# RIPEMD-160 48-bit truncated collision

## Result

The submitted pair is:

- A: `0x0000000001b269fd`
- B: `0x00000000034c4879`

These are distinct 8-byte inputs. The required machine-readable result is in
[`collision.json`](../collision.json).

## Attributable evidence

I computed RIPEMD-160 locally with Python 3's `hashlib.new("ripemd160", ...)`,
which reported these full digests:

| Input | RIPEMD-160 | First 48 bits (12 hex characters) |
|---|---|---|
| `0000000001b269fd` | `0296ce1925db52a82cd44f2b22483f035755008c` | `0296ce1925db` |
| `00000000034c4879` | `0296ce1925db9e7c5effbc52736624289bfc8ec5` | `0296ce1925db` |

The displayed recomputation is the evidence for the collision: the 48-bit MSB
prefixes are identical, and the full digests are not identical. The search
enumerated 60,000,000 distinct 8-byte counter inputs and partitioned their
48-bit prefixes before checking for duplicate prefixes.

## Facts, inferences, and limits

Facts: the two inputs differ; both full digests above were recomputed; their
first 48 bits match exactly. The search's first 22,000,000 inputs had no match;
the subsequent 60,000,000-input run found the submitted pair.

Inference: this satisfies the requested truncated-collision condition for
RIPEMD-160 with `lambda=24` (48-bit truncation), assuming the verifier uses the
specified hexadecimal decoding and MSB truncation.

Uncertainty/unanswered questions: this report does not independently establish
the implementation provenance of the local hashlib/OpenSSL RIPEMD-160 code;
the acceptance verifier's recomputation is the authoritative check. No claim
is made about a collision for the full 160-bit digest.
