# RIPEMD-160 truncated collision (λ = 24)

The delivered [collision.json](../collision.json) contains two distinct eight-byte inputs whose RIPEMD-160 digests share the first 48 bits. The `0x` values represent raw hexadecimal bytes, not UTF-8 strings containing hexadecimal characters.

| Input | Raw bytes (hex) | Full RIPEMD-160 digest |
|---|---|---|
| A | `19bef10000000000` | `902e5fc86be47b1e2a17de2aab65d4e765623a05` |
| B | `1022730100000000` | `902e5fc86be4a99253faddc650510cb85e77233d` |

**Observed result:** Both digests start with `902e5fc86be4`, exactly six bytes (48 bits), taken from the start of the digest in its conventional hexadecimal representation. The complete digests differ.

## Method and attributable evidence

The local [search source](search.c) enumerated unsigned integers encoded as eight-byte little-endian messages. It computed RIPEMD-160 using the installed OpenSSL library and stored six-byte digest prefixes in a hash table. It found the matching indices 15,842,841 and 24,322,576 after 24,322,577 evaluations, including index zero.

The delivered [verification script](verify.py) recomputes both digests from `collision.json`, checks the exact field set, algorithm, λ, distinct decoded inputs, and matching first six digest bytes. Run from the repository root:

```sh
python3 artifacts/verify.py
```

Recorded local output:

```text
inputA digest: 902e5fc86be47b1e2a17de2aab65d4e765623a05
inputB digest: 902e5fc86be4a99253faddc650510cb85e77233d
PASS: distinct inputs; shared 48-bit MSB prefix: 902e5fc86be4
```

OpenSSL 3.0.13 command-line recomputation on the decoded binary inputs also returned the full digests shown above. The search can be reproduced in an environment with a C compiler and `libcrypto.so.3`:

```sh
cc -O3 artifacts/search.c -Wl,-l:libcrypto.so.3 -o /tmp/ripemd160-search
/tmp/ripemd160-search
```

## Limits

These are local computational observations, not an independent SIMD verdict. Python hashlib and the OpenSSL command line use the same underlying cryptographic implementation in this environment, so the two checks do not establish implementation independence. The verifier's SIMD recomputation has not been run here. No claim is made of a collision for the full 160-bit digest. No external factual sources or probabilistic inference are needed for the byte equality reported here.
