# Keccak-256 collision at 48 bits (lambda = 24)

## Result

Found two distinct eight-byte inputs whose Keccak-256 digests have identical
first 48 bits. The required machine-readable result is [collision.json](../collision.json).
The `0x` values below encode raw bytes; the hexadecimal characters are not hashed
as text.

| Item | Value |
| --- | --- |
| inputA | `0x8375360100000000` |
| inputB | `0x7131040200000000` |
| Keccak-256(inputA) | `8851a59bbb9d6231d46ab9566296d3aed4afb5cd4212a1f68a094142b0366868` |
| Keccak-256(inputB) | `8851a59bbb9d27a12c8340ba34a0ac8820e6315e00542945f74d66f4ef53a9b1` |
| Shared first six bytes / 48 MSB | `8851a59bbb9d` |

## Attributable local evidence

The original computation is implemented in [tools/search.c](../tools/search.c).
It hashes consecutive unsigned counters serialized into eight little-endian
bytes and stores fingerprints in a collision table. A suspected match is
checked against all six relevant digest bytes. This run found its first match
at counter 33,829,233, after that many evaluations of candidate inputs (additional
hash evaluations can occur when checking table matches).

A separate, coordinate-based Python implementation is provided in
[tools/verify.py](../tools/verify.py). It generates round constants using an LFSR,
instead of the search program's constant table. It uses Keccak padding with the
`0x01` suffix, a 136-byte rate, and 24 permutation rounds. It checks the empty
string and `abc` known-answer values before checking the submitted JSON, distinct
decoded inputs, and the first six bytes of their full digests.

Observed local check, executed with `python3 tools/verify.py` (exit status 0):

```text
inputA: 0x8375360100000000
inputB: 0x7131040200000000
digestA: 8851a59bbb9d6231d46ab9566296d3aed4afb5cd4212a1f68a094142b0366868
digestB: 8851a59bbb9d27a12c8340ba34a0ac8820e6315e00542945f74d66f4ef53a9b1
First 48 bits (MSB): 8851a59bbb9d
PASS: distinct inputs, exact schema, matching first six digest bytes.
```

## Interpretation and limits

The observed equal six-byte prefixes establish the requested truncated collision
under the supplied implementations. The full digests differ; no full Keccak-256
collision is claimed. These are reproducible local computations, not an external
review or an independently authoritative certification. SIMD was not available
in this workspace, so its acceptance verdict remains unobserved. All code needed
to repeat the local verification is included, with no network dependencies.
