# SHA-256 collision for a 48-bit prefix

The requested collision was found. `collision.json` contains exactly the four requested fields, with lambda 24 and two distinct UTF-8 inputs. Hash the string contents without quotation marks, a newline, or a terminating NUL.

| Input | Full SHA-256 digest |
| --- | --- |
| `identitymd-sha256-48-42456592` | `09fa3cea0bea38de0e8d319dc3df3ccb15fc9295cd0ee8142631662784232412` |
| `identitymd-sha256-48-59284374` | `09fa3cea0bea7262258d1bef236f1c8d120dd7d4e9d4ecf5d1452418073bea8f` |

Both digests begin with `09fa3cea0bea`: the same six bytes, or 48 most significant bits. Their full digests differ. This establishes the requested truncated collision, not a collision of the full SHA-256 digest.

## Attributable local evidence

The search source is `scripts/find_collision.cpp`. It hashes strings of the form `identitymd-sha256-48-N` using the local OpenSSL SHA256 function, sorts each batch by its first six digest bytes, and searches adjacent entries for equal prefixes. Batch 0 (N from 0 through 33,554,431) had no match. Batch 1 (N from 33,554,432 through 67,108,863) produced the pair above. The run evaluated 67,108,864 inputs; comparisons were within each batch.

A separate implementation, Python's `hashlib.sha256`, checked the submitted JSON, decoded the inputs, checked that their bytes differ, and recomputed both full digests. Run `python3 scripts/verify_collision.py` from an offline environment with Python 3. The observed output was:

```json
{
  "inputA_sha256": "09fa3cea0bea38de0e8d319dc3df3ccb15fc9295cd0ee8142631662784232412",
  "inputB_sha256": "09fa3cea0bea7262258d1bef236f1c8d120dd7d4e9d4ecf5d1452418073bea8f",
  "shared_first_48_bits": "09fa3cea0bea",
  "verified": true
}
```

The table and verification output are observed local results. The conclusion follows from equality of their first 12 hexadecimal digits. No external research claims or probabilistic estimates are needed to validate this particular pair. These checks are self-verification, not independent review. The external SIMD verifier was not available here, so its acceptance remains untested.
