# Keccak-256 collision in the first 48 bits

The requested collision is in [`../collision.json`](../collision.json). Both inputs are hexadecimal encodings of exactly eight bytes, not UTF-8 encodings of the displayed characters.

| Value | Result |
| --- | --- |
| inputA | `0x8375360100000000` |
| inputB | `0x7131040200000000` |
| Keccak-256(inputA) | `8851a59bbb9d6231d46ab9566296d3aed4afb5cd4212a1f68a094142b0366868` |
| Keccak-256(inputB) | `8851a59bbb9d27a12c8340ba34a0ac8820e6315e00542945f74d66f4ef53a9b1` |
| Common first 48 bits, MSB | `8851a59bbb9d` |

## Method and attributable evidence

The local birthday search in [`../tools/search.c`](../tools/search.c) enumerated eight-byte little-endian counters starting at zero, computed Keccak-256 with 24 permutation rounds and Keccak padding, and stored six-byte digest prefixes in a hash table. It found the pair after **33,829,234 input evaluations**. This count is the search program's observed output, excluding the two final digest computations.

The separate verifier in [`../tools/verify.cjs`](../tools/verify.cjs) uses the vendored [js-sha3 version 0.9.3 source](https://github.com/emn178/js-sha3/blob/v0.9.3/src/sha3.js), authored by Chen, Yi-Cyuan, under the [MIT license](../tools/sha3.LICENSE.txt). The delivered [`../tools/sha3.js`](../tools/sha3.js) has SHA-256:

```text
6378cc474ad0a0db3e88c0c67b7bd4a154e1b318f44dbbd13927f6e220efaa38
```

Run offline from the repository root:

```sh
node tools/verify.cjs
```

The check passed locally. It validates the exact four JSON keys and requested algorithm/lambda, checks that the decoded bytes differ, and recomputes the full digests shown above using the separate implementation. It also checks the empty-string and `abc` Keccak-256 regression vectors. No installed package or network access is needed for verification.

## Facts, inference, and limits

**Observed facts:** The delivered inputs differ as bytes. The C search and the separate JavaScript implementation produced the same full digests. Their first six bytes are identical. The verifier exited successfully.

**Inference:** These locally recomputed values satisfy the requested 48-bit truncation collision for lambda 24. The full 256-bit digests differ, so the result is a collision only under the requested truncation.

**Uncertainty and unanswered questions:** SIMD's external verification has not been run in this environment. These checks are reproducible local evidence, not independent review or a claim of external acceptance. No uncertainty remains about which bytes this submission intends to hash.
