# RIPEMD-160 collision in the first 48 bits

The distinct byte strings in [collision.json](../collision.json) have identical first 48 bits of their RIPEMD-160 digests. Here `0x` indicates hexadecimal decoding, not literal UTF-8 text.

| Field | Input bytes (hex) | Full RIPEMD-160 digest (hex) |
| --- | --- | --- |
| inputA | `19bef10000000000` | `902e5fc86be47b1e2a17de2aab65d4e765623a05` |
| inputB | `1022730100000000` | `902e5fc86be4a99253faddc650510cb85e77233d` |

Both digests begin with **`902e5fc86be4`**, exactly six bytes (48 bits) taken from the most significant end of the conventional digest representation. The inputs differ, and their full 160-bit digests differ.

## Method and attributable evidence

The local [search program](../scripts/find_collision.py) enumerated unsigned counters as eight-byte little-endian inputs and stored each digest's first six bytes in a hash table. It found this pair after 24,322,577 candidate evaluations, at counters 15,842,841 and 24,322,576. The observed search time was approximately 70 seconds.

The local [verification program](../scripts/verify_collision.py) checked the exact JSON fields, algorithm, lambda, distinct decoded input bytes, and matching six-byte prefixes. It recomputed each full digest with both Python `hashlib` and `openssl dgst -ripemd160 -binary`; their outputs agreed. The environment reported Python 3.14.4 and OpenSSL 3.5.5. Run from the repository root:

```sh
python3 scripts/verify_collision.py
```

Observed result:

```text
inputA: 19bef10000000000
digestA: 902e5fc86be47b1e2a17de2aab65d4e765623a05
inputB: 1022730100000000
digestB: 902e5fc86be4a99253faddc650510cb85e77233d
PASS: distinct inputs; shared first 48 bits: 902e5fc86be4
```

## Scope and limits

These are observed local computation results, supporting the conclusion that the pair satisfies the requested truncated collision. Python and the OpenSSL CLI may share the same cryptographic implementation; this cross-check is not an independent implementation review. No SIMD verifier was available or run here, so acceptance by that external verifier remains unobserved. This result concerns only the first 48 bits and does not claim a full RIPEMD-160 collision.
