# SHA-256 truncated to 48 bits: collision evidence

The requested collision is recorded in [collision.json](../collision.json), with exactly the four requested fields. Both inputs are hexadecimal encodings of eight raw bytes.

| Input | Raw bytes (hex) | Full SHA-256 digest |
| --- | --- | --- |
| A | `e8f1380000000000` | `67171c0eb1922b1b1e7b76dd2213a661d3542f3c6b00e39279800abaaf50b502` |
| B | `23f68e0000000000` | `67171c0eb192a147eff93d18c3adf2a803bba554778ef76416669125a3a46e19` |

**Observed facts:** The input byte strings differ. Both computed digests begin with the same six bytes, `67 17 1c 0e b1 92`, equal to the first 48 bits in most-significant-bit order. The full digests differ.

**Method and attribution:** A local C search used the installed OpenSSL 3.0.13 `SHA256` function. Candidates were successive integers starting at zero, encoded as eight-byte little-endian unsigned values. A hash table indexed digest prefixes and compared six digest bytes before accepting a candidate pair. The search found integers 3,731,944 and 9,369,123 after evaluating 9,369,124 candidate inputs. Scratch search code is temporary and is not part of the delivered evidence.

A separate local computation using Python's standard-library `hashlib.sha256` reproduced both complete digests above. The delivered [verify.py](../verify.py) checks the JSON fields, decodes the hexadecimal inputs, checks byte inequality, and compares the first six digest bytes. Run from the repository with:

```sh
python3 verify.py
```

Observed verification output:

```text
inputA SHA-256: 67171c0eb1922b1b1e7b76dd2213a661d3542f3c6b00e39279800abaaf50b502
inputB SHA-256: 67171c0eb192a147eff93d18c3adf2a803bba554778ef76416669125a3a46e19
Matching first 48 bits: 67171c0eb192
PASS: distinct inputs with matching 48-bit SHA-256 prefixes
```

**Conclusion:** The local computations establish a collision for the specified 48-bit truncation (lambda = 24), using hexadecimal byte decoding.

**Limits and unanswered questions:** This is not a full SHA-256 collision. The verification is local evidence, not independent certification; Python and the C search may share an underlying cryptographic library. The external SIMD verifier has not been run here, so its acceptance remains unobserved. No external factual claims or web sources are needed for this directly reproducible computation.
