# Keccak-256 truncated collision (lambda = 24)

A collision was found for the first 48 bits of Keccak-256. The deliverable is
[`collision.json`](../collision.json); inputs beginning with `0x` represent raw
hexadecimal bytes, not the UTF-8 characters of their hexadecimal spelling.

## Observed evidence

The search evaluated 50,331,648 distinct eight-byte messages, each encoding an
integer in little-endian order. The colliding integers were 20,346,243 and
33,829,233. The complete independently recomputed digests were:

| Input | Keccak-256 digest |
| --- | --- |
| `0x8375360100000000` | `8851a59bbb9d6231d46ab9566296d3aed4afb5cd4212a1f68a094142b0366868` |
| `0x7131040200000000` | `8851a59bbb9d27a12c8340ba34a0ac8820e6315e00542945f74d66f4ef53a9b1` |

Both digests begin with the same six bytes, `8851a59bbb9d`. These are the first
48 bits in conventional digest display order. The input bytes are distinct;
the remaining digest bytes differ. Thus the observed result is a truncated
collision, not a full 256-bit collision.

## Attribution and reproduction

The evidence comes from local execution of the delivered
[`tools/find_collision.cpp`](../tools/find_collision.cpp) search and
[`tools/verify_collision.py`](../tools/verify_collision.py) verifier.
The search uses eight-lane AVX-512 computation and sorting of six-byte digest
prefixes. The verifier uses scalar Python, a different rotation/permutation
implementation, and checks the empty-message and `abc` known-answer vectors
before checking the JSON schema, distinct decoded inputs, and equal prefixes.
Both implement Keccak padding with suffix `0x01` and a 136-byte rate.

Run verification from the repository root, without network or dependencies:

```sh
python3 tools/verify_collision.py
```

To repeat the search on an AVX-512-capable machine with a C++ compiler:

```sh
mkdir -p test/scratch
g++ -O3 -mavx512f -std=c++17 tools/find_collision.cpp -o test/scratch/find_collision
test/scratch/find_collision
```

The local verifier completed successfully. Its output included both full
digests above, `first_48_bits: 8851a59bbb9d`, and `verified: true`.

## Limits

These are local check results attributable to the included programs, not an
independent certification. The network's SIMD verifier was not run here;
its eventual result remains unobserved. There is no claim about collision
resistance of full Keccak-256 or about other truncation lengths.
