# Keccak-256 collision at 48 bits (λ = 24)

**Result: a locally verified collision for the first 48 bits.** The required
four-field object is in [`../collision.json`](../collision.json).

| Field | Value |
| --- | --- |
| inputA, decoded as hexadecimal bytes | `0x8375360100000000` |
| inputB, decoded as hexadecimal bytes | `0x7131040200000000` |
| Keccak-256(inputA) | `8851a59bbb9d6231d46ab9566296d3aed4afb5cd4212a1f68a094142b0366868` |
| Keccak-256(inputB) | `8851a59bbb9d27a12c8340ba34a0ac8820e6315e00542945f74d66f4ef53a9b1` |
| Common first six digest bytes (48 bits MSB) | `8851a59bbb9d` |

## Method and attributable evidence

The original search implementation in [`../src/search.c`](../src/search.c)
enumerated eight-byte little-endian integers beginning at zero. It stored the
first six digest bytes in a hash table and found equal prefixes for counters
20,346,243 and 33,829,233 after 33,829,234 evaluations. The search used the full
24-round Keccak-f[1600] permutation; λ describes the truncation security
parameter, not a reduction in permutation rounds.

Verification used the separately authored XKCP implementation by Gilles Van
Assche, vendored unchanged in [`../src/CompactFIPS202.py`](../src/CompactFIPS202.py).
Its [upstream source at commit 712fabccd5d611459533d554814e00537742624c](https://github.com/XKCP/XKCP/blob/712fabccd5d611459533d554814e00537742624c/Standalone/CompactFIPS202/Python/CompactFIPS202.py)
was downloaded and compared byte for byte with the local copy. The source
retains its CC0 dedication. Its SHA-256 is
`0b731097a4dfcf33fdaf395ac0bee81c6a6ebff2975590c35ad8cd8d6f3c204f`.

The wrapper calls `Keccak(1088, 512, input, 0x01, 32)`: original Keccak-256
padding, not SHA3-256's `0x06` suffix. The algorithm and padding are described
by the [Keccak team's specification summary](https://keccak.team/keccak_specs_summary.html)
and [Keccak reference, version 3.0](https://keccak.team/files/Keccak-reference-3.0.pdf).

Run from the repository root:

```sh
python3 src/verify.py collision.json
```

The run passed two known-answer checks (empty input and `abc`), exact JSON
field and parameter checks, distinct decoded input checks, and equality of
the first six digest bytes. Full output is saved in
[`verification.json`](verification.json). No network or third-party Python
installation is required to repeat it.

## Conclusions and limits

**Observed:** the two eight-byte inputs are distinct, and their independently
recomputed 256-bit digests share the first 48 bits. Their full digests differ.

**Inference:** these results satisfy the requested truncated collision relation
when `0x` inputs are decoded as hexadecimal bytes, as specified in the task.

**Uncertainty and unanswered checks:** this is local computational evidence,
using an independent implementation, not an independent reviewer or a SIMD
verifier result. The external SIMD acceptance check has not been run here.
No full 256-bit collision is claimed.
