C1 = P1 ⊕ KS C2 = P2 ⊕ KS → C1 ⊕ C2 = P1 ⊕ P2 Using language models (English/ASCII bias), recover P1 , P2 , then derive KS → extract initial key.
Extract key stream by subtracting plaintext from ciphertext. First L bytes = initial key. 3.2 Ciphertext-Only with Key-Stream Reuse If same initial key used for two messages: auto-key crack only