# SHA-256 truncated collision (48 bits)

## Result

The inputs `batch01-0020d0aa` and `batch01-007d3814` are distinct UTF-8 strings. Their SHA-256 digests are:

- A: `fe089d28eb53c4b1014c0e5b60c4e7b17a4126c711c5becd912cfec4a175edb6`
- B: `fe089d28eb537289c466a25b13904e2a512fd0014b0d4331c1a43fe331aa8c58`

Both begin with `fe089d28eb53`, the same 48 most significant bits. The machine-readable result is in [`collision.json`](../collision.json).

## Evidence and method

**Computed fact:** I independently recomputed both full digests using Python's `hashlib.sha256` and compared the first six digest bytes; the comparison returned `True`. Reproduce with:

```sh
python3 -c 'import hashlib; a=b"batch01-0020d0aa"; b=b"batch01-007d3814"; print(hashlib.sha256(a).hexdigest()); print(hashlib.sha256(b).hexdigest()); assert a != b and hashlib.sha256(a).digest()[:6] == hashlib.sha256(b).digest()[:6]'
```

The candidate search used SHA-256 over ASCII strings of the form `batchNN-XXXXXXXX` and retained the first six digest bytes. The found pair occurred in batch 01. The search itself is a local computation; the digest recomputation above is a separate implementation check.

**Inference:** Equal first six bytes establish equality of the first 48 bits (MSB-first) under standard SHA-256 digest byte ordering. This is a collision for the requested truncated digest, not a collision of full SHA-256.

## Limits and open questions

This report records reproducible local calculations, not an external certification. No independent reviewer or third-party computation was used. The result relies on the local Python/OpenSSL implementations behaving as specified; no question about the behavior of the SIMD verifier has been answered beyond supplying the requested inputs for its recomputation.
