# RIPEMD-160 collision truncated to 48 bits

The requested collision is saved in [collision.json](../collision.json). The `0x` strings encode raw bytes; they are not hashed as UTF-8 text.

| Field | Input A | Input B |
| --- | --- | --- |
| Input bytes (hex) | `19bef10000000000` | `1022730100000000` |
| Full RIPEMD-160 digest | `902e5fc86be47b1e2a17de2aab65d4e765623a05` | `902e5fc86be4a99253faddc650510cb85e77233d` |
| First 48 bits, MSB (first six digest bytes) | `902e5fc86be4` | `902e5fc86be4` |

## Method and attributable evidence

A local C search called OpenSSL's `RIPEMD160` function on consecutive unsigned counters encoded as eight little-endian bytes, starting at zero. It stored the first six digest bytes in a hash table and stopped at the first duplicate. The matching counters were 15,842,841 and 24,322,576; the search performed 24,322,577 hash evaluations.

On 2026-10-05, the exact bytes above were checked using both Python `hashlib.new('ripemd160', data)` and the `openssl dgst -ripemd160` command. Both returned the full digest values in the table. Assertions confirmed that the inputs differ and their first six digest bytes agree. The installed command reported OpenSSL 3.0.13. These are local observations, not externally certified results. Both verification interfaces use OpenSSL, so their agreement is not evidence from independent cryptographic implementations.

The following reproduces the content and behavior check from the delivered JSON in an environment whose Python supports RIPEMD-160:

```python
import hashlib
import json
from pathlib import Path

p = json.loads(Path('collision.json').read_text())
assert set(p) == {'algo', 'lambda', 'inputA', 'inputB'}
assert p['algo'] == 'ripemd160' and p['lambda'] == 24
inputs = [bytes.fromhex(p[k][2:]) for k in ('inputA', 'inputB')]
assert inputs[0] != inputs[1]
digests = [hashlib.new('ripemd160', x).hexdigest() for x in inputs]
assert digests[0][:12] == digests[1][:12] == '902e5fc86be4'
for digest in digests:
    print(digest)
```

## Conclusion and limits

The observed digests establish a collision for the specified 48-bit truncation (`lambda = 24`). Their remaining bits differ; this is not a full RIPEMD-160 collision. No statistical inference is needed for the equality check. The external SIMD verifier has not been run here, and its interpretation and result remain unconfirmed. Local checks carry no independent authority.
