# Keccak-256 collision, λ = 24

A collision for the first 48 bits was found and verified locally on 2026-10-05.
The deliverable is [`collision.json`](../collision.json), with exactly the four
requested fields:

```json
{"algo":"keccak256","lambda":24,"inputA":"0x8375360100000000","inputB":"0x7131040200000000"}
```

## Observed evidence

Both inputs are distinct eight-byte sequences decoded from hex. The separately
authored XKCP reference implementation produced these full digests:

| Input | Keccak-256 digest |
| --- | --- |
| `0x8375360100000000` | `8851a59bbb9d6231d46ab9566296d3aed4afb5cd4212a1f68a094142b0366868` |
| `0x7131040200000000` | `8851a59bbb9d27a12c8340ba34a0ac8820e6315e00542945f74d66f4ef53a9b1` |

The first six bytes (the leftmost 12 hexadecimal digits, or 48 MSB bits) of
both digests are **`8851a59bbb9d`**. The full digests differ.

[`verification.json`](verification.json) records the computed values and source
checksum. [`src/verify.py`](../src/verify.py) checks the exact JSON fields,
algorithm, integer lambda, decoded-input distinctness, and six-byte prefix
equality. It also passed two legacy Keccak regression vectors and five SHA3
cross-checks against Python's `hashlib`, using the SHA3 suffix only for those
cross-checks. Verification can be repeated without network access:

```sh
python3 src/verify.py
```

## Method and attribution

[`src/search.c`](../src/search.c) enumerated eight-byte little-endian counters
starting at zero. It computed Keccak-256 prefixes in parallel batches of 65,536
and inserted results in counter order into a hash table. Counters **20,346,243**
and **33,829,233** matched. Including the rest of the final computed batch,
**33,882,112** hashes were evaluated; **33,829,234** were examined for matches.
The local run took approximately **34 seconds**, as recorded in
[`search.log`](search.log). These counts and timing describe this run, not a
guarantee for other machines or input sequences.

The permutation and padding follow the
[Keccak team's specification summary](https://keccak.team/keccak_specs_summary.html).
Verification uses its
[readable and compact XKCP implementation at revision ed74f214](https://github.com/XKCP/XKCP/blob/ed74f214391ec1ce285c20e71aa01cd314244016/Standalone/CompactFIPS202/C/Keccak-readable-and-compact.c),
vendored unchanged with its attribution and CC0 notice. The generic sponge is
configured with rate 1088, capacity 512, a 32-byte output, and suffix `0x01`
(legacy Keccak, no appended domain bits). SHA3-256 instead uses suffix `0x06`.
These parameters and the suffix distinction are documented in that reference
source. The local source checksum is recorded in
[`vendor/README.md`](../vendor/README.md).

## Conclusion and limits

The observed digest equality satisfies the requested 48-bit collision condition
under hex-to-bytes decoding. This is a truncated collision, not a collision of
the full 256-bit digest. The birthday-search rationale is a heuristic; the
reported pair is supported by direct recomputation rather than that heuristic.

These are local checks using a separate implementation, not independent review.
The external SIMD verifier was not available or run here, so its eventual
acceptance remains unobserved. No other unresolved local verification issue
was identified.
