# RIPEMD-160 collision truncated to 48 bits

The requested collision was found and verified locally. The deliverable is
[collision.json](../collision.json), with exactly the four requested fields.
`lambda` is 24; the comparison uses the first 48 bits (six bytes) of the
serialized RIPEMD-160 digest.

## Observed evidence

Inputs beginning with `0x` are hexadecimal encodings of raw bytes, not UTF-8
encodings of the displayed text. Each input decodes to eight bytes.

| Value | Input A | Input B |
| --- | --- | --- |
| Input | `0x19bef10000000000` | `0x1022730100000000` |
| Full RIPEMD-160 | `902e5fc86be47b1e2a17de2aab65d4e765623a05` | `902e5fc86be4a99253faddc650510cb85e77233d` |
| First 48 bits, MSB | `902e5fc86be4` | `902e5fc86be4` |

These are local measurements, obtained using OpenSSL 3.0.2's RIPEMD160
function during search and recomputed with the OpenSSL command-line legacy
provider. A separate pure Python compression implementation produced the same
full digests. Its machine-readable output is
[verification.json](verification.json), attributable to
[tools/verify_collision.py](../tools/verify_collision.py).

The search enumerated eight-byte little-endian counters starting at zero and
stored six-byte digest prefixes in a hash table. It found counters 15,842,841
and 24,322,576 after 24,322,577 hash evaluations. The search implementation is
[tools/find_collision.c](../tools/find_collision.c). Its final diagnostic was:

```text
evaluations=24322577 prefix=902e5fc86be4 counters=15842841,24322576
```

## Checks and inference

Run the offline, dependency-free verifier from the repository root:

```sh
python3 tools/verify_collision.py
```

It checks six known-answer vectors, the JSON field set, algorithm and lambda,
decoded input distinctness, and equality of the first six digest bytes. It
prints both full digests and the matching prefix, and exits with an error if a
check fails. This command passed on the submitted file.

Additional local checks compared the Python implementation with OpenSSL on
deterministic messages of lengths 0, 1, 8, 55, 56, 63, 64, 65, 119, 120, 128,
and 1024 bytes; all 12 agreed. Negative checks confirmed rejection of identical
inputs, a noncolliding pair, an incorrect lambda, and an extra JSON field.

For search reproduction on a system with a C compiler and `libcrypto.so.3`:

```sh
cc -O3 tools/find_collision.c -Wl,-l:libcrypto.so.3 -o /tmp/find_collision
/tmp/find_collision > /tmp/reproduced-collision.json
python3 tools/verify_collision.py /tmp/reproduced-collision.json
```

The search needs about 768 MiB for the table. Verification needs only Python 3
and the ordinary files included here, with no network or installed packages.

**Inference:** the distinct decoded byte strings and equal measured six-byte
prefixes satisfy the requested truncated collision. The full digests differ;
the evidence establishes a 48-bit truncated collision only.

**Limits and uncertainty:** all checks were performed by the implementing
agent. The Python implementation provides a separate computational check,
not an independent reviewer. The external SIMD verifier has not been run in
this workspace, so its acceptance remains unobserved. There are no unanswered
questions about the submitted encoding or local comparison result.
