# SHA-256 truncated to 48 bits: collision found

The answer is delivered in [`collision.json`](../collision.json), with exactly
the requested four fields. Inputs beginning with `0x` denote decoded hexadecimal
bytes, not the UTF-8 text of the hexadecimal representation. Both inputs are
eight bytes long.

## Observed evidence

| Input | Bytes (hex) | Full SHA-256 digest |
| --- | --- | --- |
| A | `000000000017211c` | `4e84dca19fa699674e41dc0ff0f92046577a96fd3bbc22ae6a036986dc268301` |
| B | `00000000014060cc` | `4e84dca19fa67ad46fd0f73243c0081834a4767ce3fc91b0b4dade47ab574d2e` |

The distinct input bytes produce the same first six digest bytes:
**`4e84dca19fa6`**. Six bytes are 48 bits, corresponding to the requested
lambda of 24. Their full digests differ.

Evidence is attributable to the local execution of
[`tools/find_collision.py`](../tools/find_collision.py) and
[`tools/verify_collision.py`](../tools/verify_collision.py) during this assignment.
The search hashed consecutive eight-byte big-endian counters beginning at zero,
finding the match after **20,996,301 evaluations** in approximately **56.75 seconds**.
The verifier independently recomputed both full digests through Python's
`hashlib.sha256` and the OpenSSL command line (OpenSSL 3.0.13). It checked the exact
JSON field set, algorithm, lambda, distinct decoded inputs, agreement between
the hash interfaces, and equality of the first six digest bytes. It exited
successfully and printed:

```text
PASS: common 48-bit MSB prefix 4e84dca19fa6
```

## Inference and limits

The displayed byte equality establishes a collision for this 48-bit truncation
under the specified hexadecimal decoding. This conclusion follows directly from
the locally computed digests; it does not establish a collision for full SHA-256.

No independent reviewer or SIMD verifier was run here. Python and OpenSSL may
share underlying cryptographic implementation code, so their agreement is not
claimed as two independent cryptographic implementations. The downstream SIMD
acceptance result remains unobserved. No external factual sources are needed for
this computed result; the provided scripts and input bytes permit recomputation.
