Hide messages inside carrier text using four zero-width Unicode characters as 2-bit positions per visible character. The carrier looks unchanged; the bits are invisible.
The carrier text looks identical.
Hidden bits sit in invisible characters (U+200B, U+200C, U+200D, U+FEFF) that most software ignores. Copy-paste the stego text into a chat, email, or document and it looks exactly like the carrier — but anyone with this tool and your secret can pull the message out. Anyone running a ZW detector can also detect something is there. This is not encryption.
This tool scans for the four zero-width characters and reconstructs the message. Reveal mode shows positions in highlighted spans.
Each carrier character position holds 2 bits (4 ZW chars). One byte of hidden data needs 4 carrier positions.
Compare visible text of carrier vs stego. They should look identical.
Unicode reserves a handful of "format" characters that have no glyph and no advance width. They were added for legitimate typographic purposes (joining Arabic letters, controlling line breaks in word processors) but the format nature — invisible but real — makes them perfect for hiding data.
The four characters used here. U+200B (Zero-Width Space, ZWSP) — common in word-processor output. U+200C (Zero-Width Non-Joiner, ZWNJ) — controls Persian/Arabic ligatures. U+200D (Zero-Width Joiner, ZWJ) — joins emoji and complex scripts. U+FEFF (Byte Order Mark, BOM / Zero-Width No-Break Space) — encoding signature at file start, or no-break formatting mid-string.
Four characters = 2 bits. If we map each ZW char to a 2-bit pattern (00, 01, 10, 11), each carrier character position holds 2 bits of payload. So a 100-character carrier can hide 25 bytes (200 bits). A short message of "Hi" is 2 bytes — needs 8 carrier positions, meaning 8 carrier characters with 2 ZW chars inserted between them.
Detection. A simple byte-frequency histogram on any channel will see "this file has a suspiciously large number of U+200B/U+200C/U+200D/U+FEFF." That's the tradeoff. Watermarking tools and abuse detection scan for exactly this. Don't rely on it for anything sensitive.
Embed a customer ID or build hash in the text itself. Useful for tracking where a leaked document originated, provided you know the recipient won't strip ZW chars.
Build a challenge where the answer is hidden in plain sight. Provide the stego text and a hint like "look at what isn't there."
Investigate how an attacker hid data in a public-looking document. Understanding the encoding is necessary to decode the captured artifacts.