Unbreakable, and almost unusable
Key as long as the message, truly random, used exactly once: provably secure and almost impossible to run at scale.
The proof, and the price
The one-time pad is the only cipher in the history of cryptography that carries a mathematical proof of security. Not a practical argument, not an engineering confidence — a proof. Claude Shannon demonstrated in 1949 that a message encrypted with a truly random key, as long as the message itself, used exactly once, and kept entirely secret, yields precisely zero information about the plaintext to an adversary who intercepts the ciphertext. Every possible plaintext of that length is equally consistent with what was captured. The mathematics is clean and final.
The conditions attached to that proof are where history gets complicated.

The key must be truly random — not pseudorandom, not generated by an algorithm, but drawn from a source that has no pattern whatsoever. It must be exactly as long as the message; a key that runs out and repeats collapses the whole guarantee. It must never be used for a second message, even in part. And it must reach the intended recipient without being seen by anyone else, then be destroyed completely after use. Meet every one of those conditions, and the system is unbreakable. Fail any one of them, and it is not.
The operational arithmetic
The problem is not theoretical. Consider the volumes involved. A busy diplomatic mission exchanging several thousand words a day needs several thousand random characters of key material per day. Those characters must be physically generated, recorded on pads or tape, transported to the other end of the channel before the traffic begins, and then destroyed in the right order after each use. Multiply that by every station in a network, add the bureaucratic fact that both parties must use the same page in the same sequence, and the logistics become crushing before the volume gets large.
Soviet intelligence used a version of the one-time pad for agent communications during the Second World War. The Venona project, in which American and British signals intelligence spent decades reading a fraction of that traffic, did not break the pad itself — it found pad pages that had been duplicated under production pressure and reused across different messages. Two ciphertexts enciphered with the same key material could be combined, and the result attacked much as a polyalphabetic cipher is attacked once the keyword repeats. The mathematics of the pad remained intact; the procedure around it failed.
That pattern — the procedure failing while the mathematics stands — runs through the entire history of the one-time pad. The German Lorenz teleprinter cipher, known to British codebreakers at Bletchley Park as Tunny, was not a pad in the strict sense, but it shared the fatal vulnerability: operators sending a long message twice with the same starting position gave analysts a depth, a pair of ciphertexts on the same key, and Tunny was broken from there. The lesson is identical.
What genuine security actually requires
Shannon's proof demands a rigorous sense of what "random" has to mean: not merely hard to predict, but informationally independent of everything. Atmospheric noise, radioactive decay, or physical lottery draws can supply this; any deterministic process cannot, no matter how complicated it appears. Generating enough genuinely random material for a high-volume channel is itself a significant engineering problem, and in practice many systems that called themselves one-time pads were using key material that was random enough for most purposes but not provably so in Shannon's sense.
The distribution problem is arguably the deeper one. The key has to travel securely before the message can travel at all, which means the channel used to share the key must itself be secure. For a single exchange between two people who can meet, this is manageable. For a network of embassies, submarines, or field agents who may never meet their handlers, it is an ongoing logistical commitment that never ends, grows with traffic volume, and carries its own points of failure at every step.
The one-time pad remains the endpoint toward which cryptography points when it wants to say what security actually means. It is also a system that history has used, in corners and under pressure, and always found the same thing: the mathematics is immovable, and the humans running it are not.