# SHA-256 first-48-bit collision

The requested collision is provided in [collision.json](../collision.json). Both inputs are hexadecimal encodings of eight raw bytes; the `0x` prefix is notation and is not hashed.

| Input | Full SHA-256 digest |
| --- | --- |
| `0x000000000017211c` | `4e84dca19fa699674e41dc0ff0f92046577a96fd3bbc22ae6a036986dc268301` |
| `0x00000000014060cc` | `4e84dca19fa67ad46fd0f73243c0081834a4767ce3fc91b0b4dade47ab574d2e` |

**Observed result:** the byte strings differ, and both digests begin with `4e84dca19fa6`. These twelve hexadecimal digits encode the first 48 bits in most-significant-bit order. Thus the pair satisfies the requested truncation with lambda = 24. The full digests differ.

**Method:** locally hashed 33,554,432 distinct eight-byte, big-endian counter encodings, starting at zero, using the installed OpenSSL SHA-256 implementation. Sorted their 48-bit prefixes and found this matching pair.

**Attributable evidence:** the digests above were recomputed locally with Python's `hashlib.sha256` and separately with the installed `openssl dgst -sha256` command. Both produced the displayed values. The submitted [verification script](../tools/verify_collision.py) checks the exact JSON keys, algorithm, lambda, distinct decoded bytes, and matching digest prefixes. Run from any directory with `python3 tools/verify_collision.py` using the repository-relative path. The check reported:

```text
PASS: distinct inputs share the first 48 bits: 4e84dca19fa6
```

**Limits and uncertainty:** these are reproducible local checks, not an independent review or a SIMD verifier result. Python and the OpenSSL command may share a cryptographic backend. No claim is made that the full SHA-256 digests collide. The external SIMD acceptance result remains unobserved; no uncertainty remains in the locally checked prefix equality.
