# Verified SHA-256 collision for the first 48 bits

The deliverable [collision.json](../collision.json) contains two distinct UTF-8 inputs whose SHA-256 digests have identical first six bytes (48 most significant bits), for lambda = 24.

| Field | Exact input (no newline) | Full SHA-256 digest |
| --- | --- | --- |
| inputA | `simd-collision-13665727` | `0bba3a891cb002366c83200aa33d33e227cc331fd3c7117d6cda6e7f0140a647` |
| inputB | `simd-collision-18006063` | `0bba3a891cb09619f244ad1c7f780406eaff80df916f4331dd3d789dfbbbd0cb` |

The common prefix is **`0bba3a891cb0`**. The complete digests differ; this result is a truncated collision only.

## Method and attributable evidence

A local C search hashed ASCII strings of the form `simd-collision-<counter>` with OpenSSL's SHA256 function, starting at counter zero. A hash table retained each six-byte prefix and its first counter. It found the displayed pair after 18,006,064 evaluations, when counter 18,006,063 matched counter 13,665,727. The search scaffolding was in the disposable `test/scratch/` directory; it is not required to verify the delivered result.

The delivered [verification script](../verify_collision.py) recomputes the full digests using Python's standard-library `hashlib`, checks the exact JSON field set and parameters, checks distinct decoded input bytes, and compares the first six digest bytes. Run from the repository root:

```sh
python3 verify_collision.py
```

The local run passed and printed the two full digests above and the shared prefix. A separate invocation of `openssl dgst -sha256`, supplied with each exact UTF-8 input through standard input without a newline, also produced those full digests. These are direct local measurements, not inferred or externally sourced digest values.

## Limits

No SIMD verifier or independent reviewer was run here. Python and the OpenSSL command line may share the same underlying cryptographic library, so their agreement is not evidence of independent implementations. The supplied bytes and script make the claim reproducible offline with Python 3; the recipient's recomputation remains authoritative. There are no unresolved questions about the locally checked prefix equality, and no claim of a full SHA-256 collision.
