How spies actually hid messages: from microdots to pixels
The trick that connects every spy communication method across hundreds of years is not the code. It is the carrier.
A cipher scrambles a message so anyone who intercepts it sees nonsense. Hiding the message in plain sight means nobody looks twice at the carrier in the first place. Those are two different problems, and spies have been solving the second one since before there were intelligence agencies in any modern sense. The thing worth knowing is that the idea never changed. Only the technology did.
Wax tablets and tattooed scalps
The oldest documented example comes from Herodotus, writing in the 5th century BC. A Greek named Histiaeus needed to send a message to a distant ally without Persian forces intercepting it. His solution: shave a trusted slave's head, tattoo the message on the scalp, wait for the hair to grow back, then send the man on his way. The recipient shaved the slave's head to read it.
That is steganography. Not encryption. The message itself was not scrambled at all. Nobody inspecting the slave saw anything suspicious because there was nothing to see.
A generation later, another Greek in Herodotus sends a military warning on a wax writing tablet by scratching the message into the wood underneath, then covering the wood with fresh wax. Anyone who intercepts it sees a blank tablet. The recipient knows to scrape off the wax.
Both methods share the same operating logic: hide the fact that there is a message at all, and you do not need to worry about whether the message can be decoded.
Invisible ink
The Romans used milk. The message dried clear on the page; hold it near a flame and it browns into legibility. Lemon juice works the same way, and the technique earned a second life with schoolchildren before eventually finding its way back to actual spies.
By World War I, British, French, and German intelligence services were all running dedicated labs trying to develop ink formulas the other side's chemists could not detect. The problem was fundamental: invisible ink is only invisible until someone checks. If the enemy knows to look, they check every letter. By World War II the technique was still in use as a fallback, but it had stopped being a reliable front-line method.
The deeper issue with invisible ink, null ciphers, and most physical methods is that they all assume the carrier will get through uninspected. Once adversaries start checking everything, "hidden in plain sight" only works if it looks exactly like the things they are not checking.
Null ciphers
German intelligence in World War II relied heavily on null ciphers, which are not really ciphers at all. You write a grammatically correct, socially plausible letter about nothing in particular, and the real message is encoded in the structure. Take the second letter of every word. Read every fifth word. Extract the first letter of every sentence after the greeting.
The FBI intercepted one such letter that, when the second letter of each word was extracted in sequence, produced a complete and accurate report on Allied ship movements. The outer letter was unremarkable. An agent reading it for content would have set it down and moved to the next one.
Null ciphers require no equipment and leave no chemical trace. Their weakness is that writing natural-sounding prose with a predetermined hidden structure is genuinely difficult, and the statistical properties of forced text are detectable if an analyst knows what to look for. The better your null cipher, the harder it is to write and the less information you can fit into it.
Microdots
The German intelligence service, working in the late 1930s, developed what J. Edgar Hoover would eventually call the enemy's "masterpiece of espionage": the microdot. A full typewritten page is photographed at extreme reduction until the image is roughly one millimeter across. That dot replaces the period at the end of an ordinary sentence in an ordinary letter. The letter gets mailed. The recipient locates the dot, places it under a microscope, and reads the original page at full resolution.
The FBI got its first tip from a double agent in 1940 and spent a year failing to find one. They intercepted their first confirmed microdot in 1941.
What made microdots compelling was scale. Any document, any length, reduced to a speck indistinguishable from a typographical period. A trained reader looking at the letter had nothing to find because the thing they were looking for was, by definition, not visually distinguishable from nothing. That is a harder problem than invisible ink, which at least gives an adversary something to chemically test for.
Dead drops and the Cold War
By the Cold War, the problem had shifted from disguising the content to disguising the exchange itself. A dead drop separates the two people involved in a message transfer so they never appear in the same place at the same time. Leave something in a prearranged location. The other person picks it up later. A hollow bolt in a park. A piece of tape on a mailbox. A chalk mark on a fence post to signal that the drop is live.
The message inside could be anything: film, a handwritten note, a microdot pasted inside a magazine. The sophistication had moved up a level. It was no longer just about hiding the content. It was about hiding the fact that a transfer happened at all.
Digital steganography
Digital steganography follows the same logic as the microdot. Take a carrier that looks completely ordinary (a photo, an audio file, a video) and embed data inside it in a way the human eye cannot detect. The file travels through ordinary channels. Only the person who knows to look, and knows how, extracts what is inside.
Intelligence agencies were developing digital steganography tools through the 1990s. What changed in the 2020s is who has access to the technique. GhostCode does this from a phone: write a message, choose a key, and the message is hidden inside an ordinary-looking photo or QR code. The person who receives it sees a normal image. The right person, with the right key, opens it in the app and reads the original text.
No signals lab. No microscope. No dead drop. The whole exchange looks like you sent a picture.
What stayed the same
The striking thing about running through this history is how consistent the underlying move is. Histiaeus tattooed a message on a scalp in 500 BC because walking a human carrier through enemy territory was less conspicuous than sending a document. The microdot worked because a period in a letter is less conspicuous than a roll of film. A hidden message in a photo works because a photo on your camera roll is less conspicuous than an encrypted file.
The technology changes every generation. The idea does not. The best hidden message is the one that does not look like a message at all.
The practical difference between the spy version and the modern version is mostly one of access. The tradecraft, the labs, the training: those were what kept the technique in the hands of intelligence services for most of its history. The phone in your pocket changed that part. The hiding-in-plain-sight part was always the same. You can read more about hiding a message inside a photo if you want to see what the modern version looks like in practice.
Questions people ask
How did spies communicate in World War II?
WWII spies used several overlapping methods: invisible ink for hidden writing in ordinary letters, null ciphers where the real message was embedded in the structure of a cover letter, and microdots, which reduced an entire typewritten page to a speck small enough to replace a period. Radio operators also used Morse transmissions on covert frequencies, though those were detectable by direction-finding equipment. The challenge in every case was not just hiding the content but getting the carrier to the recipient without it being flagged as suspicious.
What is a microdot in espionage?
A microdot is a photograph of a document reduced to approximately one millimeter in size, small enough to be pasted over a period or other punctuation mark in an ordinary letter. The technique was developed by German intelligence in the late 1930s and relied on the fact that the human eye, reading a letter for content, would never notice one period out of hundreds. The recipient used a microscope to read it. The FBI's first confirmed intercept of a microdot was in 1941, a year after they learned the technique existed.
What is the difference between a cipher and steganography?
A cipher transforms a message so that it becomes unreadable without a key. The message is visible but meaningless. Steganography hides the message inside a carrier object (a letter, a photo, a full-stop) so that the existence of the message itself is concealed. A skilled adversary looking at an intercepted cipher knows there is something to decode. Looking at a well-executed piece of steganography, they see only the carrier. Both have legitimate uses and both have been combined throughout history: a hidden message that is also encrypted gives you both layers of protection.
Put a hidden message in your own photo
GhostCode hides your message inside a photo or a QR code, so only the person you choose can read it. See how it works.