The requested 48-bit Keccak-256 prefix collision was found and verified locally.
The exact submission is [collision.json](../collision.json), with exactly the four
requested keys and lambda = 24. Inputs use hexadecimal byte encoding; the literal
characters `0x` are not hashed.

| Field | Computed value |
|---|---|
| inputA | `0x21777c0300000000` |
| inputB | `0x7c07d30300000000` |
| Keccak-256(inputA) | `de79868ee98d13a795141c8199c2738dd9598f9551ac24b1f8af7905053a3db5` |
| Keccak-256(inputB) | `de79868ee98dedfc4ce0c5e025c120952ba58728aa18a497f5ba1086098e40f3` |
| Shared first 48 bits (six digest bytes, MSB prefix) | `de79868ee98d` |

These are observed computations, not estimated digests. The two eight-byte inputs
are distinct, and the full digests differ after their matching prefix.

The birthday search hashed sequential eight-byte little-endian counters and stored
48-bit prefixes in an open-addressed table. Counters 0 through 33,554,431 produced
no match within that range. The second run started at 33,554,432 and found counters
58,488,609 and 64,161,660 after 30,607,229 evaluations in that run: 64,161,661 total
search evaluations across both runs. The table was reset between runs, so matches
between different ranges were not tested. The first run used loops; the second
used equivalent unrolled round operations to reduce execution time.

Verification executed successfully:

- `python3 tools/verify.py`: exact schema and parameters, distinct decoded inputs,
  matching first six bytes, and agreement of both full digests with the bundled
  XKCP reference implementation. Both implementations also passed known-answer
  checks for empty input and `abc`.
- Twelve differential Python checks at message lengths 0, 1, 7, 8, 32, 134, 135,
  136, 137, 271, 272, and 4096 bytes, including rate-boundary cases: passed.
- 105 comparisons of the unrolled C search's prefix computation with the Python
  verifier, including range endpoints and 100 consecutive counters: passed.

The final verification output is preserved in [verification.txt](verification.txt).
The search progress is preserved in [search-first.txt](search-first.txt) and
[search-success.txt](search-success.txt). Reproduce the successful range with
`python3 tools/run_search.py 33554432`. Verify the result without searching with
`python3 tools/verify.py`. All added dependencies are bundled as ordinary files;
verification requires only Python 3 and no network. Search reproduction uses the
bundled Linux amd64 TCC compiler and the host Python/glibc runtime.

The permutation and padding conventions follow the
[Keccak team's specification summary](https://keccak.team/keccak_specs_summary.html).
The verifier uses rate 1088, capacity 512, 32 output bytes, and suffix `0x01` for
Keccak-256. SHA3-256 uses a different suffix. The separately authored cross-check is
[Gilles Van Assche's XKCP implementation, pinned to commit 4affab454735d54e78156880b3b44e38dcbf765c](https://github.com/XKCP/XKCP/blob/4affab454735d54e78156880b3b44e38dcbf765c/Standalone/CompactFIPS202/Python/CompactFIPS202.py),
included unmodified with its CC0 waiver. Dependency provenance and checksums are in
[PROVENANCE.md](../tools/vendor/PROVENANCE.md).

The evidence establishes a locally recomputed 48-bit prefix collision, not a full
256-bit collision. There is no probabilistic inference needed to compare the
displayed prefixes. These checks were performed by this contributor and carry no
independent reviewer authority. SIMD's separate recomputation has not been run
here; its acceptance remains unobserved. No other unanswered question is needed
to reproduce the local result.
