# RIPEMD-160 48-bit collision

The two distinct byte strings in [`collision.json`](../collision.json) have the same first 48 bits of RIPEMD-160. The `0x` values encode raw bytes, not literal UTF-8 text.

| Input | Raw bytes (hex) | Full RIPEMD-160 digest |
|---|---|---|
| A | `19bef10000000000` | `902e5fc86be47b1e2a17de2aab65d4e765623a05` |
| B | `1022730100000000` | `902e5fc86be4a99253faddc650510cb85e77233d` |

The shared MSB prefix is **`902e5fc86be4`** (six bytes, 48 bits). The full digests differ. The task parameter is λ = 24.

## Method and evidence

A local C search called OpenSSL RIPEMD160 on successive positive integers encoded as eight-byte little-endian values. A hash table retained each six-byte digest prefix and its input index. It found indices 15,842,841 and 24,322,576, after 24,322,576 digest evaluations. No probabilistic claim is needed to establish this particular collision.

Both full digests above were then recomputed using Python `hashlib.new("ripemd160", raw_bytes)` and the `openssl dgst -ripemd160` command (OpenSSL 3.6.1). Both interfaces agreed, and assertions checked distinct inputs and equal first twelve digest hex characters. These are locally observed results; the interfaces may share the OpenSSL implementation, so they are not independent cryptographic implementations.

Run `python3 verify.py` from the repository root to check the delivered JSON, its exact field set, input inequality, and digest-prefix equality. This uses Python's standard library and requires its underlying crypto provider to expose RIPEMD-160.

## Limits

This is a collision only for the requested 48-bit truncation, not for full RIPEMD-160. SIMD verification has not been run here; external acceptance remains unconfirmed. The evidence is local recomputation, not independent certification. No web sources or unverified external claims are used.
