# SHA-256 48-bit truncated collision (λ=24)

## Answer

```json
{"algo":"sha256","lambda":24,"inputA":"simd-2ed1119e4b80","inputB":"simd-0170dc5eabd6"}
```

Both inputs are UTF-8 (ASCII) strings, 17 bytes each, with no trailing newline.
The same JSON is committed as `collision.json` at the repository root.

## Evidence

| Input (UTF-8) | SHA-256 | First 48 bits |
|---|---|---|
| `simd-2ed1119e4b80` | `1470dfedd885f6fda595296b5c3f6f8dc0f42e0564b2b43d817367b4e2e59a5d` | `1470dfedd885` |
| `simd-0170dc5eabd6` | `1470dfedd88572fe74fa197c5f3e101ba9a422db26aa65bf91eff34ef0b2a868` | `1470dfedd885` |

Reproduce the check:

```sh
printf %s 'simd-2ed1119e4b80' | sha256sum
printf %s 'simd-0170dc5eabd6' | sha256sum
```

Reproduce the search (Python 3 standard library only, about 22 s on this machine):

```sh
python3 tools/find_collision.py
```

## Facts

- The two inputs are distinct strings.
- Their SHA-256 digests agree on the first 6 bytes (48 bits, most significant first) and differ from the 7th byte on.
- The digests were computed twice, with Python 3.12.3 `hashlib` and with coreutils `sha256sum`; both gave the values in the table.
- The search used Floyd cycle finding on `f(x) = first 6 bytes of SHA-256("simd-" + hex(x))`, starting from six zero bytes. It took 54,723,279 hash evaluations (about 2^25.7) and constant memory. The run is deterministic, so rerunning the script yields the same pair.

## Inferences

- The evaluation count is in line with the expected cost of a memoryless birthday search on a 48-bit output (a small multiple of 2^24), so the result says nothing unusual about SHA-256; it is an ordinary generic collision on a truncated digest.

## Uncertainty

- The task allows inputs as "hex 0x... or utf8". I chose UTF-8 strings that do not start with `0x`, on the assumption that the verifier hashes such strings as their raw UTF-8 bytes. If the verifier instead requires hex form, the equivalent values are:
  - inputA: `0x73696d642d326564313131396534623830`
  - inputB: `0x73696d642d303137306463356561626436`
- "Truncated to 48 bits MSB" is read as the first 6 bytes of the digest in its standard big-endian byte order.

## Unanswered questions

- None for the task itself. The SIMD verifier was not available here, so its acceptance of this file is not confirmed.
