# SHA-256 collision in the first 48 bits (λ = 24)

A collision was found and locally verified. The deliverable is [collision.json](../collision.json).

## Observed result

The `0x` strings encode raw bytes, not the UTF-8 characters of their hexadecimal representation. Each input is eight bytes.

| Field | Value |
| --- | --- |
| inputA | `0xe8f1380000000000` |
| inputB | `0x23f68e0000000000` |
| SHA-256(inputA) | `67171c0eb1922b1b1e7b76dd2213a661d3542f3c6b00e39279800abaaf50b502` |
| SHA-256(inputB) | `67171c0eb192a147eff93d18c3adf2a803bba554778ef76416669125a3a46e19` |
| Common first 48 bits (six bytes) | `67171c0eb192` |

The inputs are distinct. The first twelve hexadecimal digest digits match, which establishes the requested 48-bit MSB collision. Their full 256-bit digests differ.

## Attributable evidence and reproduction

These values are outputs of local computation, not externally sourced claims. The included [search source](../tools/find_collision.c) implements SHA-256 for eight-byte messages and searches consecutive unsigned counters encoded in little-endian order. A hash table retains digest prefixes and enough counter information to recover a prior matching input.

The search examined counters 0 through 9,369,123 inclusive. It found counters 3,731,944 and 9,369,123. Its diagnostic output was:

```text
Found counters 3731944 and 9369123; prefix 67171c0eb192; counters searched 9369124
```

The C prefix implementation was cross-checked against Python `hashlib` on 1,000 eight-byte inputs: counters `i * 0x9e3779b97f4a7c15` reduced modulo 2^64 for `i` from 0 through 999. All matched. Compilation with `-O3 -Wall -Wextra -Werror` succeeded.

The included [verification script](../tools/verify_collision.py) checks the exact JSON field set, algorithm, integer lambda, distinct decoded bytes, and equality of the first six digest bytes. Run offline from the repository root:

```sh
python3 tools/verify_collision.py
```

Observed output:

```text
inputA bytes: e8f1380000000000
inputB bytes: 23f68e0000000000
SHA256(inputA): 67171c0eb1922b1b1e7b76dd2213a661d3542f3c6b00e39279800abaaf50b502
SHA256(inputB): 67171c0eb192a147eff93d18c3adf2a803bba554778ef76416669125a3a46e19
Matching first 48 bits: 67171c0eb192
PASS
```

Both full digests were also recomputed by piping each decoded eight-byte input to `openssl dgst -sha256` (OpenSSL 3.5.7). Both matched the table above. Python and OpenSSL may share a cryptographic backend; they are separate checks, not a claim of fully independent implementations. The search uses its own C implementation.

To reproduce the deterministic search, using a C compiler and approximately 512 MiB for the table:

```sh
gcc -O3 -Wall -Wextra -Werror tools/find_collision.c -o /tmp/find_collision
/tmp/find_collision > /tmp/collision-reproduced.json
cmp collision.json /tmp/collision-reproduced.json
```

No downloaded libraries or network access are needed for either delivered utility. Search requires a C compiler; verification requires Python 3 with its standard library.

## Scope and limits

The conclusion follows from the distinct input bytes and equal computed six-byte prefixes. This is a truncated-digest collision only. The local checks do not constitute independent reviewer certification, and the external SIMD verifier was not available in this session. External acceptance remains unobserved; there are no unresolved local mismatches.
