# RIPEMD-160 collision truncated to 48 bits

The requested collision is in [collision.json](../collision.json). The inputs are distinct eight-byte sequences, decoded from the `0x` hexadecimal strings; they are not the literal text of those strings.

| Field | Input A | Input B |
| --- | --- | --- |
| Input hex | `19bef10000000000` | `1022730100000000` |
| Full RIPEMD-160 digest | `902e5fc86be47b1e2a17de2aab65d4e765623a05` | `902e5fc86be4a99253faddc650510cb85e77233d` |
| First 48 bits (six bytes, MSB) | `902e5fc86be4` | `902e5fc86be4` |

## Attributable local evidence

On 2026-10-05, [the search program](../tools/find_collision.py) found the pair at counter 24,322,576, with prior counter 15,842,841. It enumerates eight-byte little-endian counters and stores candidates in a hash table. The counter measures primary input evaluations; occasional candidate recomputations are additional evaluations.

[The verification program](../tools/verify_collision.py) parsed the JSON, checked its exact keys and requested parameters, decoded and compared the inputs, recomputed both complete digests with Python `hashlib`, and compared each digest with `openssl dgst -ripemd160 -binary`. It then compared the first six bytes. Run from the repository root:

```sh
python3 tools/verify_collision.py
```

Observed output (exit status 0):

```text
input=0x19bef10000000000 digest=902e5fc86be47b1e2a17de2aab65d4e765623a05 prefix48=902e5fc86be4
input=0x1022730100000000 digest=902e5fc86be4a99253faddc650510cb85e77233d prefix48=902e5fc86be4
PASS: distinct inputs, exact JSON keys, matching first 48 bits.
```

The environment reported Python 3.12.3 and OpenSSL 3.0.13. No package was installed. The delivered scripts use the standard library and the environment's existing RIPEMD-160 support; the JSON itself has no runtime dependencies.

## Conclusion and limits

Observed fact: the two local recomputation interfaces returned the digests above. Direct comparison establishes equal 48-bit prefixes and distinct inputs, satisfying the requested local collision check for lambda 24. The full digests differ.

The two interfaces can share the OpenSSL implementation, so this is not evidence from independent cryptographic implementations. SIMD verification was not available or run locally, and its acceptance remains unobserved. These local checks carry no independent review authority. No inference about full-length RIPEMD-160 collisions or general security follows from this result.
