# RIPEMD-160 collision, first 48 bits (λ = 24)

A collision was found and locally verified. The requested four-field output is [collision.json](../collision.json). Inputs use `0x` hex encoding and must be decoded to bytes before hashing; they are not the ASCII representations of the hex strings.

| Field | Input A | Input B |
| --- | --- | --- |
| Input (8 bytes) | `0x19bef10000000000` | `0x1022730100000000` |
| Full RIPEMD-160 digest | `902e5fc86be47b1e2a17de2aab65d4e765623a05` | `902e5fc86be4a99253faddc650510cb85e77233d` |
| First 48 bits (6 bytes, MSB) | `902e5fc86be4` | `902e5fc86be4` |

The inputs are distinct. The first twelve hexadecimal digits of their digests match exactly. Their full digests differ, so this is a collision only for the specified truncation.

## Attributable evidence and reproduction

The [search program](../tools/find_collision.py) enumerated unsigned integers encoded as eight little-endian bytes, starting at zero, and retained the first six digest bytes in a lookup table. It found indices 15,842,841 and 24,322,576 after 24,322,577 candidate evaluations. The recorded search duration was approximately 44.53 seconds. These measurements come from the local execution, preserved in [search_result.json](search_result.json).

The [verification program](../tools/verify_collision.py) read the saved JSON, checked its exact keys and parameters, decoded both inputs, checked distinctness, and recomputed both digests with Python `hashlib`. It passed. Reproduce from the repository root with:

```sh
python3 tools/verify_collision.py
```

Both byte strings were also supplied separately to `openssl dgst -ripemd160` through standard input. OpenSSL 3.5.5 returned the full digests shown above; its captured outputs are in [verification.json](verification.json). Python and the OpenSSL command may share the same cryptographic implementation, so these checks do not constitute independent implementation validation.

To repeat the entire search, run `python3 tools/find_collision.py` from the repository root. It requires Python with RIPEMD-160 available through `hashlib` and several gigabytes of memory. No downloaded dependencies were installed or are required by the submitted solution. Verification of the existing pair is immediate and does not require repeating the search.

## Scope and uncertainty

The matching prefix and distinct inputs are observed local results, not estimated collision candidates. The conclusion follows directly from those recomputed bytes. SIMD verification was not available in this workspace and has not been claimed. Local checks have no independent authority; the downstream verifier must recompute the digest using the specified hex decoding and MSB truncation. No claim is made about a full 160-bit collision.
