FIELD GUIDE · SUBSTITUTION CIPHERS
The Alphabet Backwards, and the Cipher Hidden In It
Say it once and it is a party trick. Write it under the alphabet and it becomes a cipher that hid the name of Babylon for twenty-five centuries.
THE SHORT VERSION
The alphabet backwards runs Z Y X W V U T S R Q P O N M L K J I H G F E D C B A. Written underneath the ordinary alphabet it forms the Atbash cipher: every letter swaps with its partner, A with Z and M with N, and the same swap undoes it.
THE METHOD
- Write the two alphabets. Write the alphabet, then write it backwards underneath, lining the letters up.
- Take the letter opposite. Find each ciphered letter in one row and take the letter directly opposite it.
- Keep going. There is no key to find and no second pass.
The alphabet backwards is Z Y X W V U T S R Q P O N M L K J I H G F E D C B A. Most people want that list and nothing more. But writing it underneath the ordinary alphabet produces one of the oldest ciphers we have a record of, and the reason it works takes about a minute to learn.
What is the alphabet backwards?
Twenty-six letters in reverse order, starting at Z and ending at A.
Line it up against the forward alphabet and every letter acquires a partner. A sits above Z, B above Y, C above X, and so on until the two halves meet in the middle at M and N.
There are thirteen pairs and no leftovers, because twenty-six is even. Each pair also shares a small piece of arithmetic: the two positions always add up to 27. A is 1 and Z is 26. M is 13 and N is 14. That is the whole rule, and it is the only rule.
How do you say the alphabet backwards from memory?
Not by reversing the forward alphabet in your head. That is why it feels hard: you are running a well-worn track in the wrong direction, and the childhood song fights you the entire way.
Learn it as its own sequence instead, in chunks of four or five, the way you learned the first one:
Say each chunk until it arrives without effort, then join two chunks, then three. Most people have the whole thing inside twenty minutes. It sticks better than you expect, because the reverse order has no competing tune attached to it.
A note on the party trick: reciting the alphabet backwards is not part of any standardised field sobriety test in the United States. The three standardised tests are the horizontal gaze nystagmus, the walk and turn, and the one leg stand. An officer may ask for the backwards alphabet, but it is not on the official list, and being unable to do it sober is entirely normal.
What is the Atbash cipher?
The backwards alphabet used as a code. Write the two alphabets one above the other, then swap each letter for its partner. A becomes Z, B becomes Y, and the message turns into something that looks like nothing.
Atbash is its name, and the name is also the instruction. In Hebrew, the first letter is aleph and the last is tav; the second is bet and the second to last is shin. Take those four in order and you get A-T-B-SH. The cipher is named after its own first two swaps.
What makes Atbash unusual among ciphers is that it has no key. A Caesar cipher has twenty-five possible shifts and you have to work out which one was used. Atbash has exactly one form. There is nothing to choose, nothing to agree in advance, and nothing to guess. The mirror is the whole system.
That also makes it its own undo. Encoding a message twice returns the original, because swapping a letter for its partner and then swapping back lands you where you started. There is no separate decoding procedure to learn.
How do you decode an Atbash message?
Three steps, and the first one is the only work.
- Write the alphabet, then write it backwards underneath, lining the letters up.
- Find each ciphered letter in one row and take the letter directly opposite it.
- Keep going. There is no key to find and no second pass.
Worked example: SVOOL.
S sits opposite H. V sits opposite E. O sits opposite L, twice. L sits opposite O. That gives HELLO.
Try it in the other direction with MEET. M pairs with N, E pairs with V twice, T pairs with G. MEET becomes NVVG, and NVVG run through the same mirror becomes MEET again.
Once the thirteen pairs are familiar you stop consulting the chart. The middle pairs go first, because M and N sit next to each other and are impossible to forget.
Where did the Atbash cipher come from?
The Hebrew Bible, and it is still sitting there in the text.
The book of Jeremiah refers twice to a place called Sheshach, in passages that are otherwise listing the kingdoms of the known world. No such kingdom existed. Run the name through Atbash on the Hebrew alphabet and Sheshach becomes Babel: Babylon, the empire the prophet had every political reason not to name outright. Chapter 51 hides Kasdim, the Chaldeans, as Leb Kamai by exactly the same method, and names Sheshach a second time in the same breath.
Scholars have argued for centuries about why. Some read it as protective, a way of writing dangerous names during an occupation. Others read it as a literary device, or as a scribal habit that carried no intent to conceal anything at all. What is not in dispute is the mechanism: the letters were mirrored, deliberately, and the substitution is reversible in one step.
That makes Atbash the oldest cipher most people can name, and it survives because it costs nothing. No key to distribute, no equipment, no training. Anyone who knows the alphabet already knows the system, which is why it kept turning up in medieval manuscripts and still turns up in puzzle books today.
Is the Atbash cipher secure?
No, and it is worth being precise about why, because Atbash is weaker than the ciphers it resembles.
A substitution cipher is normally broken with frequency analysis: count the symbols, guess that the commonest is E, and work outward. Atbash falls to that too. But it rarely comes to that, because Atbash has no key, so there is nothing to recover. A solver who suspects Atbash simply applies the mirror and reads the answer. One attempt, no search.
The one place it still bites is recognition. A short Atbash message looks like any other scrambled text, and a solver who has not thought of the mirror can spend a long time running frequency counts on it. The tell is the double letters. In HELLO the two Ls become two Os, and any repeated pair survives the mirror intact.
For the ciphers that genuinely resist a solver, and the method that beats them, our guide to solving cryptograms covers the full toolkit: frequency counts, pattern words, and the footholds that open any substitution.
Questions, answered
What is the alphabet backwards?
Z Y X W V U T S R Q P O N M L K J I H G F E D C B A. Twenty-six letters in reverse order, beginning at Z.
What letter is opposite A in the backwards alphabet?
Z. The pairs run A and Z, B and Y, C and X, and so on to M and N. The two positions in any pair always add up to 27.
Is the backwards alphabet the same as the Atbash cipher?
The list is not a cipher by itself. It becomes the Atbash cipher when you use it to swap letters: write the alphabet backwards under the alphabet forwards and replace each letter with the one opposite it.
Why is it called Atbash?
The name spells out its own first two swaps in Hebrew. Aleph swaps with tav, bet swaps with shin, giving A-T-B-SH.
Does the Atbash cipher have a key?
No. It has exactly one form, so there is nothing to agree in advance and nothing to guess. That is what makes it the easiest classical cipher to break.
How do you decode Atbash without a chart?
Remember that each pair of positions adds up to 27. If a letter is the 4th of the alphabet, its partner is the 23rd. Learn the middle pairs first, because M and N sit next to each other.
Is Atbash used in Murdcrypt?
Yes. It is the second cipher in the Field Manual, it appears in Tier I of the book, and it comes up regularly on the daily case at murdcrypt.com.
THE CIPHER IN PLAY
ATBASH
The dossier calls it the Mirror. It is the second cipher in the Field Manual and one of the few in the book with nothing to find: no key, no shift, no keyword. That is why it sits in Tier I. The daily case at murdcrypt.com runs it regularly.
Learn it in the Field Manual ▸NEXT CASE IN –D ––H ––M ––S
Last updated September 9, 2026