One plaintext letter does not have to produce one ciphertext sign.
That simple fact changes the Voynich cipher debate enormously.
Imagine the plaintext letter E.
A simple substitution cipher gives it one disguise.
E → 17
Every E becomes 17.
Frequency analysis can exploit that regularity.
A homophonic cipher gives E several disguises.
E → 17, 42, 63, 81
The encipherer rotates among them.
Now the most common plaintext letter no longer produces one screamingly common ciphertext sign.
Push the idea further.
Let one plaintext letter expand into several visible glyphs.
Let one source syllable have multiple legal ciphertext groups.
Allow spelling simplification before encryption.
Allow different visible options at different positions.
Now a modest, meaningful plaintext can acquire:
- many visible word forms;
- low exact phrase repetition;
- dense families of similar ciphertext tokens;
- unusual character frequencies;
- strange word-length distributions;
- statistics that no longer resemble ordinary plaintext directly.
This is why Michael Greshko’s 2025 Naibbe cipher matters.
It is not a Voynich solution.
It is something scientifically more useful than another unsupported “solution”.
It is a constructive counterexample.
Greshko designed a verbose homophonic substitution cipher that can be executed by hand with fifteenth-century-compatible materials. When applied to meaningful Latin and Italian plaintext, it remains decipherable while reproducing many statistical properties associated with Voynichese.
That result defeats one lazy argument:
“Meaningful ciphertext could not possibly look this Voynich-like.”
It could.
But that immediately creates a higher burden.
If Voynich is homophonic ciphertext, which exact multiplicity rules produce its particular structure—and can those rules decode unseen text without being redesigned?
That is the Homophony Problem.
Quick Read
Direct answer: homophonic and verbose substitution are historically plausible mechanisms capable of turning meaningful language into ciphertext with several Voynich-like statistics. The 2025 Naibbe construction demonstrates that viability but does not identify Voynich’s plaintext, key or exact mechanism. A genuine homophonic solution must recover a compact mapping whose alternatives are constrained, whose source grammar emerges, whose Currier/hand/document differences are explained, and whose predictions survive text not used to build the key.
- Homophony means one plaintext unit can be represented by several ciphertext alternatives.
- It is a classical defence against frequency analysis.
- Historical European cipher keys used homophones extensively.
- Nomenclators could combine letter substitution, homophones, codes and nulls.
- Homophony can flatten visible character frequencies without destroying meaningful plaintext.
- Verbose substitution can expand one plaintext unit into several ciphertext signs.
- The combination can create many surface variants from the same source word.
- This can suppress exact repetition and enlarge apparent vocabulary.
- Greshko’s Naibbe cipher, published in Cryptologia in 2025, is a verbose homophonic substitution system designed as a historically plausible Voynich control.
- Naibbe can be performed by hand with materials available in the fifteenth century.
- When encrypting Latin and Italian, it produces decipherable ciphertext that reproduces many Voynich-like statistics simultaneously.
- That establishes cipher-class viability, not Voynich identity.
- A mechanism can match many headline statistics and still fail newer discriminators such as boundary-level structure.
- Homophonic freedom can make false decipherments extremely easy if mappings are allowed to change by context without penalty.
- A real key must converge: later pages should require fewer new assignments, not more.
- No generally accepted homophonic Voynich key currently satisfies that standard.
Simple Substitution Is Too Weak a Cipher Baseline
Many arguments against the cipher hypothesis begin with the wrong cipher.
Take ordinary plaintext.
Replace each letter with one Voynich glyph.
Measure the output.
It does not look like Voynich.
Therefore Voynich cannot be ciphertext.
The conclusion does not follow.
Monoalphabetic substitution preserves too much of plaintext statistics.
Common letters remain common.
Word lengths remain unchanged.
Repeated plaintext words become repeated ciphertext words.
Many natural-language signatures survive transparently.
A historically competent cryptographer had reasons to make stronger systems.
Homophones are one of the oldest and most practical upgrades.
What Homophones Buy the Encipherer
Suppose plaintext E occurs twelve percent of the time.
Give E four ciphertext alternatives and use them roughly evenly.
Each visible sign now occurs around three percent instead of twelve.
The frequency spike disappears.
Do the same for other common letters.
The ciphertext distribution flattens.
This is not theoretical hindsight.
Historical cipher instructions explicitly emphasised rotating among homophones rather than repeatedly using one substitute.
The cipher operator becomes part of the security system.
Homophony Does Not Have to Live at One Character
The simplest model gives one plaintext letter several ciphertext symbols.
Voynich invites more complex possibilities.
- one plaintext letter → several possible Voynich glyphs;
- one plaintext letter → several possible glyph groups;
- one plaintext syllable → several visible token fragments;
- one common word → several dedicated code groups;
- position-dependent alternatives.
Each extra layer changes the surface statistics differently.
This is why “homophonic cipher” is not one single model.
It is a family of many-to-one mappings whose details matter.
Verbose Substitution Changes Word Length
A one-to-one substitution preserves source word length exactly.
Verbose substitution does not.
A source letter can expand into two or more visible signs.
Now the ciphertext word length depends on which plaintext letters occur and which enciphering alternatives are selected.
This makes verbose homophony directly relevant to the Voynich Word-Length Problem.
A correct mechanism should derive the observed length distribution rather than merely assert that verbose ciphers can make words longer.
Homophony Can Destroy Exact Repetition Without Destroying Meaning
Suppose the plaintext word rosa appears ten times.
If each letter has several possible ciphertext representations, the ten encrypted instances need not look identical.
This solves one old intuition problem.
Voynich repeats individual tokens but exact multiword phrases are surprisingly scarce.
Meaningful language under homophonic encoding can suppress exact repetition dramatically.
That makes phrase scarcity compatible with cipher.
It does not prove cipher.
A good homophonic model should quantitatively reproduce the observed repetition spectrum across single tokens, bigrams and longer phrases.
Homophony Can Create Apparent Word Families
If one source word can be encrypted several ways, its ciphertext variants may form a visible family.
One variant differs by one sign.
Another by a short group.
Another by an alternative ending.
Suddenly edit-distance neighbourhoods appear even though the source word did not change.
This is important because Voynich word-family structure is sometimes interpreted directly as morphology or local generation.
Homophony provides a third route.
The family may be cryptographic variation.
A real cipher model should predict which visible family members collapse to the same plaintext and why.
The 2025 Naibbe Cipher Changes the Debate
Greshko’s Naibbe work asks a deliberately constructive question.
Can a historically plausible hand cipher turn meaningful Latin or Italian into ciphertext that resembles Voynich on many statistical dimensions at once?
The answer reported in the 2025 paper is yes.
The system is verbose.
Homophonic.
Designed for hand execution with fifteenth-century-compatible materials.
Meaningful source text remains recoverable.
The resulting ciphertext reproduces many unusual properties associated with Voynichese.
This is a major methodological upgrade because it replaces:
“I can imagine a complicated cipher doing this.”
with:
“Here is an explicit cipher that actually does several of these things.”
Naibbe Is a Control, Not a Key
This distinction must remain bright.
Naibbe does not show that the historical Voynich writer used Naibbe.
It does not produce an accepted translation of MS 408.
It does not identify the author.
It does not turn every Voynich anomaly into a cipher consequence.
Its strongest public contribution is narrower:
some statistical arguments once used to dismiss ciphertext are no longer sufficient, because a constructive historically plausible cipher can reproduce them from real plaintext.
The bar has moved.
Cipher theories now need better discriminators.
A Good Control Is Valuable Because It Eventually Fails
If a synthetic cipher reproduced every known Voynich property by design, it could be an overfit imitation.
The more useful question is where it fails.
The 2026 Edge Problem is an example of this research direction.
Recent work reports a boundary-level coupling in Voynich that some strong Voynich-like controls do not reproduce even when they match older headline statistics.
That is progress.
A control model narrows the field by surviving old tests and failing a new one.
The next cipher must explain the failure too.
Homophony Creates an Identifiability Problem
Suppose four Voynich signs all represent plaintext E.
How do we discover that?
Any four signs could be proposed.
Worse, a sufficiently flexible model can let one Voynich sign represent several plaintext letters too.
Now mappings become many-to-many.
The search space explodes.
A solver can fit almost any desired plaintext if mapping multiplicity is unconstrained.
This is why the key must converge.
Each new decoded passage should reduce ambiguity.
If every page requires new alternatives, homophony has become a license rather than an explanation.
Homophony Must Preserve Source Grammar
Ciphertext can hide character frequencies.
It cannot make the source language cease to have grammar.
After decryption, recurring function words should stabilise.
Morphology should make sense.
Word order should be plausible unless a separate transposition step is independently justified.
Proper names should follow the same mappings.
Historical spelling should be period-appropriate.
A homophonic key that produces fluent English paraphrases without a stable source-language layer has not demonstrated decipherment.
Homophony Must Explain the Vowel Problem
If Voynich encodes ordinary vocalised language, vowels are frequent plaintext units.
Homophony could distribute them across several visible signs and weaken vowel/consonant clustering.
Verbose encoding could bundle them with neighbouring consonants.
This makes homophony one plausible explanation for why no clean visible vowel class has emerged.
But a concrete key should recover the vowels consistently.
The Vowel Problem becomes a validation target rather than a reason to invent more freedom.
Homophony Must Explain Currier A and B
If A and B encode the same source language under different homophone preferences, the theory gains a natural mechanism.
One key state uses alternatives set A.
Another favours alternatives set B.
That could change surface frequencies while preserving plaintext.
This is attractive.
It also predicts something powerful.
After decryption, A and B should collapse toward the same source grammar and much of the same core vocabulary unless they truly encode different languages or genres.
A homophonic Currier model is therefore directly falsifiable.
Homophony Must Explain Scribal Variation
Historical instructions often told encipherers to vary homophones rather than use one repeatedly.
Different scribes may develop different preferences among legal alternatives.
This can create a bridge between cipher behaviour and palaeographic hands.
But the direction matters.
First define legal homophones.
Then test whether proposed hands prefer different subsets.
Do not assign every scribal difference a new plaintext value after seeing it.
Labels Are a Dangerous Test for Homophony
If labels contain proper names, homophonic encoding could disguise repeated sounds heavily.
That makes crib discovery harder.
Yet labels are short enough that a mature key should eventually decode them cleanly.
A homophonic system cannot use infinite alternatives without key-management cost.
If every unique label requires unique values, the key is not converging.
Short labels are therefore a strong late-stage validation set.
The Almost-Correctionless Manuscript Tests Operator Complexity
Homophonic ciphering requires choices.
Which substitute do I use for E this time?
Which group is legal at word end?
Which key state applies?
The more choices, the more opportunities for error.
Voynich writing remains remarkably fluent and lightly corrected.
A proposed homophonic mechanism must therefore be usable enough for a trained person to execute rapidly and accurately.
This is one reason Naibbe’s hand-executable design matters as a control.
Historical plausibility includes human ergonomics.
Word Boundaries Could Be Preserved, Changed or Manufactured
A homophonic cipher can preserve plaintext spaces.
It can remove them.
It can insert separators.
Verbose groups can create internal gaps or make one source word look like several visible chunks.
This connects directly to the Edge and Spaces problems.
A mature cipher model should state exactly how source word boundaries become Voynich gaps.
If uncertain spaces are truly weak internal boundaries, the enciphering mechanism should predict them rather than treat them as transcription nuisance.
Homophony Can Mimic Morphological Productivity
Natural language creates many forms from one root.
Homophonic ciphertext can do something visually similar from the opposite direction.
One fixed plaintext word can produce many ciphertext variants.
This means visual family size alone cannot distinguish rich morphology from rich ciphertext multiplicity.
The discriminator is grammatical behaviour.
If visible variants represent the same source word, they should occupy equivalent source syntactic roles after decryption.
If they are inflected forms, their roles should differ systematically.
The same word-family graph can conceal two very different mechanisms.
The Key Cannot Grow Forever
This is the central failure mode.
First page:
twenty glyphs receive values.
Second page:
thirty more contextual alternatives are needed.
Third page:
every common sign now has five values.
Soon the “key” is simply a record of how each individual occurrence was translated.
A real homophonic key should saturate.
New pages increasingly reuse known mappings.
Unknowns decline.
Grammar resolves ambiguity.
The key should become smaller relative to the amount of text it explains.
Homophony Needs an Encryption Receipt
One of the strongest tests is reversibility.
If a decoder claims a plaintext, take that plaintext and the proposed key.
Can an independent operator regenerate valid Voynich-like ciphertext under the stated rules?
Not necessarily the identical historical choices if homophones permit alternatives.
But the generated outputs should inhabit the same structural distribution.
Encryption and decryption should be two directions of one mechanism.
A one-way interpretive mapping is weaker.
What Survives the Homophony Work
- Homophonic substitution is historically real and relevant to the Voynich period.
- It can flatten plaintext frequency signatures.
- Verbose homophony can alter word lengths and visible token structure.
- Homophony can reduce exact repetition while preserving meaningful source text.
- It can create visible families from one underlying plaintext form.
- Greshko’s 2025 Naibbe cipher is a constructive demonstration that meaningful Latin/Italian can be converted into decipherable ciphertext matching many Voynich-like statistics simultaneously.
- Naibbe establishes viability for a cipher class, not an identification of the Voynich mechanism.
- Newer discriminators such as boundary-level structure can separate Voynich from controls that pass older tests.
- A homophonic Voynich model must converge toward a stable key and source grammar.
- No accepted key currently meets that full burden.
What Does Not Survive as Established Knowledge
- Voynich is proven to be homophonic ciphertext.
- Voynich uses the Naibbe cipher.
- Matching several statistics establishes identity of mechanism.
- Every Voynich word family is one plaintext word under alternative homophones.
- Currier A/B are proven key changes.
- Every visible glyph may take unlimited plaintext values.
- A fluent translation is valid if the key never converges.
- Cipher-class plausibility is equivalent to decipherment.
The cipher class survives.
The Voynich key does not.
A Better Homophony Analysis
- Specify the plaintext unit: letter, syllable, morpheme or word.
- Specify how many ciphertext alternatives each unit may have.
- State whether mappings change by position or key state.
- Count every mapping alternative as model complexity.
- Fit mappings on one bounded corpus.
- Freeze the key.
- Decrypt unseen bifolia.
- Require source-language phonotactics, morphology and syntax.
- Explain Currier, hand and document-role variation without unlimited new mappings.
- Run encryption forward and compare generated ciphertext statistics.
- Test newer discriminators, not only classic frequency metrics.
- Report every place the fixed key fails.
What Would Count as a Real Homophony Breakthrough?
Imagine one bounded set of Voynich pages yields a compact homophonic key.
The key is frozen.
On unseen bifolia, most glyph groups receive already-known values.
Several visible Voynich word families collapse into stable source lemmas under alternative ciphertext forms.
Currier A/B differences reduce to documented shifts in homophone preference rather than new language rules.
Labels recover plausible names under the same mapping.
The source language develops period-appropriate morphology and syntax.
An independent encipherer can take new source text, use the frozen key and produce ciphertext matching Voynich not only on entropy and word length but on edge coupling, line effects and register differences.
That would be a homophonic breakthrough.
Homophony becomes a solution only when many visible disguises collapse into fewer stable source values and every new page makes the key more certain rather than more permissive.
Primary School: Many Symbols, One Letter
Choose three shapes to represent the letter E.
Every time E appears, choose one shape at random.
A repeated word no longer looks exactly repeated.
The child learns why many visible forms can hide one underlying unit.
Secondary School: Flatten the Frequency
Take a short English text and count E.
Encrypt every E using four different symbols in rotation.
Recount ciphertext frequencies.
The original high-frequency letter has disappeared into several smaller peaks.
This demonstrates the historical cryptanalytic purpose of homophony.
JC and Adult Readers: Homophony as a Many-to-One Latent Map
Formally, each observed ciphertext unit maps to a latent plaintext class, while one plaintext class may emit multiple observed units.
The central statistical problem is identifiability.
With too many emission alternatives, many plaintexts fit.
Source-language priors, key-size penalties, historical constraints and out-of-sample prediction are therefore not optional.
The best model is not the one with the prettiest deciphered paragraph.
It is the smallest historically plausible map that predicts the most unseen structure.
A Parent and Teacher Guide
- Separate simple substitution from homophonic substitution.
- Understand what multiple ciphertext alternatives do to frequency.
- Treat Naibbe as a constructive control, not a Voynich solution.
- Count mapping freedom.
- Demand key convergence.
- Require source grammar.
- Test forward encryption as well as reverse decoding.
- Use new discriminators when old statistics are no longer sufficient.
The wider lesson is:
showing that a mechanism can imitate the evidence keeps a hypothesis alive; showing that one fixed mechanism uniquely predicts new evidence is what begins to identify it.
Reader Checklist: Before You Accept a Homophonic Voynich Solution
- What is the plaintext unit?
- How many homophones are allowed per unit?
- Are mappings position-dependent?
- Are mappings Currier-dependent?
- How many total free assignments exist?
- Was the key frozen before testing new pages?
- Does the key size saturate?
- Does source-language grammar emerge?
- Do proper names use the same mappings?
- Do labels work?
- Does the model explain word-length and repetition spectra?
- Does it explain edge coupling?
- Does it explain line effects?
- Can plaintext be encrypted forward to generate comparable ciphertext?
- Are failures reported without adding another homophone automatically?
Frequently Asked Questions
What is a homophonic cipher?
It is a substitution system in which one plaintext unit can be represented by several alternative ciphertext symbols or groups, often to flatten frequency patterns.
Were homophones historically used?
Yes. Surviving European cipher keys and instructions document homophonic substitution as a real historical cryptographic technique.
What is the Naibbe cipher?
Michael Greshko’s 2025 Naibbe cipher is a verbose homophonic substitution system constructed to test the Voynich ciphertext hypothesis. It can transform meaningful Latin and Italian into decipherable ciphertext reproducing many Voynich-like statistical properties.
Does Naibbe solve Voynich?
No. It shows that a historically plausible cipher class can generate many relevant properties. It does not recover an accepted Voynich key or plaintext.
Could homophony explain why Voynich words vary so much?
Potentially. Multiple ciphertext alternatives can create visible variants from the same source word, but a real key must identify those equivalence classes predictively.
What is the biggest danger?
Unlimited mapping freedom. If any sign can mean several things whenever needed, almost any plaintext can be fitted. A valid key must converge and generalise.
Related eduKateSG Reading
- Cipher, Plaintext or Generated System?
- The Control Problem
- Word Families
- Exact Repetition
- The Edge Problem
- The Null Problem
Research and Further Reading
- Michael A. Greshko — The Naibbe Cipher (Cryptologia, 2025)
- Greshko — Naibbe Cipher Code and Data
- Cipher Key Instructions in Early Modern Europe
- Historical Cryptology Portal — Nomenclator Encryption Systems
- Bowern & Lindemann — The Linguistics of the Voynich Manuscript
The Final Idea
The old cipher debate asked whether meaningful language could survive a transformation strong enough to make Voynichese look strange.
The answer is now clearer than it used to be.
Yes.
A historically plausible hand cipher can hide frequencies.
Multiply surface forms.
Change word lengths.
Suppress repetitions.
And still preserve recoverable plaintext.
That does not bring us closer by itself to one Voynich reading.
It does something more disciplined.
It removes an easy dismissal.
Now the cipher hypothesis must face harder questions.
Why these exact word families?
Why these edges?
Why Currier?
Why these labels?
Why this visual-document structure?
The Homophony Problem is no longer whether a cipher can look like Voynich. It is whether one compact historical key can explain why Voynich looks precisely like itself—and keep working after the key is no longer allowed to change.