In April 1542 a letter left Rome for the court of Charles V in Spain. On its first page the Italian stops in the middle of a line and digits begin:

Figure 1. The opening of the cipher, f. 70r. Archivio Apostolico Vaticano (AAV), Segr. Stato, Spagna 1A, photograph supplied through DECODE record 92. Detail enlarged from the photograph.
Read with the key recovered below, the first ten digits group like this:
73 4 57 4 9 03 5
d o p o · l a
Dopo la, "after the". The 9 stands for nothing: it is a null. The
difficulty is deciding where each code ends. 73 is d, but 7 3 is also
two letters, n m. Even with the key, a run of digits can be read more than
one way.
Two problems follow: finding the key without knowing where one code ends and the next begins, and then, once a key exists, telling the writer's words from a plausible guess.
The sender was Cardinal Alessandro Farnese, grandson of Paul III and, at twenty-one, head of the papal secretariat. The recipient was Giovanni Poggio, bishop of Tropea and nuncio, the Pope's ambassador, at the Emperor's court.1 The letter opens in ordinary Italian: Poggio will have heard by word of mouth from Giovanni Ricci da Montepulciano about la materia della pace, the peace between the Emperor and France, so Farnese will not repeat it. Montepulciano had returned from Spain in February with the Emperor's terms and had left Rome for Spain again in late March.2
Montepulciano's name is also on a cipher key. Aloys Meister's 1906 study of papal cryptography prints, among the old ciphers of the papal secretariat, a key headed Cifra ultima con Mons. Poggio mandata per il Montepulciano: the latest cipher with Poggio, sent by Montepulciano. Meister dates it 1538–42.3
The letter fills eight pages on four leaves, 70r to 73v in the archive's numbering: r for the front of a leaf, v for the back. Page 70r is cleartext for most of its length. Then the digits take over in the middle of a line and fill the whole of pages 70v to 72r. On 72v they surround a cleartext passage about church business and news from Ancona, "fresh and from a good source". The cipher ends on 73r, and the rest of that page is clear. Page 73v is clear and dated Da Roma alli X[?] di Aprile 1542: the day is a Roman numeral beginning with X whose remaining strokes lie under a flourish, still unread. What is in clear is the frame; the instructions are in cipher.4

Figure 2. Ff. 70r and 70v. AAV, Segr. Stato, Spagna 1A, through DECODE record 92, public previews. The change from prose to digits comes near the foot of 70r. The cipher continues across the next page.
Ludwig Cardauns cited this volume in his 1912 collection of the nuncios' reports, but his selected correspondence does not include this letter.5 In July 2019 George Lasry set the text as Part 5 of the Vatican Challenge on MysteryTwister, a site of cipher puzzles: key unknown, plaintext unknown, language probably Italian. In their study, published online in 2020, Lasry, Beáta Megyesi, and Nils Kopal still listed the Spagna 1A material as unsolved. Their digit-frequency analysis placed it in a separate cluster. They compared another part of the collection, IA-1, with Meister's Poggio key, without success, and thought this letter, IA-2, used a different key.6 On 16 September 2026, the challenge page still displayed zero solves.7
The search began with a public transcription, now distributed with the
DECODE record and the challenge. Its header credits EHum, dates the
transcription 9 January 2016, and records about six and a half hours' work
on the eight pages. The transcription contains 6,577 cipher digit positions:
44 recorded as ?, unreadable, and 207 with a mark above them, mostly dots.
There is no consistent word division. The full ciphertext
is reproduced as text, with its page and line breaks. The counts and searches
below used this public transcription. I checked it against the larger
photographs later.8
In the public transcription, digit 7 makes up 17.5 percent of the text and
1 only 3.1. A few pairs are far more common than chance: 80 occurs 349
times, 57 317, 27 263, 03 258, 73 220. Doubled digits are nearly
absent: 00 six times, where independent digits would give about 117; 11
three times; 44 twice. And the digits alternate between two groups,
4 5 6 8 and 0 1 2 7 9, with 3 belonging to neither: after 73, for
instance, the next digit is 6, 8, 4 or 5 in 93 percent of cases.9

Figure 3. How often each digit follows each other digit in the public transcription. The five pairs in bold turned out to be the codes for t, p, c, l, and d. The pale diagonal is the avoidance of doubles. Author's computation from EHum's 2016 transcription.
That looks like consonants and vowels taking turns. But it does not decide
whether 73 is one code or two frequent neighbors, and no fixed rule of
cutting, such as pairs at even positions or certain digits always beginning
a pair, gave a consistent result.
The papal ciphers of the 1540s used several designs. In some, one digit stands for several letters and the reader chooses. In some, pairs spell syllables. One 1545 key writes the vowels as pairs and the consonants as single digits.10 I tried these designs with earlier versions of the search, without obtaining readable Italian.11 The design that fitted was a simple one also printed in Meister's collection: every letter has one code, of one or two digits, and the reader tells them apart by context.

Figure 4. A key of that design: Meister no. 7, for Alessandro Vitelli, dated by Meister to 1546. Single digits for some letters, pairs for the rest, one null, a few words. Aloys Meister, Die Geheimschrift (1906), p. 179; Getty Research Institute copy, digitized by Internet Archive. Cropped from the printed edition.
I searched for the key and the code boundaries together. An outer search changed the assignments of letters to codes. For each candidate key, an inner decoder searched for a good way to divide the digits and read them. The outer search could then compare keys by how well their readings scored.12
To judge those readings, I trained a character model that estimates the probability of each letter from the four before it: a five-gram model. It trained on about 4.9 million letters. Most came from Machiavelli, Castiglione, and Vasari on Wikisource. About 720,000 came from Italian-looking lines extracted from the OCR of Cardauns's Nuntiaturberichte aus Deutschland I.7, which includes correspondence of the Farnese secretariat from 1541–44. That volume does not print this letter.13 I lower-cased the text, stripped accents, folded v into u, deleted h, and collapsed doubled letters. These were guesses about the clerk's habits, and they turned out to match: the letter writes tute, esendo, facia; its key has one code for u and v and none for h.
A letter sequence absent from the corpus still needed a chance. The model blended the counts for a four-letter context with estimates from shorter contexts, down to individual letter frequencies. This smoothing let it score unfamiliar names and damaged words without ruling them out altogether.14
The decoder walks the digits from left to right. Under the key eventually recovered, the opening has these two possible paths, among others:
Digits 7 3 4 5 7 4
One path 73 4 57 4 d o p o
Another 7 3 4 57 4 n m o p o
The first path consumes 73 at once and emits d; the second consumes 7
and 3 separately and emits n m. Each emitted letter adds its base-10 log
probability to the path's score. The letters that follow can favor one path
over the other, so the decoder keeps several partial readings alive.
Each partial reading is a state, which records the position in the digits, the last four emitted symbols, and the score so far. If two paths reach the same position with the same language-model context, their possible continuations are identical: only the better-scoring path needs to survive. Among different contexts, the decoder keeps the eight best at each position. This is a beam search. It is an approximation: a path discarded early cannot recover when later letters would have made it convincing.
In the successful searches, I set aside the digits with a dot or comma above them and cut the text at those places and at unreadable digits. Each fragment began with a fresh language-model context. The key received the sum of its best surviving fragment scores, including penalties for nulls and digits it could not decode. The dotted codes would come back once the letters were known.15
The outer search began with random assignments, favoring codes that occurred more often. It could swap two assignments, move one to an unused code, or turn off an optional unit such as a null. It accepted any improvement. It could also accept a worse key, with a chance that fell as the run went on. This is simulated annealing. Accepting worse moves lets the search escape a key that beats its immediate neighbors but is still wrong. I repeated the search from fresh random keys. Each repetition is a restart.16
The first search to produce recognizable Italian gave this opening, with underscores marking the null:
dopo_lapartitadelmontepinmcian_il_manon
Dopo la partita del Montepulciano, "after Montepulciano's departure". The cleartext on the same page mentions his departure. Further along were prepararsi contra … del turco, cento naui, ungaria, ridolfo gonzaga, forteza di luzara, mons. di granuela.
Much of the rest was still garbage. This search had been allowed a pool of optional word codes, and it used them to explain away inconvenient digits. Searches that were allowed several nulls declared three frequent digits meaningless. Allowing two codes per letter also gave high scores for worse text. Yet four of the first search's six restarts had given the same codes to the same eighteen letters, the whole alphabet the clerk used. The letter assignments were stable even while the extra codes spoiled the reading.17
I tightened the search to one code per letter, at most one null, and no
word codes. I also retrained the Italian model with word spaces removed.
A model trained on del quale expects a boundary after the l, but the
decoder presents it with delquale. The unspaced model learns the letter
sequences across those boundaries. With these changes, the search reached
the same letter key from two of three restarts. The third stopped at a worse
key.
Table 1. Settings for the tightened search.15
| Setting in the tightened search | Value |
|---|---|
| Candidate codes | Single digits and pairs occurring at least three times in the scored fragments |
| Breaks in the input | 203 above-dot/comma tokens and 44 unreadable tokens; one belongs to both groups |
| Input after those cuts | 219 scored fragments; 6,331 retained digits18 |
| Beam width | Eight states per digit position |
| Proposal attempts per restart | 500,000 |
| Penalty per null | 1; emits no letter and preserves context |
| Penalty per undecodable digit | 4, when neither the single digit nor the available pair has a code |
The penalties discourage a key from improving its score by leaving text unread. Scores below divide the penalized total by the retained-digit count. Nearer zero is better. They rank the keys found under these settings, rather than measuring the probability that a reading is correct.

Figure 5. The recovered key. The single digits 4, 5, 6, and 8 are the vowels o, a, i, and e that the pairs table showed taking turns with the rest. Author's reconstruction.
Could the same key be recovered without the opening name? I split the text after its third cipher page and solved each half on its own, from random assignments. Every restart recovered the same eighteen letters and the null.
I also enciphered known Italian with two invented keys of the same design: one synthetic cipher was clean; the other had digits substituted or marked unreadable. Finally, I shuffled the real ciphertext and searched that. These controls used the tightened search settings.
Table 2. Recovery and control runs.19
| Input | Result | Score per retained digit |
|---|---|---|
| Whole letter | Same eighteen letters and null in two of three restarts | −0.783; third restart −1.150 |
| First and second halves, solved separately | Same letters and null in all twelve restarts, six per half | −0.777 / −0.785 |
| Clean synthetic cipher | Letters and null recovered in all three restarts | −0.630 |
| Synthetic cipher with digit substitutions and 44 digits marked unreadable | Letters and null recovered in all three restarts | −0.692 |
| Shuffled real ciphertext | Best of two restarts | −1.351 |
The synthetic tests did not recover the word code for et, which the letter-only search could not express. Their Italian also later proved to overlap in part with the model's training text. All the controls share the Italian model and its habits, so the check I trust most is the split: either half of the letter alone yields the letter key and null.
Lasry and his coauthors reported that, in their project, variable-length homophonic keys (those allowing several codes for a letter) had required matching plaintext or an already documented key. The simpler, monoalphabetic key used here came out of the digits.20
With the letters fixed, the decoded text around repeated dotted pairs
revealed their meanings. A 27 with the dot on its second digit, the 7,
sat where Marchese has its che, and wherever the sense wanted che,
"that". A 72 dotted on its second digit too sat where carichi,
"burdens", has its chi; a 57, dotted the same way, where non si vede,
"one does not see", has its non. With the dot on the first digit instead,
the same pairs gave qua, que and qui.

Figure 6. The dot on the first digit gives qua, que, qui; on the second, che, chi, non. Three more dotted pairs are titles: Sua Santità, Sua Maestà, Vostra Signoria, written here as the cleartext abbreviates them. Author's reconstruction.
The search alphabet had also included q, which the cipher does not need
as a separate letter. In the tightened full-text run it occupied 81.
The decoded contexts gave that code the reading et, "and". The null 9
is not a consistent word divider. It ends some words and not others, appears
inside words (tu·te for tutte, the dot marking the null), and is used in
con, written 27 4 9 7. It can prevent misreadings: 8 9 0 reads
e s, where 80 would be read as t.21
Recovering the key does not settle the text. The sequence 0 5 7 8 0 5
occurs four times in the letter. Under the key it has two Italian readings.

Figure 7. The digits 0 5 7 8 0 5 under the key: santa or spesa. Author's diagram.
My first reading, in three of the four places, was la santa [impresa], the holy enterprise, with a word supplied. The surrounding argument calls for la spesa, the expense, every time: the Pope will contribute what he can to the expense; the ships may not be ready in the year the expense is for; he will pay his share of the expense against the Turk.22
Some passages suggested errors in the digits themselves. In Montepulciano's
name, the transcription gave 2, which the key reads as r, where the name
needed u. I wrote a second decoder to compare literal readings with readings
that required small changes to the transcription. The key, now including the
dotted codes, stayed fixed.
The key search had cut the text at unreadable and dotted digits. This decoder
worked through the cipher on each page, keeping the language context across
unreadable places. It preserved the transcriber's qualifications:
2? meant a doubtful 2, 1/2 offered two readings, and ? meant an
unreadable digit. Dots, commas, and dashes above the digits were retained too.
At each position, the program compared the next digit or pair with the codes in the fixed key. An exact match cost nothing. Where nothing matched, it could propose a different digit or a changed above-mark. It could also drop a digit, supply the missing half of a pair, or insert a single-digit letter code. I assigned different costs to these operations so that filling a known hole was easier than contradicting a digit the transcriber had read without qualification.
Table 3. Edit costs in the fixed-key decoder.23
| Proposed operation | Cost in base-10 log units |
|---|---|
| Keep the digit, or the first offered alternative | 0 |
Fill an unreadable ? |
0.3 |
| Choose the second offered alternative | 0.5 |
| Substitute a listed look-alike for a digit marked uncertain | 1 |
| Substitute a listed look-alike for a digit not marked uncertain | 3 |
| Substitute a digit outside the list | 6 |
| Supply or ignore an above-dot | 3 |
| Ignore an above-comma / above-dash | 2 / 1 |
| Insert or drop a digit | 5 |
The look-alike list included such confusions as 1 with 2, 3 with 5
or 7, and 0 with 8 or 9. These were hand-set costs, not measured
error probabilities.
The score combined the two kinds of evidence:
reading score = sum of letter log probabilities − sum of edit costs
Code divisions and edits were searched together. A changed digit might join the next one into a pair, changing both the number of letters emitted and the context for the letters after them. As before, the decoder kept several partial readings alive and recorded the choices behind each one.
At the disputed digit in Montepulciano, keeping 2 emits r without an
edit cost. Choosing 1 emits u but subtracts three from the score. That
choice also changes the model's predictions for the following letters, until
the changed letter has passed out of its four-letter context. The gain in
the Italian score was enough for u to win. The edit list records:
Source Change Letter Context
2 2>1 u elmontep [u] lcian il
This repairs the middle of the name, but its final o is still absent.
Another proposal supplied the dot that turns 72, b, into 7̇2, que.
The result reads in quele di Ungaria, "in those [affairs] of Hungary", in
place of in ble di Ungaria.
The same scoring rule could damage a passage that already read correctly.
On 71r it proposed reading an 8 as the null 9 and regrouping the nearby
digits, turning a le sue sei galere, "his own six galleys", into
al tuti galere. I refused that change. The model judged short letter
sequences. It did not know how many ships the Pope had or follow the
argument about paying for them. A gain large enough to pay for an edit
could still produce the wrong reading.
The edit list tied each proposal to its source digits and surrounding text. I could accept or reject a reading and locate the disputed digits in the photographs.
Table 4. Changes proposed by the decoder.23
| Type of proposed change | Value |
|---|---|
| Fills of unreadable digits | 44 |
| Other proposed operations, including choices of an offered alternative | 126 |
| Other operations divided by the public transcription's digit count | 1.9% |
The totals include rejected proposals. Whether an apparent error belonged to the transcriber, the clerk, or the reader still required checking against the page.
The edited text, the edition from here on, uses square brackets for conjectural letters. A digit-by-digit alignment behind it records what brackets cannot show: ignored dots, dropped digits, digits read as the null. The alignment makes departures visible; it does not make the readings true.24
To test the conjectures, I gave the key to two readers, each a fresh run of the GPT-6 Astra language model, together with the digits of one page decoded literally under it: 72r for one and 71v for the other, the two pages with the most departures. Each was asked for a continuous reading and an account of every place where it left the literal decode. Each recovered its page's argument and many of the edition's words, and each caught something the edition had wrong.
On 72r the edition had left a gap and supplied [che potrà] on no digits
at all. The reader found that the twenty digits behind that gap read verà
la magior piena exactly, "the greater flood will come". With the lost verb
recovered, the supplement was unnecessary. On 71v the edition had the Emperor
knowing that the Pope's forces are small in themselves, S.M.tà s[a] che,
at the cost of one 2 read as 5 and two digits read as nulls. The
reader's o[l]tre che, "besides the fact that", needs one ignored dot and
one missing digit, and fits a sentence that goes on to say the forces are
also divided. Both were adopted. The readers were independent of the
edition, not of the key or the transcription. Like the edition, they had
never seen the page.25
I checked the disputed readings against photographs of the manuscript.
In Montepulciano's name, the decoder wanted a u where the transcription
gave 2, the code for r. On the page, the disputed digit is a single
stroke with a foot: the clerk's 1, which gives u.

Transcription 57 2 03 27
Page 57 1 03 27
Reading p u l c
Figure 8. F. 70r, second cipher line. AAV, Segr. Stato, Spagna 1A, through DECODE record 92; enlarged detail. The name was already a plausible correction from the Italian. The photograph shows why the digit was misread.
The clerk often joins one digit to the next. The top bar of a 7 runs into
the preceding digit. The foot of a 1 can make it look like a 2. In a small
pilot, I showed four short strips to three vision models. They made roughly
12–18 percent digit errors, often on those same confusions. That pilot was
too small, and its scoring too different, to establish a character-error-rate
comparison with the public transcription.26
I needed a way to compare a doubtful digit with the clerk's other examples.
I wrote a program that first straightened each cipher line and removed the
handwriting's slant. It looked for cuts in the white gaps and the thin joins
between digits, then fitted the transcription to those cuts. Each transcribed
digit became a provisional label on a small image. A 2 in the transcription
meant "this image is an example of a 2", even where that label would later
prove wrong.
A seven-neighbor classifier compared each image with examples from other lines. It used their shapes and proportions to find the seven closest matches, then combined their labels to propose a digit. Leaving out the current line kept a digit from being compared with itself or a neighboring piece of the same joined stroke.

Figure 9. The glyph transcribed as 2 in Montepulciano, followed by its seven nearest
matches from other lines. These are the straightened, normalized images used
for comparison. The labels come from the public transcription. Author's
analysis of AAV, Segr. Stato, Spagna 1A, ff. 70r–73r, photographs supplied
through DECODE record 92.
The classifier agreed with the transcription on 90.5 percent of the glyphs, and on 98.9 percent of the roughly two-thirds of glyphs it read most confidently. Those figures measure agreement with the old labels. To find transcription errors, I needed the disagreements.27
For each suspect, a review sheet put the digit in its line of handwriting,
beside the seven matches and a reference sheet of the clerk's forms from
0 to 9. I checked the ink and recorded the reading, the reason, and how
certain it was. I examined all 196 ranked suspects this way, together with
every line where the segmentation had found a different number of digits
than the transcription. Where the classifier doubted a
digit the edition had left alone, my reading mostly sided with the
transcriber: a smear could flatten a 3 into the shape of a 5, or the
next digit's stroke could give a 7 the base of a 2.28
Some errors were in the number of digits. On 71v the transcription repeated the five digits that read anco, "also". The photograph has them once.

Transcription 5 7 2 7 4 5 7 2 7 4
Page 5 7 2 7 4
Reading a n c o
Figure 10. F. 71v, fourth cipher line. AAV, Segr. Stato, Spagna 1A, through DECODE record 92; enlarged detail. The edition had already dropped the second anco as a repetition by the clerk. The repetition was in the transcription.
The check found five such doubled groups, totaling twenty-one digits not on the page, as well as fourteen omitted digits and two swapped pairs. Some of the extra digits had supplied words for the edition: sendosi [c]osì firmat[o] became sendosi firmat[o], "having been agreed", with no così, "thus".29
On 70v, a dot and two hooked 1s closed a gap in the account of the naval
expenses. The transcription had missed the dot over the 7 and read both
1s as 2s.

Transcription 27 2 6 9 2 5
Page 27̇ 1 6 9 1 5
Reading che u i · u a
Figure 11. F. 70v, third cipher line. AAV, Segr. Stato, Spagna 1A,
through DECODE record 92; enlarged detail. With 1 standing for both u and v, this reads
che vi va: the full phrase is della spesa che vi va dentro, "of the
expense that goes into it". The dot in the reading row marks the null 9.
Other corrections confirmed letters the edition had supplied. In è s[t]ato
on 70r and aiu[t]o on 72r the transcription has 0 8 where the page has
80, the code for t. The s of stato still has no digit behind it: the
page has the null 9 there, so the edition now reads è [s]tato. Other
bracketed letters, ris[p]osta and sol[d]o among them, stand on the page
as the edition read them. Some letters the edition had supplied turn out to
be on the page: the n of Massimi[li]a[no] is a 7 the transcription
read as 9; the c of ues[c]ou[o], vescovo, bishop, is a 2 the
transcription skipped, completing 27; the i of Dor[ia] is a 6
dropped at a line end.
On 72r the edition had conte[n]ti with a supplied n. The page has a 7
where the transcription has 4, and contenti is exact. On 70v the
conjecture [ca]pitarà il bisogno is withdrawn: the transcription's 8 is a
1, and the edition now reads [d]'ovunche più sarà il bisogno, "wherever the
need will be greater". The initial d remains conjectural. Other checks went
the other way. On 73r the edition had [ne]l qual luogo by changing a 6,
but the 6 is plain and the text reads il qual luogo. On 70r the 2 the
edition read as 3 for contra [l]'armata has the clerk's usual 2 form:
if l was meant, the clerk miswrote it.
One correction changed who had asked for a public announcement. Under the archive stamp on 72r, the corrected digits give la S.M.tà [h]a voluto, "His Majesty has wished", where the edition had read S.S.tà, His Holiness. The Emperor had asked for the Hungarian subsidy to be offered publicly at Speyer, in the Pope's name.
The castle's name remains conjectural. Where the edition had supplied [Poviglio] from the Gonzaga genealogy, the corrected digits give a pore in · pui ·, with the dots here marking nulls. The edition now reads a porre in P[o]ui[glio], "to settle in Poviglio". The missing letters still come from the proposed historical identification.30
I also checked the dots wherever the edition added or ignored one. In
risposta, the mark transcribed above a 7 was the top bar of the 5
before it. Other apparent dots belonged to strokes from the line above. In
Marchese, the dot was real but on the wrong digit of the pair: the clerk
had written qua where the name needs che.29
The corrections judged sure or probable went into a new transcription. Unresolved readings stayed open. I then aligned the edition against those corrected digits.31
Table 5. Source digits consumed by the edition's alignment. Both the transcription and the edited reading changed after the page check.32
| How the edition reads the digits | Before the page check | After |
|---|---|---|
| Digits in the transcription | 6,577 | 6,562 |
| Read exactly under the key, including nulls | 6,216 | 6,358 |
| Read with a recorded departure | 300 | 170 |
| Left in gaps | 61 | 34 |
Blots, the archive stamp, and smears along the page edges leave some digits and dots unread. I have not checked every glyph the classifier accepted, and substitutions between unlike digits still need another look. The day of the month also remains unread.
A contemporary copy in clear could help with the remaining readings. The Archivio Apostolico Vaticano searched the index to a register cited by Cardauns, but found no entry for an April 1542 letter from Farnese to Poggio.33
The summary below follows the proposed decipherment. Its quotations translate the edited Italian. Gaps and conjectures remain in the edition.
After Montepulciano's departure, the imperial ambassador in Rome, the Marqués de Aguilar, has been with the Pope and brought him Andrea Doria's advice on arming against the Turkish fleet, and a request for help.34
The Pope will hold back nothing within his means, at sea or in Hungary, wherever the need turns out to be greater. But nobody yet knows whether the greater danger will come by land or by sea, and he will not decide where to spend, "so as not to fall into the error of spending in vain in one place that needed it less, and then be unable to help the other." He leaves that to the Emperor's prudence.35
He has two doubts about the plan to arm a hundred ships. He argues that a mixed fleet of galleys and sailing ships has never done well. And a hundred ships would take so long to fit out that they would hardly serve this year, the year the money is for. He will pay his share anyway, beyond his own six galleys.36
The soldiers on his ships must be his own. The Papal State is full of good soldiers used to going to war. Unless he keeps them employed, no edict in the world will stop them taking pay from whoever offers it, to the disturbance of his own state and no advantage to the Emperor. He means, too, to stay neutral so that he can broker the peace, and to give nobody grounds to say he pays for anything but defense against the Turk.37
Then there are the other commitments. The Hungarian subsidy, which Charles V asked for at Lucca, was settled in Rome with the imperial minister Granvelle. At the Emperor's request, the bishop of Modena, Giovanni Morone, has now offered it publicly, in the Pope's name, at the Diet of Speyer, the assembly of the German estates then in session. The enclosed extract from Modena's letter shows that those at the Diet are not content and ask for much more. Ancona, Civitavecchia, the other ports, and the guard of Lombardy also need money. The Pope cannot yet say what more he will give on either side.38
Finally, Ridolfo Gonzaga, son of Gianfrancesco, is said to have taken a commission from someone whose name is still unread. He gathered infantry at Luzzara, his brother Massimiliano's castle in Mantuan territory, then moved to his own castle in the territory of Parma and began to fortify it, either because the Marchese del Vasto, the governor of Milan, was preparing to remove him by force or for some design of his own. Whether this is mere rashness on Ridolfo's part or something larger is not yet clear. The Pope's legate has orders to stop him, by force if necessary, and troops have moved into Parma. Vederassi il successo: we shall see how it goes.39
Morone's surviving reports independently confirm a public presentation of papal aid at Speyer on 23 March and complaints that the offer was too small. They corroborate the decipherment's account, although the particular enclosed extract has not been identified.40 The Pope and the Emperor had met at Lucca in September 1541, two weeks after the Turks took Buda.41
The Gonzaga genealogy also fits. Gianfrancesco's sons included Massimiliano, who held Luzzara, and Rodolfo, spelled Ridolfo in the letter, associated with Poviglio in the Parma territory. A published archival inventory describes a 1546 letter to Rodolfo as "signore di Poviglio". That supports the proposed castle name without supplying its missing letters.30
The peace Montepulciano was carrying did not come. Francis I declared war on Charles V in July 1542. By the end of that month Montepulciano was back in Italy. On 30 July the nuncio Girolamo Verallo reported Ferdinand's statement that la pratica della pace era exclusa: the negotiation for peace was finished.42
This is a candidate reading. The key is stable: either half of the letter alone yields the same letters and null. The page check examined the disputed readings and the classifier's suspects, not every glyph.
No other cryptanalyst has yet verified or challenged the solution. On 15 September I sent the key and plaintext to MysteryTwister, whose team checks Level X solutions by hand.7
The notes identify the evidence for individual claims, including the article's own computations and proposed readings. References to printed books use their printed page numbers; manuscript references use folios. Cipher-line numbers count only lines containing cipher. English translations follow the cited Italian passages. The edition supplies word division, punctuation, and some spelling; its brackets and alignment record uncertain readings. Online catalog and challenge statuses were checked on 16 September 2026.
ASV/i1025/SdS/Spain/IA/2. Older references use ASV,
Archivio Segreto Vaticano. The April date is the reading of this letter's
dateline, rather than the wider date range assigned to the archival bundle.ASV_i1025_SdS_Spain_IA-2, 9 January 2016.
Public original;
complete transcription, including the transcriber's header;
ciphertext appendix and notation. This is the input to
the key search. The
manuscript-corrected transcription
is a later research product, used for the edition's final alignment.Individual entries in the Dizionario Biografico degli Italiani are cited by their named authors, volumes, years, and online entry titles in the notes. Their online text does not supply printed page breaks. Methodological references and the signed institutional history of Buda are likewise given in full at the relevant notes.
The edition appendices contain the key tables, machine-readable key, edited Italian text, and digit-by-digit alignment. The automatic reading preserves the decoder's proposals, including those rejected in the edition. The transcription appendix includes the public and corrected texts and the individual manuscript decisions. The results supplement reports the search and control results, model details, and independent rereadings. The earlier alignment supplies the before-check figures in table 5. These are the article's research outputs, not an independently transmitted plaintext.
The figure source register records source images, folios, crop coordinates, transformations, and figure data. The public previews and the full-resolution manuscript photographs are different files; the latter were supplied through DECODE with restricted access and are not reproduced in full here. The reproduced details and processed glyphs are identified individually in the register.