# Keccak-256 collision in the first 48 bits

The two distinct byte strings in [`collision.json`](../collision.json) have identical first six digest bytes (48 bits). Hex inputs are decoded to bytes before hashing.

| Input | Full Keccak-256 digest |
| --- | --- |
| `0x8375360100000000` | `8851a59bbb9d6231d46ab9566296d3aed4afb5cd4212a1f68a094142b0366868` |
| `0x7131040200000000` | `8851a59bbb9d27a12c8340ba34a0ac8820e6315e00542945f74d66f4ef53a9b1` |

**Observed common 48-bit MSB prefix:** `0x8851a59bbb9d`. The complete digests differ; this is a collision only under the requested truncation, with lambda 24.

## Method and attributable evidence

[`src/search.c`](../src/search.c) deterministically hashes eight-byte little-endian counters starting at 1. It found counters 20,346,243 and 33,829,233 after 33,829,233 candidate evaluations (additional hashes check possible table matches). It uses a linear-probing table and checks all six prefix bytes before accepting a match.

The search permutation comes from Markku-Juhani O. Saarinen's [tiny_sha3 source](https://github.com/mjosaarinen/tiny_sha3/blob/master/sha3.c), vendored as [`src/keccak.c`](../src/keccak.c), with the finalization suffix changed from `0x06` to `0x01` for Keccak. The upstream header and MIT license are included. Its API names retain `sha3`, but this modified finalization computes Keccak rather than standardized SHA3.

Local verification used a separate implementation: Chen, Yi-Cyuan's [js-sha3 v0.9.3](https://github.com/emn178/js-sha3/blob/v0.9.3/src/sha3.js), included unchanged in [`vendor/sha3.js`](../vendor/sha3.js) with its MIT license. [`src/verify.cjs`](../src/verify.cjs) checks the empty-string and `abc` Keccak-256 vectors, exact JSON fields, input byte inequality, and equality of the first 12 hexadecimal digest characters. Running `node src/verify.cjs` succeeded and printed the full digests above. This check requires no network or package installation.

The concrete evidence is the two independently recomputed digests. Their shared first 48 bits establish the requested collision under the local implementations. No SIMD acceptance result is available from this environment; these are local checks, not an independent certification of the submission.

## Reproduction

Verify the delivered result with:

```sh
node src/verify.cjs collision.json
```

To repeat the search with a C compiler (approximately 512 MiB for the table):

```sh
cc -O3 src/search.c src/keccak.c -o /tmp/collision-search
/tmp/collision-search > /tmp/collision-result.json
node src/verify.cjs /tmp/collision-result.json
```

The performed search used Zig 0.13.0's C compiler with `-O3 -march=native`. Compiler tooling is not required to verify the delivered collision. No search executable or downloaded compiler is a runtime dependency of the verifier.
