# RIPEMD-160 collision, truncated to 48 bits (lambda = 24)

A collision was found and locally verified on 2026-10-05. The required machine-readable result is [collision.json](../collision.json):

```json
{"algo":"ripemd160","lambda":24,"inputA":"0x4b3fd300","inputB":"0x942def00"}
```

## Observed facts

The `0x` values denote raw hexadecimal bytes, not the UTF-8 text of those values. Each input is four bytes, including its final zero byte; no newline is hashed.

| Input | Bytes (hex) | Full RIPEMD-160 digest |
| --- | --- | --- |
| A | `4b3fd300` | `a753ebe0c45aae16f469e0777f027348ee2bd8d0` |
| B | `942def00` | `a753ebe0c45ac7e92464fbe55b9f6a6e260405f5` |

The first six bytes of both digests are `a7 53 eb e0 c4 5a`. These are the first 48 bits, read from the left of the standard digest hex representation. The decoded inputs differ, and the full 160-bit digests differ.

## Attributable evidence and reproduction

The [self-contained C search](../tools/find_collision.c) enumerated unsigned counters as four-byte little-endian messages and compared their six-byte digest prefixes. It found counters **13,844,299** and **15,674,772** after **15,674,773 distinct candidates**, starting at zero. The [search log](search.txt) records 3.564 CPU seconds on the local ARM64 machine. Before searching, all 20 digest bytes from this C implementation matched Python `hashlib` for 108 inputs: eight boundary values and 100 pseudorandom values generated with `random.Random(160)`.

The delivered [verification script](../tools/verify_collision.py) separately recomputed both complete digests using Python `hashlib` and the `openssl dgst -ripemd160 -binary` command (LibreSSL 3.3.6). Both paths agreed. It also checked the exact JSON field set, algorithm, integer lambda, distinct decoded inputs, and equality of the first six digest bytes. The successful output is preserved in [verification.txt](verification.txt).

Run from the repository root, without network access:

```sh
python3 tools/verify_collision.py
```

To reproduce the deterministic search, using a C compiler and approximately 512 MiB for its hash table:

```sh
mkdir -p test/scratch
cc -O3 -std=c11 -Wall -Wextra -Werror tools/find_collision.c -o test/scratch/find_collision
test/scratch/find_collision > test/scratch/reproduced.json
python3 tools/verify_collision.py test/scratch/reproduced.json
```

SHA-256 of the delivered `collision.json`, including its final newline:

```text
97e7fb4dc0cb7a150ec251aae13638f673e8535c86372094199b03608fccb12a
```

## Conclusion and limits

The observed digest equality establishes the requested **48-bit truncated collision** for lambda 24. It does not establish a collision in full RIPEMD-160.

All evidence above comes from local computations. The Python and command-line checks are separate verification paths, but their underlying libraries may share implementation ancestry. No external SIMD verifier or independent reviewer was run, so its acceptance remains unobserved. No unanswered question remains about the local byte comparison.
