# SHA-256 collision for a 48-bit MSB truncation

The requested collision was found and locally verified. The delivered
[collision.json](../collision.json) contains exactly the four requested fields.
Inputs beginning with `0x` represent decoded hexadecimal bytes, not the literal
characters of the hexadecimal string.

## Observed evidence

| Value | Input A | Input B |
| --- | --- | --- |
| Input bytes (hex) | `494d44430092d146` | `494d4443018a8ace` |
| Full SHA-256 | `e6638acfbfe4a235ee4f74ee9a68128e8c0e00f8e64558fd467cca4fd788e0f4` | `e6638acfbfe458abbeb5432450696d62aadcaa2ede695e43ef2e3f585d6b7150` |
| First six bytes (48 MSB bits) | `e6638acfbfe4` | `e6638acfbfe4` |

The inputs are distinct, and their first 48 digest bits match. Their full
digests differ. Here lambda is 24, so the requested truncation is 2 × 24 = 48 bits.

The search hashed eight-byte inputs consisting of ASCII `IMDC` followed by a
four-byte unsigned counter in big-endian order. It compared the first six digest
bytes using a hash table. Counters 9,621,830 and 25,856,718 produced the match;
the sequential search made 25,856,719 evaluations including counter zero.

Evidence is attributable to local computation: the search used the system
OpenSSL library, and verification used Python `hashlib` and the OpenSSL 3.0.13
command-line tool. Both verification paths produced the full digests above.
Python's underlying hashing provider may also be OpenSSL, so these checks are
not claimed to be independent implementations or an independent review.

## Reproduction and limits

Run `python3 verify.py` from the repository. The delivered
[verification script](../verify.py) uses only the Python standard library,
checks the exact JSON field set and parameter values, decodes the inputs,
checks that they differ, and recomputes both digests and their six-byte prefixes.
The local run exited successfully with:

```text
Shared first 48 bits: e6638acfbfe4
PASS: distinct inputs and identical 48-bit MSB prefixes
```

The additional local command `openssl dgst -sha256` on the decoded binary
inputs returned the same full digests. Scratch search files are excluded from
delivery; the collision and its verification do not depend on them.

This is a collision for the specified truncation only. No full SHA-256 collision
is asserted. No external SIMD verifier was available during this task, so its
acceptance remains unobserved; the reported success is a local check, not an
external certification. There are no unresolved questions about the locally
computed input bytes or prefix equality.
