# Keccak-256 truncated collision (lambda = 24)

## Result

The two distinct eight-byte inputs in `collision.json` have matching first
48 bits of Keccak-256. Local recomputation on 2026-10-05 produced:

| Field | Input A | Input B |
| --- | --- | --- |
| Hex-encoded bytes | `0x8375360100000000` | `0x7131040200000000` |
| Full digest | `8851a59bbb9d6231d46ab9566296d3aed4afb5cd4212a1f68a094142b0366868` | `8851a59bbb9d27a12c8340ba34a0ac8820e6315e00542945f74d66f4ef53a9b1` |
| First six digest bytes (48 bits MSB) | `8851a59bbb9d` | `8851a59bbb9d` |

`0x` denotes hex encoding of raw bytes; it is not part of the hashed message.
The prefix is taken from the serialized digest in its displayed byte order.

## Method and attributable evidence

The included [`search.c`](../search.c) hashes consecutive unsigned counters
encoded as eight little-endian bytes, starting at zero. It uses the complete
24-round Keccak-f[1600] permutation, rate 1088 bits, capacity 512 bits, and
original Keccak padding. It stores the first six output bytes in a hash table
and stops when another input has the same prefix. Its recorded output was:

```text
A=0x8375360100000000
B=0x7131040200000000
evaluations=33829234
```

The permutation, sponge, and padding are described by the designers in the
[Keccak reference, version 3.0](https://keccak.team/files/Keccak-reference-3.0.pdf).
Their [specification summary](https://keccak.team/keccak_specs_summary.html)
also describes the permutation and the delimited suffix convention. Original
Keccak here uses suffix byte `0x01`; SHA3-256 uses `0x06`.

The separate [`verify.py`](../verify.py) implementation uses a two-dimensional
lane matrix rather than the searcher's in-place lane cycle. Running
`python3 -B verify.py` exited successfully and produced the full digests above.
The machine-readable result is saved in [`verification.json`](verification.json).
Its assertions check the exact JSON field set and parameters, distinct decoded
inputs, and equality of the first six bytes. It also passes the empty-message
and `abc` Keccak-256 vectors, plus nine comparisons with Python's
`hashlib.sha3_256` using suffix `0x06`, at lengths 0, 1, 8, 135, 136, 137, 271,
272, and 1000 bytes. The SHA3 comparisons support the permutation and absorption
implementation, while the Keccak vectors check the original padding mode.

## Facts, inference, and limits

Observed local facts: the search reported the above inputs after 33,829,234
evaluations; the separately written verifier returned identical six-byte
prefixes and different full digests. The conclusion that this is the requested
48-bit collision follows directly from those recomputed bytes, subject to the
correctness of the local implementations.

This is not a full 256-bit collision. No SIMD verifier or external reviewer was
run in this environment, so independent acceptance remains unobserved. Local
checks do not carry independent authority. All verification dependencies are
Python standard-library modules; no network, downloaded compiler, search table,
or scratch files are needed to verify the delivered JSON.
