# RIPEMD-160 first-48-bit collision

Found two distinct eight-byte inputs. `0x` denotes hexadecimal bytes, not literal UTF-8 text.

| Field | Value |
|---|---|
| inputA | `0x19bef10000000000` |
| inputB | `0x1022730100000000` |
| RIPEMD-160(inputA) | `902e5fc86be47b1e2a17de2aab65d4e765623a05` |
| RIPEMD-160(inputB) | `902e5fc86be4a99253faddc650510cb85e77233d` |
| Common first 48 bits | `902e5fc86be4` |
| lambda | 24 |

## Evidence and method

The deterministic [search](../src/search.py) hashed consecutive integers encoded as eight little-endian bytes and retained their first six digest bytes. It found this pair after 24,322,577 evaluations (approximately 76.64 seconds locally). The requested exact four-field answer is [collision.json](../collision.json).

The [verification script](../src/verify.py) independently recomputed both digests after the search, checked distinct decoded inputs, checked the JSON fields, and asserted equality of the first six bytes. Its observed output is [verification.json](verification.json). A second invocation through the OpenSSL command-line tool produced matching full digests, recorded in [openssl-check.txt](openssl-check.txt). The command was `openssl dgst -ripemd160`, with each decoded input supplied on standard input. Local OpenSSL version: 3.5.7.

## Conclusion and limits

Observed fact: the two full digests above have identical first six bytes and different remaining bytes. Thus the local computations establish the requested 48-bit truncated collision; this is not a full 160-bit collision.

These checks are local evidence, not independent certification. Python hashlib and the OpenSSL command-line tool may share the same cryptographic implementation. The external SIMD verifier was not available here, so its acceptance remains untested. No claim is made about its execution or verdict.
