# Keccak-256 first-48-bit collision (λ = 24)

A collision was found and verified locally. The required machine-readable result is [collision.json](../collision.json). Hex inputs denote raw bytes, not the UTF-8 characters of the hex strings.

| Item | Value |
| --- | --- |
| Input A (8 bytes) | `0x8375360100000000` |
| Input B (8 bytes) | `0x7131040200000000` |
| Keccak-256(A) | `8851a59bbb9d6231d46ab9566296d3aed4afb5cd4212a1f68a094142b0366868` |
| Keccak-256(B) | `8851a59bbb9d27a12c8340ba34a0ac8820e6315e00542945f74d66f4ef53a9b1` |
| Shared first 48 bits, MSB | `8851a59bbb9d` |

## Evidence and method

The local [C search implementation](../tools/search.c) enumerated eight-byte little-endian counters starting at zero, storing hash fingerprints in a birthday-search table and checking all six prefix bytes before accepting a candidate. It found counters 20,346,243 and 33,829,233 after 33,829,234 candidate evaluations, plus additional evaluations to check table matches. It uses Keccak-256's `0x01` domain suffix and 136-byte rate.

The [bundled Python verifier](../tools/verify.py) independently recomputes the digests with a differently structured permutation implementation. It checks the exact JSON key set, algorithm, integer lambda, distinct decoded inputs, and equality of the first six digest bytes. Its captured output is [verification.json](verification.json).

Local cross-checks also recomputed both submitted digests using the environment's PyCryptodome 3.23.0 `Crypto.Hash.keccak`; both matched the bundled verifier exactly. The C implementation matched PyCryptodome on five counter inputs. The Python implementation matched PyCryptodome on ten input lengths, including padding boundaries and multiple blocks (0, 1, 8, 32, 135, 136, 137, 271, 272, and 1000 bytes). The bundled verifier also checks fixed empty-string and `abc` test vectors.

## Reproduction and limits

Run `python3 tools/verify.py` from the repository root. This check uses only the Python standard library and requires no network or installed packages. The optional C search can be built with `cc -O3 tools/search.c -o /tmp/keccak-collision-search` and rerun with `/tmp/keccak-collision-search`; it uses a 512 MiB table and stops after 50 million candidates if unsuccessful.

The observed bytes establish a collision of the first 48 bits only; the complete 256-bit digests differ. These are local computational results, not an independent review or a SIMD verifier result. SIMD verification has not been run in this environment. No claimed hash values are estimates, and no external research claims are needed for this result. PyCryptodome was used only as an additional local check and is not a dependency of the delivered verifier.
