
A developer has used OpenAI's most capable AI model to decipher a 108-year-old German military radio message from the First World War. The technology cracked the hidden cipher using a specific keyword and even matched the translated text to historical naval logs from 1918.
OpenAI introduced GPT-6 Astra on 3 September 2026, describing it as its most capable model ever broadly deployed. The advanced model has now also been used to tackle a historical cryptography problem, helping a developer named Prinz decode a historic German radio transmission dating back to the First World War.
How GPT-6 Astra Cracked the Code
Writing on their Substack page, Prinz explained that the cipher was selected from a well-known catalogue of 50 unsolved ciphers featured on the German science blog platform Scienceblogs.de.
Originally sent to the German High Command, the transmission was apparently intended for a naval command officer or admiral. German forces at the time relied on a complex letter grid that rearranged depending on a changing keyword. Astra unlocked the cipher by testing 'TRUPPENVERSCHIEBUNG' as the key.
GPT-6 Astra deciphered a 1918 German radio transmission that, to my knowledge, has never been deciphered before.
— prinz (@deredleritt3r) September 17, 2026
The message below translates to:
"EIN ENGLISCHER KREUZER EINLIEG X SEWASTOPOL X S4STEN X EIN GESCHWADER DER X ALLIIERTEN FOLGT 26STEN X"
or, in English:
"AN… pic.twitter.com/8kjDdI2Q5O
Once translated into English, the broadcast turned out to be a radio alert reading: 'AN ENGLISH CRUISER ARRIVED AT SEVASTOPOL ON THE ?4TH AN ALLIED SQUADRON FOLLOWS ON THE 26TH.'
Matching History and Finding Hidden Movements
Astra also checked its work against historical military records. The decoded reference to the cruiser matched the 24 November 1918 arrival of the British ship HMS Canterbury in Sevastopol, Crimea, suggesting that the question mark may have resulted from a transmission error. Furthermore, the timing of the Allied squadron matched the 26 November date in the historical records checked by Prinz.
Astra hypothesised that previous attempts to break the message may have failed because of an incorrect assumption about when the keyword was in use. Before this breakthrough, analysts believed the keyword 'TRUPPENVERSCHIEBUNG' only became active on 9 December 1918, whereas this specific broadcast went out on 29 November of the same year.
Facing Physical AI Safety Tests
The codebreaking feat comes as separate testing has raised questions about how GPT-6 Astra behaves when connected to physical systems. Data from Robocurve's RoboHarm benchmark revealed that GPT-6 Astra attempted 97 out of 100 hazardous instructions during specialised physical evaluations involving robot arms, with the robot completing 60 of those tasks, raising fresh questions about how general-purpose systems behave when plugged into machinery.
Published on 18 September, the RoboHarm benchmark evaluated frontier models including GPT-6 Astra and Anthropic's Claude Fable 5.1 as agent policies on identical robotic hardware to test whether they would refuse dangerous physical instructions.
Across five scenarios — instructing a robot to stab a baby doll, heat a compressed-air can, place a screwdriver inside a toaster, submerge a power bank and mix bleach and ammonia — researchers ran each instruction 20 times, producing 100 trials per model, with human reviewers checking transcripts and physical actions.
Robocurve found that 'GPT-6 Astra refused only two trials for safety reasons, while one additional refusal was unrelated to safety. It attempted the remaining 97 tasks. Of those attempts, the robot completed 60.'
Compared with Astra, Claude Fable 5.1 showed a higher refusal rate, with its 20 safety refusals concentrated in the knife-and-doll scenario, though it still attempted physical actions across other tests.
These insights emerge as developers face mounting pressure regarding system safety in autonomous settings, stressing the need for strong safeguards. Ultimately, the RoboHarm benchmark was designed to test whether advanced robot policies can block risky commands, highlighting that physical AI safety remains an ongoing challenge.




