Skip to content

Cicada 3301 – Server Infrastructure and Missing State Paperwork

Cicada 3301 required global physical deployment yet ran on a cheap, shared server. Archival records reveal a total vacuum of public funding, contractor, or registration paperwork compared to official state campaigns.

The Cicada 3301 logo, a stylised white line drawing of a cicada insect on a black background.

Here is the problem. The physical scale of the puzzle spanned the globe, but the digital paperwork points to a shoestring budget. The server hosting that entire operation sat on a cheap, shared commercial block alongside ordinary civilian blogs. We are looking at a total disconnect between the boots on the ground and the server bill.

Glossary

Term Definition
Glomar response A formal answer where a government agency refuses to confirm or deny that any records on a topic exist. Named after a CIA-linked ship called the Glomar Explorer.
FOIA (Freedom of Information Act) The US law that lets members of the public ask federal agencies for copies of their records, subject to a list of exemptions.
.onion address A web address that only loads through anonymising software called Tor. The server's real location is concealed.

Tracing the Budget Lease

On 3 January 2012, someone generated an RSA 4096-bit public key. RSA is the standard for digital signatures that prove a message came from the holder of a specific cryptographic key, and 4096 bits is large enough to be effectively impossible to forge with current computing power. The full fingerprint runs 6D854CD7933322A601C3286D181F01E57A35090F. From that day onward, every authentic Cicada 3301 message carried that exact signature. Anything else was treated as a copycat by the solver community, and discarded.

That key sat behind a domain called 845145127.com.

Run the domain through a routing lookup. It points at the IPv4 address 75.119.203.244. The address falls inside an ASN, an identifier assigned to organisations that run their own slice of the internet. This one is AS26347, registered to New Dream Network, LLC, trading as DreamHost. DreamHost is a low-cost shared host. Anyone with a credit card can rent space on it.

Look at the rest of that server block. Civilian domains. Ordinary blogs and small commercial sites, hosted shoulder to shoulder with the server that ran a four-year international cryptography puzzle.

And then the operators changed the routing. They flipped the DNS A record on 845145127.com to 127.0.0.1, the loopback address. That is the digital equivalent of redirecting all post to your own front door. After the flip, solvers could only reach the puzzle by typing the bare IP straight into a browser. We have no commercial subpoena return naming the account holder who paid for that lease.

The Cryptographic Identity vs. The Infrastructure Footprint

Cryptographic Scaffold

Key Generation Date

3 January 2012

Signature Format

RSA 4096-bit (Fingerprint: 6D854CD7933322A601C3286D181F01E57A35090F)

Server Footprint

Hosting Provider

DreamHost (AS26347) — Low-cost shared block

Routing Behaviour

Domain 845145127.com flipped DNS A record to loopback address 127.0.0.1

The Physical Footprint Disconnect

Then the countdown ran out. On 9 January 2012 at 17:00 UTC, the timer on 845145127.com hit zero. The page dumped a raw list of fourteen GPS coordinates.

Map them out. The points land in Warsaw, Paris, Seattle, Seoul, Miami, New Orleans, Sydney and Hawaii.

The physical deployment happened almost immediately. Somebody had to walk up to utility poles across five countries to tape up paper posters. Each poster carried a cicada logo and a QR code. Scanned by a phone, the code routed visitors to sq6wmgv2zcsrix6t.onion, an address that only loads through anonymising software designed to hide where the real server sits.

Now hold those two facts together. A poster taped to a utility pole in Hawaii. One server on the open internet whose physical location is deliberately concealed. The puzzle had a physical foot in eight cities at once, and a digital head that nobody could trace.

And the host of that head was DreamHost on a shared block.

Compare the shape of this against the closest official equivalent. When GCHQ launched its ‘Can You Crack It?’ recruitment campaign on 2 November 2011, the domain canyoucrackit.co.uk had been formally registered by an advertising agency, TMP (UK) Limited, months ahead of the launch. There is a paper trail. We expect to see a corporate registrant. We look for an agency of record and a signed contract. Cicada has none of that. We see no registrant and no contractor. There is no public award submission. Just a DreamHost lease whose buyer is not named in any document we have seen.

Support the Archive

Help fund the retrieval, hosting, and preservation of Veriarch investigations.

DONATE >

What State Recruitment Paperwork Actually Looks Like

Here is what state cryptographic recruitment looks like on the public record. There is paperwork. Lots of it.

GCHQ ran ‘Can You Crack It?’ from 2 November 2011. The domain canyoucrackit.co.uk had been formally registered by an advertising agency, TMP (UK) Limited, months ahead of the launch. Cabinet Office FOIA returns and trade-press coverage tie the campaign back to that agency contract.

Two years later, GCHQ ran a sequel. ‘Can You Find It?’ went live on 12 September 2013, on the same pattern. It had a registered domain, a named contractor, and a launch date.

Then comes the US Navy’s ‘Project Architeuthis’, launched on 28 April 2014. Lowe Campbell Ewald served as the agency of record on the work, a federal advertising contractor. The campaign hit benchmarks specific enough that the Market Research Society published a detailed case study on it. That study sets out the precise enlistment target. They were after 1,291 cryptology recruits, drawn from a demographic representing less than one quarter of one per cent of the country’s population.

We read through that entire case study. It tracks the marketing analytics. You can see the demographic targeting maps. They even laid out the media spend breakdowns and the full campaign timelines.

Project Architeuthis won awards too. They submitted a Shorty Awards entry. Communication Arts ran a feature on it. The entire marketing afterlife is archived online. Now line Cicada 3301 up next to that. We see zero registrar records. Nobody signed a contractor agreement. There is no public budget. We have no award submissions.

Four years of cryptographic puzzles ran on this scaffolding. Eight cities saw the physical postering. A cryptographic key was generated to the second. Nothing on the public record names who paid the bill.

Public Accountability: State Campaigns vs. Cicada 3301

Campaign Registrar / Contractor Public Records & Analytics
GCHQ 'Can You Crack It?' (2011) Domain registered by TMP (UK) Limited Cabinet Office FOIA returns, trade-press coverage
US Navy 'Project Architeuthis' (2014) Lowe Campbell Ewald Market Research Society case study, Shorty Awards entry, demographic targets
Cicada 3301 (2012–2016) None (Unnamed buyer on a DreamHost shared lease) No public budget, no registrar records, no award submissions, no visible contractor

The NSA Will Not Confirm or Deny

A public requester filed NSA Freedom of Information Act Case 85764 on 19 October 2019, asking the agency to release any records it held on Cicada 3301.

On 10 March 2020, the NSA returned a Glomar response. A Glomar is the formal refusal to confirm or deny that any records exist, named after a CIA-linked salvage ship from the 1970s. NSA cited Section 6 of Public Law 86-36, codified at 50 U.S.C. 3605.

What the agency did release ran to four pages. Inside those four pages, internal URLs and the names of NSA employees had been redacted under the same statute. The pages themselves are stamped and dated. We can see the shape of the file without seeing its contents.

Our reading of the Glomar is this. Confirming or denying any record would let an outside observer map out which open-internet services the agency tracks closely enough to keep files on. That is our analysis, not a statement the NSA made. NSA’s public response only cites the statute.

A parallel paper trail sits at the CIA. Look at the FOIA case logs for October to December 2016. You will see overlapping queries that reference ‘CICADA 3301’.

We even have the related request numbers:: F-2017-00103 and F-2017-00104. But here is the problem. Their disposition pages are entirely missing from the released log.

FOIA Case 85764: Glomar Response

  • The NSA refuses to confirm or deny that any records on Cicada 3301 exist.
  • Statute cited: Section 6 of Public Law 86-36, codified at 50 U.S.C. 3605.
  • Four pages released: Internal URLs and NSA employee names redacted under the same statute.

The Navy Cannot Find Its Own Emails

Now circle back to Project Architeuthis. We checked the Navy FOIA logs for 5 September 2023.

Somebody filed a request under log number DON-NAVY-2023-015936. They were asking for internal emails about the project. Specifically, they wanted anything sent to or from the contractor address @lowe-ce.com.

Navy response came back: ‘No Records Located’.

That is the disposition the SECNAV FY23 FOIA log shows. We are looking at a search that returned no records for an award-winning 2014 recruitment campaign. This is a project that has its own Shorty Awards entry, its own Communication Arts feature, and its own Market Research Society case study citing a target of 1,291 cryptology recruits. The campaign exists in public industry archives. Its internal email trail at the Navy does not.

We have no Navy archive policy in the pack that explains the absence.

Navy FOIA Log Disposition: DON-NAVY-2023-015936

  • Target: Internal emails regarding Project Architeuthis and contractor @lowe-ce.com.
  • Filing Date: 5 September 2023.
  • Disposition: 'No Records Located'.
SECNAV FY23 FOIA Log (SECNAV Reading Room).

The Visible Pipeline the State Actually Funds

For contrast, look at what a visible state pipeline for cryptographic talent actually leaves on the public record. The Heilbronn Institute for Mathematical Research, HIMR, sits inside the University of Bristol.

We pulled the public Further Particulars document for their fellowship programme. It confirms that fellows must obtain GCHQ security clearance as a hard condition of the role. HIMR fellows conduct independent academic research alongside that clearance requirement. But how they actually split their time between open research and classified work is entirely absent from the public PDF.

That is the visible side of the trade.

Public funding records show a named institute, a named host university and a published fellowship programme. Financial scaffolding is documented. Cryptographic recruitment is documented. Cicada 3301 has no such scaffold on the public record.

We have a comparator that matters. A visible pipeline runs through a named institute and a named host university. No equivalent named institution sits behind Cicada 3301, only an unnamed buyer of a DreamHost lease.

State Recruitment Paperwork: Visible vs. Missing

Heilbronn Institute (HIMR)

Named UKRI funding block.

Visible host university (Bristol).

Published fellowship programme requiring GCHQ security clearance.

Cicada 3301

No registered contractor.

No public budget line or visible pipeline.

Unnamed buyer of a DreamHost lease.

Source

Sources include: the cicada-solvers GitHub repository and IPinfo.io routing returns for the 75.119.203.0/24 range; the Saumitra Sapre puzzle archive; the Market Research Society case study on the US Navy ‘Project Architeuthis’ campaign; the NSA response document for FOIA Case 85764; CIA FOIA case logs from October to December 2016; the SECNAV FY23 FOIA log; and the University of Bristol’s ‘Further Particulars’ document for the Heilbronn Fellowships.

Claim-Source Matrix

Core Finding Primary Source Document Status
An RSA 4096-bit public key (fingerprint 6D854CD7933322A601C3286D181F01E57A35090F) was generated on 3 January 2012 for domain 845145127.com, hosted on a cheap, shared DreamHost server block (75.119.203.244). cicada-solvers GitHub repository and IPinfo.io range 75.119.203.0/24 Confirmed
On 9 January 2012, a countdown timer hit zero and released fourteen GPS coordinates across eight international cities, leading to physical QR-code posters routing to a hidden Tor .onion address. Wikipedia and the Saumitra Sapre puzzle archive Confirmed
GCHQ launched the 'Can You Crack It?' recruitment campaign on 2 November 2011, using a domain registered months earlier by advertising contractor TMP (UK) Limited. Cabinet Office FOIA returns and trade-press coverage Confirmed
The US Navy launched 'Project Architeuthis' on 28 April 2014 via federal advertising contractor Lowe Campbell Ewald, targeting 1,291 cryptology recruits drawn from a specific demographic. Market Research Society US Navy case study and Ads of the World campaign listing Confirmed
The NSA returned a Glomar response on 10 March 2020 for FOIA Case 85764, citing 50 U.S.C. 3605 and releasing four pages with redacted internal URLs and employee names. NSA FOIA Case 85764 response document (The Black Vault) Confirmed
The CIA FOIA case logs for October to December 2016 record overlapping queries for 'CICADA 3301' under numbers F-2017-00103 and F-2017-00104, but their disposition pages are completely missing. CIA FOIA case logs (October to December 2016) Confirmed
A US Navy archive search under log number DON-NAVY-2023-015936 for internal campaign emails to or from contractor address @lowe-ce.com returned a 'No Records Located' disposition. SECNAV FY23 FOIA log (SECNAV Reading Room) Confirmed
The Heilbronn Institute for Mathematical Research operates a visible fellowship programme out of the University of Bristol where fellows must obtain GCHQ security clearance as a condition of the role. Heilbronn Fellowships Further Particulars (Bristol University) and UKRI funding records Confirmed

What we still do not know

Infrastructure & Records

The Server Bill

Who paid New Dream Network for the shared space behind 845145127.com in January 2012.

The FOIA Vacuum

Why US Navy archive search DON-NAVY-2023-015936 returned entirely empty for the documented Project Architeuthis campaign.

The Redactions

Which internal tracking URLs the NSA redacted in the four-page release for FOIA Case 85764.

Physical & Personnel Elements

The Physical Deployment

How fourteen posters were simultaneously deployed across five countries without leaving public CCTV grabs, courier receipts, or flight logs.

Pre-Launch Planning

Any internal capability memos from TMP (UK) Limited pitching anonymous or hidden-message tactics to GCHQ.

PRIORITY_NEWSLETTER_BRIEFINGS

Archive Updates

New Veriarch investigations and unresolved questions, sent directly to your inbox every other week.

CONNECTION SECURE. UNSUBSCRIBE AT ANY TIME.

Comments (0)

Leave a Reply

Your email address will not be published. Required fields are marked *

Back To Top