# SHA-256 collision truncated to 48 bits

The requested collision was found and verified locally. The deliverable is
[`../collision.json`](../collision.json), with exactly the four requested fields.
Both inputs use `0x` hexadecimal byte encoding, not the UTF-8 bytes of their
displayed strings.

## Computed evidence

| Value | Input A | Input B |
| --- | --- | --- |
| Input bytes (hex) | `bc201a0000000000` | `1833c70100000000` |
| Full SHA-256 | `2cf3eca701455ab0e389b24dfde1b77792816413a99905675280fdeaf9d8a699` | `2cf3eca70145a3bbedeb37083a53563ad127435c9da75d4043e7757969623573` |
| First 48 bits (six leading digest bytes) | `2cf3eca70145` | `2cf3eca70145` |

These are measured results from the local search and verifier, not assumed
hash values. The distinct decoded byte strings and equal six-byte prefixes
establish the requested truncated collision. The full digests differ.

## Attribution and reproduction

The search implementation is [`../tools/find_collision.cpp`](../tools/find_collision.cpp).
It uses the installed OpenSSL 3.0.2 SHA256 function. It hashes 33,554,432
eight-byte little-endian integers in the first batch, sorts their 48-bit
prefixes, then recovers and rehashes the matching inputs. It found this pair
in that first batch.

The separate check is [`../tools/verify_collision.py`](../tools/verify_collision.py),
which uses Python's `hashlib.sha256` and checks the exact JSON field set,
algorithm, lambda, distinct decoded inputs, and equality of the leading six
digest bytes. Running it returned exit status 0 and:

```text
Shared first 48 bits: 2cf3eca70145
PASS: distinct inputs, exact schema, matching 48-bit MSB prefixes
```

Recheck the delivered file offline:

```sh
python3 tools/verify_collision.py
```

Optional search reproduction (requires an installed C++ compiler and OpenSSL
development library; these are not needed to consume the JSON):

```sh
mkdir -p test/scratch
g++ -O3 tools/find_collision.cpp -lcrypto -o test/scratch/find_collision
test/scratch/find_collision > test/scratch/reproduced.json
```

## Limits and remaining uncertainty

This is a collision for the specified 48-bit MSB truncation, not for full
SHA-256. All evidence above is attributable to this local execution. The
Python check is a separate verification path, but no independent reviewer
or SIMD verification was run in this environment. The external verifier's
acceptance remains unanswered; local results carry no independent authority.
There are no external research claims or citations required for these
directly computed values.
