# Keccak-256 truncated collision, λ = 24

The two distinct eight-byte inputs in `../collision.json` have identical first
48 bits (six bytes, MSB prefix) of their Keccak-256 digests.
The `0x` strings encode raw bytes, not the UTF-8 text of the hexadecimal strings.

| Field | Value |
| --- | --- |
| inputA | `0x8375360100000000` |
| inputB | `0x7131040200000000` |
| Keccak-256(inputA) | `8851a59bbb9d6231d46ab9566296d3aed4afb5cd4212a1f68a094142b0366868` |
| Keccak-256(inputB) | `8851a59bbb9d27a12c8340ba34a0ac8820e6315e00542945f74d66f4ef53a9b1` |
| Shared 48-bit prefix | `8851a59bbb9d` |

## Evidence and reproduction

These are locally computed facts. [find_collision.py](find_collision.py) searched
eight-byte little-endian encodings of consecutive integers starting at zero,
using system OpenSSL `EVP_Q_digest` with `KECCAK-256`. It found indices
20,346,243 and 33,829,233 after 33,829,234 evaluations, in approximately
54.35 seconds on this host. The elapsed time describes this run only.

[verify_collision.py](verify_collision.py) independently implements Keccak-256
in pure Python, with the Keccak `0x01` domain padding, and needs only Python's
standard library. Run from the repository root:

```sh
python3 artifacts/verify_collision.py
```

Observed result:

```text
inputA: 8375360100000000
digestA: 8851a59bbb9d6231d46ab9566296d3aed4afb5cd4212a1f68a094142b0366868
inputB: 7131040200000000
digestB: 8851a59bbb9d27a12c8340ba34a0ac8820e6315e00542945f74d66f4ef53a9b1
PASS: distinct inputs; matching first 48 bits: 8851a59bbb9d
```

The verifier also checks the JSON keys, algorithm, λ, distinct decoded inputs,
and empty-message and `abc` digest vectors. Additional local checks compared
the two implementations for message lengths 0, 1, 8, 32, 135, 136, 137, 272,
and 1000 bytes; all agreed, including absorption/padding boundaries.

## Interpretation and limits

Matching six-byte prefixes establishes the requested truncated collision.
The full 256-bit digests differ. No statistical estimate is needed to establish
the result, and no claim of a full Keccak-256 collision is made.

All verification described here was performed locally by the producing agent.
It is reproducible evidence, not an external audit. The SIMD acceptance check
has not been run here; its outcome remains unobserved. No other unanswered
question is required to assess the supplied byte pair locally.
