# SHA-256 collision for the first 48 bits

The requested collision is delivered in `collision.json`, with `algo` set to `sha256` and `lambda` set to 24. The `0x` strings encode raw bytes, not literal UTF-8 text.

| Input | Raw bytes (hex) | Full SHA-256 digest |
| --- | --- | --- |
| A | `e8f1380000000000` | `67171c0eb1922b1b1e7b76dd2213a661d3542f3c6b00e39279800abaaf50b502` |
| B | `23f68e0000000000` | `67171c0eb192a147eff93d18c3adf2a803bba554778ef76416669125a3a46e19` |

Both digests begin with `67171c0eb192`: twelve hexadecimal digits, or 48 most-significant bits. The inputs are distinct eight-byte values. Their full digests differ.

## Method and attributable evidence

A local C program enumerated integers starting at zero, encoded each integer as eight little-endian bytes, computed SHA-256 using OpenSSL, and stored the first six digest bytes in a hash table. It found the pair at integers 3,731,944 and 9,369,123 after 9,369,124 evaluations.

Python's `hashlib.sha256` recomputed both full digests from the raw bytes. The OpenSSL 3.0.13 command-line tool separately recomputed both digests and matched Python's results. Assertions checked distinct inputs and equal 48-bit prefixes. These are locally observed results, not an independent review or a SIMD verifier verdict.

Reproduce the essential verification offline with Python 3:

```python
import hashlib
import json
from pathlib import Path

p = json.loads(Path('collision.json').read_text())
assert set(p) == {'algo', 'lambda', 'inputA', 'inputB'}
assert p['algo'] == 'sha256' and p['lambda'] == 24
raw = [bytes.fromhex(p[k][2:]) for k in ('inputA', 'inputB')]
assert raw[0] != raw[1]
digests = [hashlib.sha256(x).hexdigest() for x in raw]
assert digests[0][:12] == digests[1][:12] == '67171c0eb192'
print(*digests, sep='\n')
```

## Limits

The measured bytes and digests establish the truncated collision under hex decoding. No inference about a full 256-bit SHA-256 collision is made. The external SIMD verification has not been run here; its result remains unobserved. No network sources or external factual claims are needed for this direct computation.
