# RIPEMD-160 first-48-bit collision

The requested collision was found. The exact deliverable is
[`collision.json`](../collision.json), with `algo` equal to `ripemd160` and
`lambda` equal to 24. Inputs below are hexadecimal encodings of eight raw bytes.

| Value | Input A | Input B |
|---|---|---|
| Input | `0xd5a30b0100000000` | `0xf30dac0100000000` |
| Full RIPEMD-160 digest | `701296ae0b3717c357ba2d5340e1ef85b9ef25a0` | `701296ae0b377c964cd6fc566b79717d1236c391` |
| First 48 bits (six leading bytes) | `701296ae0b37` | `701296ae0b37` |

## Method and attributable local evidence

A local C search used OpenSSL 3.0.13's RIPEMD160 function to hash 33,554,432
inputs: integers 0 through 33,554,431 encoded as unsigned eight-byte
little-endian values. Sorting by the first six digest bytes found a match at
integers 17,540,053 and 28,052,979. No dependencies were installed.

The delivered [verification script](verify.py), run with
`python3 artifacts/verify.py`, checked the JSON fields, algorithm and lambda,
decoded both inputs, asserted distinctness, recomputed their full digests using
Python hashlib, and asserted equality of the first six bytes. It exited
successfully with:

```text
inputA bytes: d5a30b0100000000
inputB bytes: f30dac0100000000
RIPEMD160(A): 701296ae0b3717c357ba2d5340e1ef85b9ef25a0
RIPEMD160(B): 701296ae0b377c964cd6fc566b79717d1236c391
PASS: distinct inputs; shared first 48 bits: 701296ae0b37
```

A separate local recomputation called libgcrypt 1.10.3's
`gcry_md_hash_buffer` through Python ctypes, selecting RIPEMD160 using
`gcry_md_map_name`. Both full digests matched the values above byte for byte.
This provides a second library implementation check; hashlib and the search
both use OpenSSL and are not independent implementations of one another.

## Findings and limits

Observed facts: the decoded inputs differ, their computed six-byte prefixes
are equal, and their full digests differ. These observations establish the
requested truncated collision under the tested implementations. This is not
a full RIPEMD-160 collision.

The evidence is local execution, not an external citation or independent
reviewer's certification. The assignment's SIMD verifier was not available
or run locally; its eventual acceptance remains unobserved. No statistical
claim or inference is needed to establish this particular collision.
