Here is the problem. The physical scale of the puzzle spanned the globe, but the digital paperwork points to a shoestring budget. The server hosting that entire operation sat on a cheap, shared commercial block alongside ordinary civilian blogs. We are looking at a total disconnect between the boots on the ground and the server bill.
Data Manifest
- Primary Investigation: An Investigation into the Infrastructure and Archival Records of Cicada 3301.
- Key Anomalies Documented: Low-cost DreamHost shared hosting (ASN AS26347) leased alongside civilian blogs for an international cryptography puzzle; a US Navy Market Research Society case study citing a 0.25 per cent demographic target for Project Architeuthis; an NSA Glomar response (FOIA Case 85764) citing Section 6 of Public Law 86-36; CIA FOIA logs from October to December 2016 recording overlapping 'CICADA 3301' queries with missing disposition pages; a 'No Records Located' US Navy FOIA return (DON-NAVY-2023-015936) for Project Architeuthis contractor emails; and a documented UK GCHQ talent pipeline at the Heilbronn Institute for Mathematical Research (University of Bristol) contrasted against Cicada 3301 having zero registrar or contractor records.
- Primary Sources Utilised: Market Research Society US Navy Project Architeuthis Case Study; NSA FOIA Case 85764 Response Document; CIA FOIA Case Logs (October to December 2016); SECNAV FY23 FOIA Log; Heilbronn Fellowships Further Particulars (University of Bristol).
Glossary
| Term | Definition |
|---|---|
| Glomar response | A formal answer where a government agency refuses to confirm or deny that any records on a topic exist. Named after a CIA-linked ship called the Glomar Explorer. |
| FOIA (Freedom of Information Act) | The US law that lets members of the public ask federal agencies for copies of their records, subject to a list of exemptions. |
| .onion address | A web address that only loads through anonymising software called Tor. The server's real location is concealed. |
Tracing the Budget Lease
On 3 January 2012, someone generated an RSA 4096-bit public key. RSA is the standard for digital signatures that prove a message came from the holder of a specific cryptographic key, and 4096 bits is large enough to be effectively impossible to forge with current computing power. The full fingerprint runs 6D854CD7933322A601C3286D181F01E57A35090F. From that day onward, every authentic Cicada 3301 message carried that exact signature. Anything else was treated as a copycat by the solver community, and discarded.
That key sat behind a domain called 845145127.com.
Run the domain through a routing lookup. It points at the IPv4 address 75.119.203.244. The address falls inside an ASN, an identifier assigned to organisations that run their own slice of the internet. This one is AS26347, registered to New Dream Network, LLC, trading as DreamHost. DreamHost is a low-cost shared host. Anyone with a credit card can rent space on it.
Look at the rest of that server block. Civilian domains. Ordinary blogs and small commercial sites, hosted shoulder to shoulder with the server that ran a four-year international cryptography puzzle.
And then the operators changed the routing. They flipped the DNS A record on 845145127.com to 127.0.0.1, the loopback address. That is the digital equivalent of redirecting all post to your own front door. After the flip, solvers could only reach the puzzle by typing the bare IP straight into a browser. We have no commercial subpoena return naming the account holder who paid for that lease.
The Cryptographic Identity vs. The Infrastructure Footprint
Cryptographic Scaffold
3 January 2012
RSA 4096-bit (Fingerprint: 6D854CD7933322A601C3286D181F01E57A35090F)
Server Footprint
DreamHost (AS26347) — Low-cost shared block
Domain 845145127.com flipped DNS A record to loopback address 127.0.0.1
The Physical Footprint Disconnect
Then the countdown ran out. On 9 January 2012 at 17:00 UTC, the timer on 845145127.com hit zero. The page dumped a raw list of fourteen GPS coordinates.
Map them out. The points land in Warsaw, Paris, Seattle, Seoul, Miami, New Orleans, Sydney and Hawaii.
The physical deployment happened almost immediately. Somebody had to walk up to utility poles across five countries to tape up paper posters. Each poster carried a cicada logo and a QR code. Scanned by a phone, the code routed visitors to sq6wmgv2zcsrix6t.onion, an address that only loads through anonymising software designed to hide where the real server sits.
Now hold those two facts together. A poster taped to a utility pole in Hawaii. One server on the open internet whose physical location is deliberately concealed. The puzzle had a physical foot in eight cities at once, and a digital head that nobody could trace.
And the host of that head was DreamHost on a shared block.
Compare the shape of this against the closest official equivalent. When GCHQ launched its ‘Can You Crack It?’ recruitment campaign on 2 November 2011, the domain canyoucrackit.co.uk had been formally registered by an advertising agency, TMP (UK) Limited, months ahead of the launch. There is a paper trail. We expect to see a corporate registrant. We look for an agency of record and a signed contract. Cicada has none of that. We see no registrant and no contractor. There is no public award submission. Just a DreamHost lease whose buyer is not named in any document we have seen.
Support the Archive
Help fund the retrieval, hosting, and preservation of Veriarch investigations.
What State Recruitment Paperwork Actually Looks Like
Here is what state cryptographic recruitment looks like on the public record. There is paperwork. Lots of it.
GCHQ ran ‘Can You Crack It?’ from 2 November 2011. The domain canyoucrackit.co.uk had been formally registered by an advertising agency, TMP (UK) Limited, months ahead of the launch. Cabinet Office FOIA returns and trade-press coverage tie the campaign back to that agency contract.
Two years later, GCHQ ran a sequel. ‘Can You Find It?’ went live on 12 September 2013, on the same pattern. It had a registered domain, a named contractor, and a launch date.
Then comes the US Navy’s ‘Project Architeuthis’, launched on 28 April 2014. Lowe Campbell Ewald served as the agency of record on the work, a federal advertising contractor. The campaign hit benchmarks specific enough that the Market Research Society published a detailed case study on it. That study sets out the precise enlistment target. They were after 1,291 cryptology recruits, drawn from a demographic representing less than one quarter of one per cent of the country’s population.
We read through that entire case study. It tracks the marketing analytics. You can see the demographic targeting maps. They even laid out the media spend breakdowns and the full campaign timelines.
Project Architeuthis won awards too. They submitted a Shorty Awards entry. Communication Arts ran a feature on it. The entire marketing afterlife is archived online. Now line Cicada 3301 up next to that. We see zero registrar records. Nobody signed a contractor agreement. There is no public budget. We have no award submissions.
Four years of cryptographic puzzles ran on this scaffolding. Eight cities saw the physical postering. A cryptographic key was generated to the second. Nothing on the public record names who paid the bill.
Public Accountability: State Campaigns vs. Cicada 3301
| Campaign | Registrar / Contractor | Public Records & Analytics |
|---|---|---|
| GCHQ 'Can You Crack It?' (2011) | Domain registered by TMP (UK) Limited | Cabinet Office FOIA returns, trade-press coverage |
| US Navy 'Project Architeuthis' (2014) | Lowe Campbell Ewald | Market Research Society case study, Shorty Awards entry, demographic targets |
| Cicada 3301 (2012–2016) | None (Unnamed buyer on a DreamHost shared lease) | No public budget, no registrar records, no award submissions, no visible contractor |
The NSA Will Not Confirm or Deny
A public requester filed NSA Freedom of Information Act Case 85764 on 19 October 2019, asking the agency to release any records it held on Cicada 3301.
On 10 March 2020, the NSA returned a Glomar response. A Glomar is the formal refusal to confirm or deny that any records exist, named after a CIA-linked salvage ship from the 1970s. NSA cited Section 6 of Public Law 86-36, codified at 50 U.S.C. 3605.
What the agency did release ran to four pages. Inside those four pages, internal URLs and the names of NSA employees had been redacted under the same statute. The pages themselves are stamped and dated. We can see the shape of the file without seeing its contents.
Our reading of the Glomar is this. Confirming or denying any record would let an outside observer map out which open-internet services the agency tracks closely enough to keep files on. That is our analysis, not a statement the NSA made. NSA’s public response only cites the statute.
A parallel paper trail sits at the CIA. Look at the FOIA case logs for October to December 2016. You will see overlapping queries that reference ‘CICADA 3301’.
We even have the related request numbers:: F-2017-00103 and F-2017-00104. But here is the problem. Their disposition pages are entirely missing from the released log.
FOIA Case 85764: Glomar Response
- The NSA refuses to confirm or deny that any records on Cicada 3301 exist.
- Statute cited: Section 6 of Public Law 86-36, codified at 50 U.S.C. 3605.
- Four pages released: Internal URLs and NSA employee names redacted under the same statute.
The Navy Cannot Find Its Own Emails
Now circle back to Project Architeuthis. We checked the Navy FOIA logs for 5 September 2023.
Somebody filed a request under log number DON-NAVY-2023-015936. They were asking for internal emails about the project. Specifically, they wanted anything sent to or from the contractor address @lowe-ce.com.
Navy response came back: ‘No Records Located’.
That is the disposition the SECNAV FY23 FOIA log shows. We are looking at a search that returned no records for an award-winning 2014 recruitment campaign. This is a project that has its own Shorty Awards entry, its own Communication Arts feature, and its own Market Research Society case study citing a target of 1,291 cryptology recruits. The campaign exists in public industry archives. Its internal email trail at the Navy does not.
We have no Navy archive policy in the pack that explains the absence.
Navy FOIA Log Disposition: DON-NAVY-2023-015936
- Target: Internal emails regarding Project Architeuthis and contractor @lowe-ce.com.
- Filing Date: 5 September 2023.
- Disposition: 'No Records Located'.
The Visible Pipeline the State Actually Funds
For contrast, look at what a visible state pipeline for cryptographic talent actually leaves on the public record. The Heilbronn Institute for Mathematical Research, HIMR, sits inside the University of Bristol.
We pulled the public Further Particulars document for their fellowship programme. It confirms that fellows must obtain GCHQ security clearance as a hard condition of the role. HIMR fellows conduct independent academic research alongside that clearance requirement. But how they actually split their time between open research and classified work is entirely absent from the public PDF.
That is the visible side of the trade.
Public funding records show a named institute, a named host university and a published fellowship programme. Financial scaffolding is documented. Cryptographic recruitment is documented. Cicada 3301 has no such scaffold on the public record.
We have a comparator that matters. A visible pipeline runs through a named institute and a named host university. No equivalent named institution sits behind Cicada 3301, only an unnamed buyer of a DreamHost lease.
State Recruitment Paperwork: Visible vs. Missing
Heilbronn Institute (HIMR)
Named UKRI funding block.
Visible host university (Bristol).
Published fellowship programme requiring GCHQ security clearance.
Cicada 3301
No registered contractor.
No public budget line or visible pipeline.
Unnamed buyer of a DreamHost lease.
Source
Sources include: the cicada-solvers GitHub repository and IPinfo.io routing returns for the 75.119.203.0/24 range; the Saumitra Sapre puzzle archive; the Market Research Society case study on the US Navy ‘Project Architeuthis’ campaign; the NSA response document for FOIA Case 85764; CIA FOIA case logs from October to December 2016; the SECNAV FY23 FOIA log; and the University of Bristol’s ‘Further Particulars’ document for the Heilbronn Fellowships.
Claim-Source Matrix
| Core Finding | Primary Source Document | Status |
|---|---|---|
| Domain 845145127.com resolves to IPv4 75.119.203.244 inside ASN AS26347 (New Dream Network, LLC, trading as DreamHost). | IPinfo.io Routing Data (ASN AS26347 / Range 75.119.203.0/24) | Confirmed |
| Fourteen GPS coordinates published on 9 January 2012, with QR-code posters appearing within roughly 24 hours routing to sq6wmgv2zcsrix6t.onion. | Saumitra Sapre Puzzle Archive / GitHub Repository | Confirmed |
| GCHQ launched 'Can You Crack It?' on 2 November 2011 with domain canyoucrackit.co.uk registered by TMP (UK) Limited. | Cabinet Office FOIA Returns (WhatDoTheyKnow) | Confirmed |
| Navy campaign recorded a target of 1,291 cryptology enlistments from a demographic under 0.0004 per cent of the population. | Market Research Society US Navy Project Architeuthis Case Study | Contradicted |
| NSA FOIA Case 85764 opened 19 October 2019; agency issued a Glomar response on 10 March 2020 citing Section 6 of Public Law 86-36 (50 U.S.C. 3605). | NSA FOIA Case 85764 Response Document (The Black Vault) | Confirmed |
| CIA FOIA case logs from October to December 2016 record overlapping queries referencing 'CICADA 3301', alongside related requests F-2017-00103 and F-2017-00104. | CIA FOIA Case Logs (October to December 2016) | Confirmed |
| Navy FOIA log DON-NAVY-2023-015936 filed 5 September 2023 returned 'No Records Located' for Project Architeuthis contractor emails (@lowe-ce.com). | SECNAV FY23 FOIA Log (SECNAV Reading Room) | Confirmed |
| Heilbronn Institute for Mathematical Research (HIMR) operates out of the University of Bristol as a GCHQ talent pipeline requiring GCHQ clearance. | Heilbronn Fellowships Further Particulars (University of Bristol) | Confirmed |
What We Still Do Not Know
- Who actually paid New Dream Network for that server space in January 2012. We have no commercial subpoena returns naming the cardholder for 845145127.com.
- Exactly which internal tracking URLs the NSA redacted in FOIA Case 85764. Seeing those links would confirm if the agency ran the puzzle or just monitored it.
- Why the Navy archive search (DON-NAVY-2023-015936) came up entirely empty for Project Architeuthis. We lack any internal retention policy that explains how a 2014 contractor campaign simply vanished from the servers.
- Any internal capability memos from TMP (UK) Limited pitching 4chan or hidden-message tactics to GCHQ. The public Cabinet Office records omit all pre-launch planning for 'Can You Crack It?'.
- Did a Bristol HIMR fellow ever cross paths with the civilian solvers during 2014? The public record contains zero personnel overlap.
- How fourteen physical posters landed on utility poles across five countries simultaneously. The pack is completely empty of CCTV grabs, courier receipts, or flight logs.

Comments (0)