# Keccak-256 collision truncated to 48 bits

## Result — locally verified fact

The distinct inputs in [`collision.json`](../collision.json) collide in the first 48 bits (six bytes, or 12 leading hexadecimal digits) of Keccak-256, satisfying lambda = 24.

| Field | Value |
| --- | --- |
| inputA (hex-encoded bytes) | `0x8375360100000000` |
| inputB (hex-encoded bytes) | `0x7131040200000000` |
| Keccak-256(inputA) | `8851a59bbb9d6231d46ab9566296d3aed4afb5cd4212a1f68a094142b0366868` |
| Keccak-256(inputB) | `8851a59bbb9d27a12c8340ba34a0ac8820e6315e00542945f74d66f4ef53a9b1` |
| Shared 48-bit MSB prefix | `8851a59bbb9d` |

The inputs each decode to eight bytes. The `0x` marker and hexadecimal characters are not hashed as text. Their full 256-bit digests differ.

## Method and attributable evidence

A deterministic birthday search enumerated eight-byte little-endian counters from zero. [`tools/search.js`](../tools/search.js) used the vendored [js-sha3 v0.9.3 implementation](https://github.com/emn178/js-sha3/tree/v0.9.3), recording the first four digest bytes in a hash table and checking the next two bytes on candidate matches. It found this pair after 33,829,234 distinct candidates in 288.823 seconds. This count excludes extra hash evaluations used to recheck table matches. The actual search output is preserved in [`search-result.json`](search-result.json).

A separate implementation recomputed both full digests: Gilles Van Assche's [XKCP CompactFIPS202.py](https://github.com/XKCP/XKCP/blob/master/Standalone/CompactFIPS202/Python/CompactFIPS202.py), called as `Keccak(1088, 512, input, 0x01, 32)`. The generic sponge function supports this legacy Keccak suffix. The [Keccak team's specification summary](https://keccak.team/keccak_specs_summary.html) describes the permutation, padding, and suffix conventions; SHA3-256 instead uses suffix `0x06`. The code used here is included unchanged under `tools/vendor/`, with source URLs, licenses, and SHA-256 file checksums in its README.

Run the independent implementation check offline from the repository root:

```sh
python3 tools/verify.py
```

The command exited successfully. Its output is preserved in [`verification.json`](verification.json). It checks the exact JSON field set, algorithm, lambda, input decoding, distinct input bytes, and equality of the first six digest bytes. It also passes known-answer checks for empty input and `abc`. Negative checks rejected a noncollision, identical inputs, an extra JSON field, malformed hexadecimal input, and a wrong algorithm identifier.

## Interpretation and limits

The matching prefix is an observed computation, not a probability estimate or a fabricated candidate. Agreement between two different implementations provides local evidence for the requested collision. No claim is made of a full Keccak-256 collision.

The external SIMD verifier was not available or run in this session; its acceptance remains unobserved. These recorded checks have no independent reviewer authority. All implementation dependencies needed for offline reproduction are ordinary included source files; Python 3 is required for verification, and Node.js for repeating the search.
