666 using the Gematria.

The Gematria created by Cicada looks a bit imposing at first glance; when I first saw this image I was pining for the days when the answer to everything was just OutGuess and book codes. If you take a second to break this down though, it’s pretty simple: The column on the left are the Anglo-Saxon runes, written in order. The column in the middle are the letters that correspond to those runes.

The column on the right are the first 29 prime numbers in order. The runes are only there to assign an order to the letters, and we aren’t going to need to start reading dead languages to understand these puzzles; we can basically throw that column out so it’s just a bunch of numbers assigned to specific letters or groups of letters. Of note, applying this Gematria to “The Instar Emergence”, the song title that shows up in the ID4 tag of the mp3, gets us a total of 761, the name of the mp3 file.

The Gematria had been found, but there was no indication what to use it on yet. Naturally, the next step was to run this image through OutGuess again. It once again provided a message that was a little too empty.

Using the same trick to convert tabs and spaces to binary, a message appeared with an onion link. The dark web site it led to simply said “Web browsers are useless here”, and had an ASCII art image of a cicada. The participants quickly discovered that web browsers were indeed useless, so they tried a bit of antiquated technology.

It still exists, though I don’t believe it’s used much anymore, but if you were an IT or Computer Science major in the early 2000’s, you will likely be familiar with a program called Telnet. Telnet was essentially a way to remotely control or communicate with another computer, and was notable for allowing two way communication. Before internet service providers existed, my very first online chat was on Telnet when I called my friend’s computer from mine.

The whole process took about an hour for us to finally get to work, and we ultimately decided it was extremely slow and stupid, and using the phone was much easier. In college, Telnet was a way for me to do my Unix programming homework from my apartment instead of having to go to the computer lab that had the Unix machines. And in 2013, Telnet was a way to call up this onion site and say hello.

And I mean that extremely literally. While the site accepted several different commands, the solution was to simply call it up and type hello.

This resulted in another dump of hex code that led to another onion. This new site was pretty boring. All it said was “patience is a virtue”.

Inspecting the HTML code for the page showed nothing else other than the words “which means, come back soon”, and this time there was no room to have hidden a message anywhere. So like the previous year, now it was time to play the waiting game. But the waiting game sucks, and some of this year’s participants weren’t having any of it, so they tried to Telnet into this website as well.

It was not the correct solution, but something much more interesting happened. The attempt made the site spew out an error message that contained the name of the VPS, or Virtual Private Server, that the site was hosted on. They now knew that site was hosted by the company Linode, which meant that somewhere, someone at Linode had billing information for the person or organization behind Cicada.

They also knew that they couldn’t just call up and ask for that information. Perhaps this was just another dead end, and the site was immediately taken down after this discovery.

When the site reopened, it held a simple message: “You already have everything you need to continue. Sometimes one must ‘knock on the sky and listen to the sound.’ Good luck.”

If you immediately recognized that as a quote from the 2010 movie “Tron Legacy”, maybe you should read a fucking book or something, because it is an old, Zen proverb. With the exception of Daft Punk’s soundtrack, that movie was absolutely horrible and shame on you for thinking the writers could have come up with something so profound sounding on their own. The actual meaning of the proverb is irrelevant for our purposes, because the puzzle solvers immediately understood this to mean they needed to ping the server.

A ping is when one computer sends a short message to another which is normally then echoed back. This is used to test connectivity and latency, or lag. If you do any online gaming, you’re probably familiar with the concept as many games have your ping displayed on screen in milliseconds.

I said that normally when you ping a server it just echoes the message back, but in this case it was sending a little something extra as well. Repeatedly pinging the site and combining the extra bytes it sent yielded a message containing yet another onion link. Instead of the organization using a cicada as their logo, maybe they should have used an image of Shrek instead because these puzzles have so many layers.

This new onion showed GPS coordinates around the world again, but of a much more limited scope. There were only seven sets of coordinates this time, five of which were in the United States. The others were in Moscow and Okinawa.

These coordinates led to six posters and one blank pole, the posters each showing a picture of a cicada and a phone number, with a two letter access code underneath it. Each phone number ended in either 3301 or 1033, so the 7th poster was never needed. While the last poster was likely torn down by a bystander, a puzzle solver who did not want to share the information, or public works employees cleaning the city, the phone number was still recovered.

By brute force dialing every single possible phone number in America that ended in 1033. The poster in Arkansas had a phone number for Colorado, thousands of miles away, so just focusing on Maryland where the poster should have been was not going to be enough. Had this not worked, I’m sure they would have moved onto the 3301 phone numbers.

The level of dedication people had to these puzzles was staggering.

It is definitely curious, however, that the physical locations chosen this time were predominantly in the United States. Could this be a clue as to a centralized location for Cicada? Is it just easier to get anonymous phone numbers here than in other countries?

Was this part of the hunt being organized by a lazy intern? Given the sort of attention the 2012 hunt received, I have a possibly more realistic solution: CCTV. The US has approximately 15 CCTV cameras for every 100 people, and is the clear worldwide leader on the metric of cameras to people.

But the US is also absolutely massive and spread out, so while that statistic makes it sound like we are under more surveillance than other countries, in a more meaningful way we are under less. Take the UK for example, where they have 7.5 CCTV cameras per 100 people. There are an average of less than 100 people per square mile in the US, versus 700 people per square mile in the UK, so we have 15 cameras per square mile to their 52 cameras.

It turns out when the people are widely spread out, you need a lot more cameras to watch them all. And with an average of only 15 cameras per square mile in the United States, that leaves a lot more blind spots for people who don’t want to be seen to put up mysterious posters in the middle of the night. This part is entirely personal conjecture of course, and if you have a better idea as to why a supposedly worldwide organization would choose to do this almost entirely in the United States after going fully global the first time, I highly encourage you to GET IN THE COMMENTS and let me know!

Getting back on track, at long last, that Gematria from several steps ago finally mattered. While the phone numbers had an access code printed, they did not want some random person walking by to call and get their top secret message, so the code was not as simple as typing the letters in on your phone’s keypad. First, the letters had to be converted to a 4 digit pin number using the Gematria obtained earlier.

Once the pin number was entered, the robotic voice on the other end would read off more hex code, as well as which of the thus far unused files from the original ISO it was to be applied to. Yeah, you wouldn’t want some random kid walking down the street to call the number and get their hands on that sweet, sweet cryptography; it’s a good thing this was guarded more closely than the QR codes from the previous year. Doing some more nerd shit with this hex code gave the participants from each location a different onion that contained, you guessed it, more computer code.

This time was different, however. If you recall, the real world portion of the 2012 challenge was when Cicada started to discourage cooperation and sharing of information. This time, however, the code was recognized as being in SSSS format, which stands for Shamir’s Secret Sharing Scheme.

It’s a clever way of breaking up secret information with a group of people so that no one person can access the secret without the help of others, but also so not all pieces are required to recover the information. In this case, only 5 of the 7 pieces would be needed; the puzzle creators likely assumed that at least one of the posters would be lost or stolen and did not take into consideration the tenacity of those involved in the search to dial every phone in America until they found the right one. After sharing their bits of data, they were confronted with an onion link, because of course they were.

This link was different, however. The website revealed no cryptic clues or hidden messages. This time, it was a test.

There is No Truth

The final leg of this journey was a literal test, 19 questions with a time limit of 5 minutes. It was a combination of 14 multiple choice questions, 13 of which had the same possible answers, and 5 open ended questions. The test is fascinating, however, because the choice of questions gives a lot of insight into the organization, their beliefs, and what they are looking for. Some of the questions are strictly mathematical or scientific.

These are presumably there because, as in the previous year’s tests, they wanted the best, not the followers, and wanted to weed out those that were simply following the puzzle online and found the onion being shared. Beyond these, however, were a number of philosophical questions.

The 19 questions were displayed to each tester in a different order, as well as a prompt for them to entire their e-mail address. Since the tests were in a random order, however, you very well could have plugged the onion into your Tor browser and been greeted with the following page. Good luck, Simon: This set of 8 responses was the same for all but one of the multiple choice questions. And that’s a Hell of a philosophical question to be saddled with out of nowhere.

Of note is that this and many of the questions that followed are very similar to questions supposedly asked by Google in interviews for key positions within the company. The abstractness of the questions can purportedly be used to determine an applicant’s personality and type. So can a five minute conversation, but I guess that’s just not how interviews work anymore.

The other questions in this style were: What you are is more important than what you do. You cannot step in the same river twice. Observation changes the thing being observed.

This sentence is false. I am the voice* inside my head. (You undoubtedly just thought “I don’t have a voice inside my head.”

That is the voice this question is referring to) Disregarding color blindness, any arbitrary color looks the same to all people. If A is not true, then it must be: People who only study material after a test do better than those who do not study at all. Grass is only green due to a relationship between the grass, the light and your mind.

All things are true We get hundreds of millions of sensations coming into our minds at any moment. Our brain cannot process them all so it categorizes these signals according to our belief systems. This is why we find evidence to support our beliefs and rarely notice evidence to the contrary.

1 = 0.999999 repeating

This is quite an array of questions. The last question, for example, is demonstrably true. I know of multiple mathematical proofs that show 0.999 repeating does in fact equal 1. However, “we cannot step in the same river twice” is a much more philosophical question, and an extension of the Ship of Theseus thought experiment.

Obligatory plug for the TopTenz video on the “10 most famous thought experiments” here. While I would argue that at least half of these questions have a definitive correct answer, I suspect it is not nearly so simple in the minds of whoever created this test.

The other multiple choice question is another one that I would argue is scientific, but there’s no way to know for sure how they meant it: “Two people are standing by a lake. One says, ‘That’s a lovely reflection in the water.’ The other says ‘I see no reflection, but it’s a fascinating assortment of fish, plants and rocks within the water.’

Which one is lying?” The choices for this question are obviously one, the other, both, or neither. Regardless of how they meant this, or any of the multiple choice questions, there is always the chance that someone could blindly stumble into the “correct” answers, and that brings us to the open ended questions.

Remember, there was a time limit, so doing outside research on these questions was not a realistic option: The mathematical operation known as addition is modeled after what? Explain, in your own words, what mathematical principle is relied upon for the security of Shamir’s Secret Sharing Scheme. What does the word “it” refer to in the following sentence: It is dark outside?

In the programming language of your choice, write a function that returns a function that returns the value of 3301. And finally, my favourite question on the entire test, and one that would have made me thought this was written in 2016 and not 2013: Name similarities between reality and the concept of the “News Feed” on facebook? I suspect leaving this question blank would have been perfectly acceptable, as I see no similarities between Facebook’s news feed and reality.

Once the tests were submitted, anyone whose test answers were deemed suitable received an e-mail instructing them to build a web server capable of performing a series of specific instructions. They were given until February 3, 2013 to complete this task. And on the date of February 3rd…nothing happened.

Nor the next day. It wasn’t until a full two weeks later, undoubtedly an eternity for the people who had submitted their programs, that the servers were finally pinged. A log from one of the servers shows Cicada connecting to it, testing all the functions that they demanded were implemented, and then logging off.

The whole thing took exactly three and a half minutes, a fact that I can only imagine made the two week wait time infuriating. And so concluded the final test of 2013. Don’t despair, because this isn’t the end of the story of Cicada 3301, it was just the last thing anyone would know until 2014.

Or at least, it was the last thing anyone was supposed to know.

The Leaked E-Mail

If you haven’t figured it out by now, the participants in the last two years of puzzle solving haven’t been particularly good at keeping secrets. While much of the information I’ve discussed with you thus far was public information, some of the pieces from the end were reports from supposed winners and was all considered unverified information for the first few years. These were things that were not meant to be shared, but given the extensive detail available now about literally every part of this, it is clear that they just couldn’t keep their mouths shut.

So what happened to the winners each year? In 2012, there was a leaked e-mail from one of the supposed winners. As best as I understand it, they changed some of the wording and punctuation on the assumption that every winner had received a slightly different message in order to identify any leakers, but by editing it, the PGP signature was removed so it was no longer verifiable as an authentic Cicada message.

Here is the leaked e-mail, with the punctuation cleaned up so Simon doesn’t have to struggle to read it:

“DO NOT SHARE THIS INFORMATION! Congratulations. Your testing has finally come to an end. We hope you have enjoyed the “vacation” over the last few weeks. You will be very busy now should you choose to join us. There are two final steps, although there won’t be any hidden codes, or secret messages, or physical treasure hunts. This first of these is only honesty. We have always been honest with you, and we shall continue to be honest with you. And we expect you to be honest with us in return. You have all wondered who we are, and so we shall now tell you : We are an international group. We have no name. We have no symbol. We have no membership rosters. We do not have a public website, and we do not advertise ourselves. We are a group of individuals who have proven ourselves. Much like you have by completing this recruitment contest. And we are drawn together by common beliefs. A careful reading of the texts used in the contest would have revealed some of these beliefs : that tyranny and oppression of any kind must end; that censorship is wrong; and that privacy is an inalienable right. We are not a “hacker” group. Nor are we a “warez” group. We do not engage in illegal activity, nor do our members. If you are engaged in illegal activity, we ask that you cease any and all illegal activities or decline membership at this time. We will not ask questions if you decline; however, if you lie to us we will find out. You are undoubtedly wondering what it is that we do. We are much like a “Think Tank” in that our primary focus is on researching and developing techniques to aid the ideas we advocate : liberty, privacy, security. You have undoubtedly heard of a few of our past projects. And if you choose to accept membership, we are happy to have you on board to help with future projects. Please answer the next few questions, and send your encrypted responses to c1231507051321@gmail.com * Do you believe that every human being has a right to privacy and anonymity, and is within their rights to use tools which help obtain and maintain privacy : i.e., cash, strong encryption, anonymity software, etc? * Do you believe that information should be free? * Do you believe that censorship harms humanity? We look forward to hearing from you. 3301”

When this e-mail was first leaked, it sparked a lot of controversy. On the one hand, it could not be verified as an authentic message from Cicada. On the other, it was being vouched for by people who were known to have solved the puzzle.

From everything we’ve just experienced going through those two years of puzzles, it certainly seems believable that this could have been the real e-mail, but there was still that lingering doubt due to the lack of PGP signature. Sorry to all the skeptics out there, but this e-mail was genuine. In 2013, the winners received the same e-mail, and in 2014 one of those previous winners uploaded their message, complete with the PGP signature, to pastebin.

And then told nobody about it. It was discovered by someone on a hacker forum in 2016, and then rediscovered by a redditor in 2019. Somehow, it wasn’t until 2021 that someone once again rediscovered it and made enough noise for people to actually pay attention to that fact that there was confirmation of the veracity of this message.

Unfortunately, this was a manifesto, not a dossier. Now people had irrefutable proof of what Cicada stood for, and an extremely vague idea of what they did, but we were no closer to identifying any members. Who they were, where they were, and why they had to operate in such clandestine ways were all still a mystery. It’s not like “tyranny is bad” or “a right to privacy is good” are exactly controversial ideas that can only be whispered in the shadows, especially when they are so adamant that illegal activities will not be tolerated.

One more interesting bit about the leaked e-mail, however, is exactly how it was leaked. I mentioned that I cleaned up the punctuation a bit for Simon, but I actually used the 2013 e-mail (which was identical except for the e-mail instructions). The leaked e-mail from 2012, however, opened with this little bit of text: “3301 cicada, this has been modified from your orriginal text in order to remove your uber sekret 0hd4y identifications signature. If you think it belongs to any particular applicant it does not; and you DO know what I mean. u mad?”

There was also a “Begin FU” and “End FU” on either side of the leaked text. That all seems a little childish and vindictive and, oh wait, there’s more text added to the end of the leak: “We look forward to hearing from you. Anonymous”.

Cicada may have forgotten that they weren’t the only organization on the internet that believes in privacy and free information. Was this message truly from Anonymous? They don’t use fancy, verified signatures, so who can say.

Considering the leaker of this e-mail made it to the end of the puzzle and definitely types like someone from 4chan, I’d say the probability is pretty high. Perhaps they leaked this because, while the groups had similar ideals, Anonymous didn’t like the elitist tone of the search, the disparaging of collaboration, or the sense that Cicada was born out of privilege and status rather than memes and lulz. Or maybe they didn’t like that the group was using a lame symbol like a stupid insect instead of something cool like the visage of a convicted terrorist.

I was really hoping this was going to lead to some badass internet turf war between Anonymous and Cicada, especially given their implication that this e-mail was not leaked by a particular applicant but rather stolen from Cicada’s server. However, since Anonymous did not release a massive dump of information about Cicada, this was likely just a boast and the message really was leaked by an individual. Sadly, this potential rivarlry is one more loose end, still waiting to be tied.

Liber Primus

On January 4, 2014, people on the internet once again gathered and prepared for the next round of Cicada puzzles. A few fake puzzles appeared, but nothing verified from Cicada. Was it over? The day ended with nothing but charlatans and disappointment.

But the very next day, the same thing happened again. Lame. On January 6th, however, the Twitter account used in the 2013 puzzle suddenly tweeted a link to Imgur. It was another black image with white text that read: “Hello.

Epiphany is upon you. Your pilgrimage has begun. Enlightenment awaits. Good Luck.

3301.” And so the game was afoot!

Before we begin this year’s set of puzzles, however, how about a little real talk. We went through the first two years of puzzles in great detail. We learned some stuff, hopefully had a few laughs, but that’s all behind us now, and it’s time to move on.

Do you really want to go through all of that for a third time? These challenges are densely packed with highly technical information about cryptography and computer programming, but this is supposed to be Simon’s light-hearted ghost hunting channel! You came for Ancient Aliens, and I gave you NPR, and for that I am sorry.

Look, what I’m trying to say is that this year’s puzzles are way too fucking hard for me to understand. Oh sure, it starts off with your usual OutGuess and book code, then it immediately goes off the rails into a cipher so complicated that it took my favourite math Youtube channel (Yes, I really have one) a ten minute video just to explain what it even is, and that doesn’t even address how you would go about solving one. And the best part of that?

The participants in this year’s puzzle didn’t really solve it in any clever or meaningful way. That answer may have existed, but they just gave up and brute forced it like when they dialed all those phone numbers. It did work though, and ultimately, through a combination of brute force, a lot of stuff I don’t understand, and of course some more OutGuess, they finally reached the end of the puzzle.

And as usual, after the final answer was submitted, they heard nothing from Cicada right away. The radio silence continued much longer than normal, but eventually, long after the community as a whole gave up waiting, there was a response. While some people claimed to receive a congratulations letter similar to those in 2012 and 2013, nothing to that effect was ever confirmed.

Instead, Cicada sent an image dump containing 58 pages of runes. These, combined with several images from earlier in the 2014 puzzle, make up the “Liber Primus”, which literally translates to “first book”. From what I can tell, the “Liber Primus” is something of a manifesto written by Cicada.

There are 76 pages total, but the first two are just the title and a full page to say “Chapter 1”, so there are 74 actual pages of text. These pages look something like this: All 58 new pages of text are encrypted differently, and in the almost 8 years since this manuscript was released, only two of those pages have been solved so far, and none since 2014. It’s not for lack of effort, either.

The community of people interested in Cicada has continuously expanded since the release of this puzzle.

Let me give you an idea of just how obtuse some of the known solutions are. Complex ciphers generally need a key to solve, some string of characters that is run against the encoded text through a sophisticated algorithm to deliver the unencrypted message. In the previous years, whenever such a key was needed, there was either a strong hint towards it, or the key was given as the reward for completing part of the puzzle.

The “Liber Primus” is different, however. Even for the pages in the early portion of this year’s puzzle, having a hint for the key was not necessarily good enough. After solving a puzzle, it was determined the key for decoding one of the pages was the word “circumference”.

Except that didn’t work. The actual key was “firfumferenfe”. I’ve seen some unconvincing arguments as to how this theoretically could have been deduced, but it really feels like one of the participants got very angry and very drunk, and just started smashing away at their keyboard.

And remember, this was still in the “easy” portion of the puzzles, before Cicada took a 58 page dump on the cryptography community.

But is the puzzle even worth solving? Everything from the previous years was able to be solved relatively quickly with some teamwork and dedicated effort, each journey was only about a month long total. These pages have remained unsolved for almost a decade, with no signs of progress, and I’m of the opinion that’s probably for the best.

Sure, it’s nice to have closure, but allow me to read you a passage from one of the pages in the early part of the 2014 puzzle: “A WARNING BELIEVE NOTHING FROM THIS BOOK EXCEPT WHAT YOU KNOW TO BE TRUE TEST THE KNOWLEDGE FIND YOUR TRUTH EXPERIENCE YOUR DEATH DO NOT EDIT OR CHANGE THIS BOOK OR THE MESSAGE CONTAINED WITHIN EITHER THE WORDS OR THEIR NUMBERS FOR ALL IS SACRED” Does the world really need 60 more pages of this? Yes, solving it could earn you membership into the elite Cicada 3301, but that may not be all it’s cracked up to be.

There’s No I In Team

But there is one in Cicada, and according to two winners of the 2012 puzzle, that was a problem. These two appear to be universally be regarded as credible sources, but there is no hard evidence I could find, so you are free to remain skeptical if you choose. These two were Marcus Wanner, and another who simply went by the name Tekknolagi.

If it isn’t clear from that username, he and Marcus were both teenagers at the time, and in fact had worked together in a group of about 12 people on the puzzles. From what they described, the prize for completing the challenge was a bit…underwhelming. They were invited to a website on the dark web and each given a login and password.

The site featured a chatroom of about 20 people, an instant message feature, and a message board of some of the groups projects and ideals. The members of this room were mostly new recruits, with a few veterans there for guidance.

The project that the group decided to work on was to be a “dead man’s switch”, a way to encrypt information and release it publicly in the event of the death or imprisonment of the individual keeping that information safe. They called it the Cicada Anonymous Key Escrow System, or CAKES for short. To be fair, that’s not a bad goal.

Especially for those living in countries where journalists are prone to disappearing or being arrested for treason, having a dead man’s switch like this could be a valuable asset. But there was just one problem. Cicada had encouraged individualism and individual talent, disparaging those who worked as a team.

While the accounts we have are from two people who did make it while being part of a team, this may have been the exception rather than the rule. The recruits were not properly accustomed to working as a team. They were trying to undertake a massive, unprecedented project, and they spent their time either arguing or working on it individually.

In only took about two weeks for Tekknolagi to stop logging into the Cicada board. “I just got bored,” he said. “I had a job.

I was working at a startup and of course that requires focus. Also the puzzle solving was over and I was what? Sixteen?

Short attention span. It’s just the puzzle solving is over so I said, ‘Screw this, I’m out.’”

He was not alone, and the chatroom of 20’s numbers did not take long to diminish. But what of Marcus and those that remained? They stayed hard at work on CAKES, working individually and sharing notes.

The veteran members of Cicada would drop in and share their notes and comments on the project, but that wasn’t enough. The high of having been accepted into this great organization had faded, and now all that was left was working in solitude. A mountain of time consuming work, assigned to a bunch of high school teenagers that felt that had more important things to do than change the world.

I actually have no idea if they were all teenagers or not, but either way it’s hard to fault them for dropping off. They were given no real information about the organization they were supposed to be part of. Even after almost a year spent on CAKES, Marcus knew little more than when he started.

And of course, this is just work being done and shared on the dark web amongst like-minded individuals; there’s no time clock or anything. I would absolutely love to work 80-100 hour weeks on something that could change humanity for the better, but fucked if I’m doing that for free…maybe I should be working for Big Pharma.

By the end of 2012, Marcus was the only person left working on CAKES, and he’d hit a dead end. He appealed to the veteran Cicada members in the chat to recruit new members to help him finish the project. This was the end of 2012 and the second series of elaborate puzzles begun on the anniversary of the first, so I don’t think his cries for help had anything to do with it.

Marcus had joined Cicada to work with others and broaden his horizons, and of course to do something ground-breaking, something that would change the world. Instead, he was quickly left with nothing but more isolation. He was a home schooled child, and I imagine this felt like more of the same.

His elders left him alone with a pile of work, and no one to talk to or collaborate with. After the 2013 puzzles concluded, the dark web chatroom remained a ghost town. Maybe none of the new applicants had fully passed Cicada’s test, maybe there were assigned to different projects, or maybe the authorities had infiltrated the organization and everything was going to come crashing down.

Marcus had no way to know amidst the radio silence. But then in March of 2013, he received a message from someone else who had been a member of his project the previous year, four simple words: “We’ve been laid off.” When Marcus went back to the dark web forum, it was gone.

Once again, dick move.

Much like Tekknolagi and Wanner did some interviews and talked about their experiences with Cicada, so did one of the 2013 winners, a Canadian who went by the name Nox Populi. Nox did an interview with the magazine The Face, which is a British fashion magazine? Simon, help me out here; I can’t tell if it’s supposed to be like Vogue or like Rolling Stone, the latter of whom had run interviews with the previous winners.

Nox’s experience was much different than our previous winners. He received an invitation from Cicada, and waited to join a group to work on the project they were assigned to, but nothing ever came. Had they thrown in the towel?

Well, we know that’s not the case because they released the puzzle in 2014, but that doesn’t mean they didn’t take a hiatus. This was taking place in 2013, which was the same year as the Edward Snowden leaks. These leaks made everyone in cryptography real scared, real fast.

Suddenly, their efforts had to be spent searching everything for backdoors and NSA surveillance rather than doing any actual work. Combine that with the failure of the first year’s project to produce results, and it makes sense that they may have wanted to just take a step back for a bit and regroup. Still, Nox’s story is the last credible piece of information that we have regarding Cicada and their inner workings.

Cicada 3301 – Post 2014

So where are they now? What had Cicada been up to since they released the puzzle in 2014? The internet again waited in anticipation in January, 2015, but no puzzles came.

Perhaps, with the previous puzzle still unsolved, they felt there was no need. Perhaps they got as bored as the winners of their puzzles had become. We really don’t know what they were up to.

There was only a single message from Cicada in all of 2015. In July of 2015, Planned Parenthood was hacked, and personal data of hundreds of thousands of employees was stolen. The anti-abortion group that claimed responsibility for this attack went by the name 3301.

No, that was not the message from Cicada that year. Cicada’s Twitter account quickly linked to a PGP signed message stating that they were in no way tied with the attack or any illegal activities, and that they did not condone the use of their name, number, or symbolism. After their very bold decision to state that “terrorism is bad”, there was more silence.

January of 2016 came again, and there was still no new puzzle. This time, however, there was a message. On January 5th, Cicada’s Twitter account posted a link to their standard white text on black background image, with the following text: “Hello.

The path lies empty; epiphany seeks the devoted. Liber Primus is the way. Its words are the map, their meaning is the road, and their numbers are the direction.

Seek and you will be found. Good luck. 3301 Beware false paths.”

This message was both an indication that they were still waiting for people to finish decrypting the Liber Primus, as well as an instruction for people to stop fucking around with all the copycat puzzles out there. It was nice to know they were still watching and waiting, but a hint of some sort would have been nice. It had been years, and no one had solved this puzzle yet.

But no hints would ever come. The final communication from Cicada came over a year later, in April of 2017, and it simply repeated to beware false paths. Thanks, super helpful.

Who Is Cicada 3301

There have been a lot of puzzles and mysterious goings on this episode, but finally we reach the ultimate question: who exactly is Cicada? The accidental revelation that their VPS was being hosted by Linode was the closest thing to a solid lead we ever got, but it yielded nothing. Still, there are a lot of theories.

While we know that the winners of the puzzles don’t have the answer to that question, Tekknolagi had the most to share on the matter. Given the skill and organization required to set up these hunts, particular the precision with which everything had to be timestamped in order to work, he felt it unlikely this was just a random group of cryptography enthusiasts chilling in their moms’ basements. It was far too professional for that.

But he also gives the sense that they wanted to seem far more professional and important than they may have been. “They wanted to make it seem like they were this network of people that had ‘infiltrated,’ if that’s the right word, various private and public organizations,” Tekk said, specifically mentioning publisher Conde Nast, a global media company worth $1.8 billion. When he asked permission to write about his journey during the test, he was told to hold on, because they had someone at Wired that could get the article published.

The teen was neither interested in waiting nor in being in Wired, so he went ahead and put it on the internet himself anyway, but it does raise the question of how liberally they were using the term “infiltrated”. Could they get this published because the Conde Nast CEO was a member of Cicada, or because one of the members was a staff writer at Wired and could try to talk his editor into letting him run the story. Were I a member of Cicada, would they claim to have infiltrated YouTube since I’m not writing scripts for Simon?

I’m inclined to think that yes, they would.

Overall, Tekk felt the entire experience was weird and creepy, with a lot of cult-like vibes. Tekk also described the dark net forum itself. The writing was very informal, with spelling and grammatical errors, so it is unlikely that this was the secret base of operations of the NSA, CIA, or GCHQ. It was too meticulous to be a bunch of random nerds having a laugh, but too slovenly to be a major government organization.

After being asked about it in an interview, Tekk also disputed the notion that this could be any sort of secret, cyberterrorist group. “There was really nothing ever said to the tune of disruption or virus creation or whatever,” he said. “All of it was like, ‘Oh yeah; we’re going to release some public open source software.’”

So we’ve hypothetically ruled out trolls, government organizations, and terrorists or other malicious actors. Who is left? One idea that people love bringing up is that it’s some shadowy organization like the Freemasons.

That’s certainly possible, that it’s an organization like the Freemasons, but I’m gonna go out on a limb and say it’s not actually them. Once upon a time, perhaps the Freemasons did run the world, but now there are literally radio commercials directing you to a website to join the Masons. My brother was walking out of the supermarket, and one of the Shriners, a subset of the Masons, said “Hey there, you’re a white male ages 18-55.

Have you ever thought about becoming a Freemason?” I don’t think a single organization would be so lax in its recruitment on one hand, and so supremely secretive and selective on the other. Maybe that’s just what they want me to think, and if so then well played, but I’m honestly not buying it.

Another theory is that it’s all just an Augmented Reality Game. That goes completely contrary to the testimonies of the winners, but they could have been in on it from the beginning. They may have been plants to help guide the competitors to the solutions, like a Gamemaster in an escape room, but for the third year they decided to remove the training wheels and have people give it a go on their own.

This is a theory, but it doesn’t seem to hold much water. Notably, and rather bewilderingly given how disappointing the experience of winning seemed to be the first time, Marcus Wanner can still be seen toiling away in an attempt to solve the Liber Primus. This only makes sense if he were not a plant, which would also mean his experience in Cicada was genuine, which would mean it’s not just an ARG.

More importantly, were it a game that had gone on this long, surely by now the creators would have attempted to monetize it in some way. I’ll leave it to you, the listener, and also to Simon, to come to your own conclusion, because I don’t really have one. If there was any evidence pointing towards who could possibly be behind or even involved with Cicada, then I don’t think this month (at the time of writing) would have marked the 10 year anniversary of the very first puzzle.

The only recurring thought I had during all of this research was “Damn, this sounds exactly like the sort of shit that Elon Musk would do and then immediately get bored with.” The man sold and manufactured flamethrowers on a whim, there’s no telling what he’ll get up to next.

Bonus Fact

Remember halfway through the episode when I did that fun little trick using statistical averages to try to assert that Americans are under less surveillance than most other countries? It turns out that you can pick and choose statistics while omitting important information to support any claim you want! For example, we all know that the United States is one of the worldwide capitals of gun violence. After all, we have 120 civilian owned guns for every 100 people, which is also roughly the population per square mile.

But what about, oh, I don’t know, Prague? The Czech Republic has 12.5 guns per 100 people, and Prague has 12,000 residents per square mile. That means that there are currently 1500 civilians packing heat per square mile of Prague. I hope you sleep well tonight, Simon.

Presented by

Simon Whistler

Simon Whistler is one of YouTube's most prolific educational creators. Decoding the Unknown is his methodical investigation into the world's strangest phenomena — examined with rigour, curiosity, and a healthy dose of scepticism.

Frequently Asked Questions

What is Cicada 3301?

Cicada 3301 is an anonymous organization that has conducted a series of internet puzzles and challenges since 2012, seeking highly intelligent individuals.

When and where did the first Cicada 3301 puzzle appear?

The first Cicada 3301 puzzle appeared on January 4, 2012, on the /x/ message board of 4chan.

What was the first clue in the 2012 Cicada 3301 puzzle?

The first clue was a message hidden in an image of white text on a plain, black background, which led solvers to a Caesar cipher.

What was the purpose of the Cicada 3301 puzzles?

The puzzles were designed to find highly intelligent individuals who could potentially join the organization, which advocates for privacy, liberty, and security.

What was the significance of the Liber Primus in the 2014 Cicada 3301 puzzle?

The Liber Primus is a 76-page encrypted manuscript that serves as a manifesto written by Cicada 3301. It contains complex ciphers that have largely remained unsolved.

What was the experience of Marcus Wanner and Tekknolagi, winners of the 2012 Cicada 3301 puzzle?

Marcus Wanner and Tekknolagi found the experience underwhelming and isolating. They worked on a project called CAKES but eventually lost interest and left the organization.

What was the final communication from Cicada 3301?

The final communication from Cicada 3301 was in April 2017, repeating a warning to beware false paths.

What are some theories about the identity of Cicada 3301?

Theories include a shadowy organization like the Freemasons, a government agency, or an augmented reality game. However, none of these theories have been confirmed.

What was the significance of the 2013 Cicada 3301 puzzle involving GPS coordinates?

The GPS coordinates led to physical locations around the world where participants found posters with phone numbers and access codes, continuing the puzzle-solving process.

What was the outcome of the 2013 Cicada 3301 puzzle?

Participants who completed the puzzle were invited to build a web server capable of performing specific instructions, but the project ultimately failed due to lack of collaboration and interest.

Sources

Related Articles