# Keccak-256 collision in the first 48 bits (λ = 24)

A collision was found and locally verified. [collision.json](../collision.json) contains raw hexadecimal byte strings, not UTF-8 text containing the hexadecimal characters.

| Field | Value |
| --- | --- |
| inputA (8 bytes) | `0x8375360100000000` |
| inputB (8 bytes) | `0x7131040200000000` |
| Keccak-256(inputA) | `8851a59bbb9d6231d46ab9566296d3aed4afb5cd4212a1f68a094142b0366868` |
| Keccak-256(inputB) | `8851a59bbb9d27a12c8340ba34a0ac8820e6315e00542945f74d66f4ef53a9b1` |
| Shared first 48 bits | `8851a59bbb9d` |

## Method and evidence

The self-contained [C search](../src/search.c) enumerated integers from zero, encoded as eight little-endian bytes. It stored six-byte digest prefixes in a hash table and found this pair after 33,829,234 evaluations. It uses Keccak-f[1600] with 24 rounds, a 1088-bit rate, a 512-bit capacity, and original Keccak padding suffix `0x01`. The suffix follows the empty trailing-bit case in the [Keccak authors' specification summary](https://keccak.team/keccak_specs_summary.html). SHA3-256 uses a different suffix.

The separate [Python verifier](../src/verify.py) uses coordinate-based permutation steps and generates round constants with an LFSR. It checks the exact JSON fields, distinct decoded inputs, known-answer vectors for the empty message and `abc`, and equality of the first six digest bytes. Run offline with the Python standard library:

```sh
python3 src/verify.py
```

[Recorded local verification](verification.txt) includes full digests and an additional check using the installed OpenSSL 3.5.5 Keccak-256 implementation. Both full digests matched between Python and OpenSSL. Comparisons at message lengths 0, 1, 8, 135, 136, 137, 272, and 1000 bytes also passed, including padding boundaries and multiple blocks. The delivered verifier does not require OpenSSL or installed packages.

Reproduce the search with a C compiler:

```sh
mkdir -p test/scratch
cc -O3 src/search.c -o test/scratch/search
./test/scratch/search > test/scratch/reproduced.json
cmp collision.json test/scratch/reproduced.json
```

The search allocates approximately 768 MiB for its hash table. Checking the supplied pair does not require rerunning the search.

## Facts, inference, and limits

Observed facts: the decoded inputs differ; their full digests differ; their first six digest bytes match. The conclusion is a collision for the requested 48-bit truncation, not a full 256-bit collision. No probabilistic assumption is needed to compare this concrete pair.

This evidence comes from local execution and separate implementations, not an independent reviewer. The external SIMD verifier was not available or run here; its eventual result remains unobserved.
