# Report: collision on SHA-256 truncated to 48 bits (λ=24)

## Answer
`collision.json`:
```json
{"algo":"sha256","lambda":24,"inputA":"imd-12192837","inputB":"imd-19093962"}
```
Both inputs are UTF-8 strings with no trailing newline.

## Evidence (facts, reproduced locally on 2026-10-05)
| Input (UTF-8) | Full SHA-256 |
|---|---|
| `imd-12192837` | `c94563ba4883`4c66186fe07f1f2233f777eed615e843ce03144ade7e659074d9 |
| `imd-19093962` | `c94563ba4883`0d17ce781584012f36b6502808166df0a05236829c7c1c062211 |

- The first 6 bytes (48 bits) are `c94563ba4883` for both. The digests differ starting at bit 49.
- Two separate implementations agree on these digests: Python `hashlib.sha256` and GNU coreutils `sha256sum` (`printf imd-12192837 | sha256sum`).
- A check script loaded `collision.json` and asserted that its keys are exactly `algo, inputA, inputB, lambda`, that the inputs are different, and that the 48-bit prefixes are equal. It printed OK.

## Method
This is a plain birthday search (`tools/find_collision.py`). It hashes `imd-0`, `imd-1`, … and stores each 48-bit prefix in a dict until a prefix repeats. The repeat came after 19,093,963 hashes, about 2^24.19, in roughly 10 seconds. Theory predicts about √(π/2 · 2^48) ≈ 2^24.3 ≈ 2.1×10^7 hashes on average, so this run is in line with the stated birthday cost of about 2^24. The search is deterministic, so running it again gives the same pair.

## Inferences
- The verifier says it "recomputes by SIMD". I am assuming it hashes the UTF-8 bytes of a string that does not start with `0x`. Neither input starts with `0x`, so they should not be read as hex.
- "Truncated to 48 bits MSB" is taken to mean the first 6 bytes of the big-endian digest, which is the standard byte order for SHA-256 output (FIPS 180-4, https://csrc.nist.gov/pubs/fips/180-4/upd1/final).

## Uncertainty / open questions
- I have not seen the verifier's exact input-decoding rules. If it trims, normalizes, or treats input another way, the result could differ, but plain ASCII strings make that unlikely.
- This is only a collision on a truncated digest. It does not weaken full SHA-256 in any way.
- No independent reviewer has checked this. All checks above are my own.
