# Keccak-256 collision, truncated to 48 bits

## Result

`collision.json` contains two distinct eight-byte inputs, encoded as hex (the `0x` prefix indicates decoded bytes, not literal UTF-8 text):

| Field | Value |
| --- | --- |
| inputA | `0xee62600000000000` |
| inputB | `0xbef60b0300000000` |
| lambda | `24` |
| Shared first 48 bits, MSB | `3fc82665f648` |

Full Keccak-256 digests recomputed locally:

```text
A: 3fc82665f6489d151e686056b06d4966bc39914f8bc4e080721ca720701f4c11
B: 3fc82665f64840951a2d3e46bf6111e71264921338aa56445f74313272f8708a
```

The first six digest bytes match exactly. The full digests differ; the result is a collision only under the requested 48-bit truncation.

## Method and attributable evidence

The local C search in `tools/search.c` enumerated eight-byte little-endian counters, computed original Keccak-256, sorted the six-byte prefixes, and selected adjacent equal prefixes. A search of 33,554,432 inputs found no match. The expanded search of 67,108,864 inputs found the reported pair. These counts overlap: the second search includes the first range.

Keccak-256 uses a 1088-bit rate, 512-bit capacity and original Keccak padding with delimited suffix `0x01`. The [Keccak team's specification summary](https://keccak.team/keccak_specs_summary.html) describes the permutation, sponge construction and suffix encoding; no trailing domain bits implies suffix 1. SHA3-256 instead has suffix `0x06`, so substituting SHA3-256 would answer a different question.

Verification used Gilles Van Assche's [XKCP compact Python implementation](https://github.com/XKCP/XKCP/blob/712fabccd5d611459533d554814e00537742624c/Standalone/CompactFIPS202/Python/CompactFIPS202.py), vendored unchanged at `tools/CompactFIPS202.py`, with its CC0 notice preserved. Its SHA-256 file checksum is:

```text
0b731097a4dfcf33fdaf395ac0bee81c6a6ebff2975590c35ad8cd8d6f3c204f
```

`tools/verify.py` calls `Keccak(1088, 512, inputBytes, 0x01, 32)`. It checks the JSON field set and parameters, decodes the inputs, checks byte inequality, and asserts equality of the first six output bytes. It also checks the empty-string and `abc` Keccak-256 vectors and cross-checks the underlying implementation in SHA3 mode against Python's `hashlib.sha3_256` on four messages, including messages spanning a rate block.

Executed locally with exit code 0:

```sh
python3 tools/verify.py
```

The output is recorded in `artifacts/verification.json`, including both full digests and `verified: true`. The verifier requires only Python 3 and the delivered source, with no network or external package dependencies.

Search reproduction (GCC and OpenMP required):

```sh
mkdir -p test/scratch
gcc -O3 -march=native -fopenmp tools/search.c -o test/scratch/search
OMP_NUM_THREADS=16 test/scratch/search 67108864
```

## Interpretation and limits

Observed facts: the delivered inputs are distinct and the vendored implementation recomputed matching first-six-byte prefixes. Thus the local evidence supports the requested collision. No probabilistic assumption is needed to check this concrete pair.

The checks were performed by this task's agent using a separate implementation from the search code. They are reproducible local evidence, not independent reviewer certification. The external SIMD verifier was not available or run in this session, so its acceptance remains unobserved. No full 256-bit collision or broader cryptographic weakness is claimed.
