# SHA-256 first-48-bit collision

Found a collision for λ = 24, where the requested truncation is the first 48 bits (six bytes, or 12 hexadecimal digits) of SHA-256. The exact submission is [collision.json](../collision.json).

| Input (hexadecimal bytes) | Full SHA-256 digest |
| --- | --- |
| `0x000000000017211c` | `4e84dca19fa699674e41dc0ff0f92046577a96fd3bbc22ae6a036986dc268301` |
| `0x00000000014060cc` | `4e84dca19fa67ad46fd0f73243c0081834a4767ce3fc91b0b4dade47ab574d2e` |

Both digest prefixes are **`4e84dca19fa6`**. Inputs are decoded from hexadecimal into eight bytes; the literal characters `0x` are not hashed. The inputs differ, and the full digests differ.

## Attributable evidence and reproduction

The local [search implementation](search.c) used the system OpenSSL 3 SHA256 function and found this pair after **20,996,301** evaluations of consecutive big-endian counters starting at zero. Input A is counter 1,515,804; input B is counter 20,996,300.

The separate [verification script](verify.py) recomputed both complete digests using Python 3 `hashlib`, checked distinct decoded inputs, checked the exact JSON keys and parameters, and compared the first six digest bytes through their 12 hex digits. Run from the repository root:

```sh
python3 artifacts/verify.py
```

This check passed locally. The table above records its actual output, not estimated hash values. The [README](../README.md) also gives the search build and reproduction commands. No external factual sources were needed: the evidence is the provided input bytes and reproducible hash computation.

## Limits

This result establishes only the requested 48-bit truncated collision. It does not establish a collision in full SHA-256. These are local checks, not an independent reviewer or SIMD attestation. No uncertainty remains in the locally computed prefix equality; independent acceptance remains for the caller to determine.
