← All news

Why numbers stations are unbreakable, and what that costs

2026-04-15 · EA5IYR

Every few months someone announces they are going to crack a numbers station. They never do, and it is worth understanding why not — because the reason is not that the encryption is clever. It is that it is perfect, in a specific and provable sense. The whole trick

Take your message as digits. Take a key of random digits, the same length. Add them together digit by digit without carrying. Read the result aloud.

The recipient has the same key, subtracts it, and gets the message back.

That is it. There is no algorithm to attack, no key schedule, no S-box, nothing with structure to exploit. Why it cannot be broken

Claude Shannon proved this in 1949. If the key is truly random, as long as the message, and never reused, then the transmitted digits carry no information at all about the plaintext.

The consequence is stranger than "very hard to break." Given the intercepted group 87807, there exists a key that decodes it to any five-digit message you like. Every possible plaintext of that length is equally consistent with what went out over the air. An attacker with unlimited compute — or a fault-tolerant quantum computer — is in exactly the same position as one with a pencil, because there is nothing to compute toward. Breaking it would require distinguishing between possibilities that are genuinely indistinguishable.

This is why the digits on 7842 kHz are as safe today as their equivalents were in 1965, and will be as safe in 2065. What it costs

Every one of those three conditions is expensive, and the third is brutal.

The key must be truly random. Not a good pseudo-random generator — actual physical randomness. Historically: dice, noise diodes, women in a basement drawing numbered tiles from a bag.

The key must be as long as everything you will ever send. There is no compression, no key expansion. A year of traffic needs a year of key.

The key must never be reused. Reuse a page and the cipher collapses immediately. This is not theoretical: the Venona project broke thousands of Soviet messages in the 1940s precisely because duplicate pad pages were issued under wartime pressure. The mathematics was never the weak point. The logistics were.

And the key has to physically reach the recipient before they need it. There is no key exchange over the air — that would defeat the entire scheme. Somebody carries it, on paper, in person.

So the modern cryptographer's verdict on one-time pads is that they are theoretically perfect and practically useless — for almost every purpose. Almost every

The exception is the situation numbers stations were built for.

You need to reach one person, in a hostile country, who cannot be seen receiving anything. You met them once, before they went. You handed them a pad then. From that moment on you need no infrastructure at their end at all: a shortwave receiver, which is legal almost everywhere and reveals nothing when used, plus a sheet of numbers and a pencil.

There is no account to compromise, no device to seize with a message history on it, no metadata trail, no server to subpoena. The recipient's entire operational footprint is a radio anyone might own.

Under those constraints, the impractical cipher is the only sensible one — and the technology that looks obsolete is the only thing that works.

That is why V32 came on air in 2026, in Persian, reading five-digit groups, using a method that would have been familiar to an operator in 1955.

---

FreqBuddy lists 314 numbers-station entries with schedules and frequencies. The V32 story is where this method is currently being used in anger.