# Keccak-256 collision at 48 bits (λ = 24)

Found and locally verified two distinct eight-byte messages whose Keccak-256
digests have the same first six bytes. The requested record is in
[`collision.json`](../collision.json). Its `0x` values encode raw bytes, not
literal UTF-8 text containing the hexadecimal characters.

| Value | Result |
| --- | --- |
| inputA | `0x8375360100000000` |
| inputB | `0x7131040200000000` |
| Keccak-256(inputA) | `8851a59bbb9d6231d46ab9566296d3aed4afb5cd4212a1f68a094142b0366868` |
| Keccak-256(inputB) | `8851a59bbb9d27a12c8340ba34a0ac8820e6315e00542945f74d66f4ef53a9b1` |
| Shared first 48 bits (MSB prefix) | `8851a59bbb9d` |

## Method and attributable evidence

The included [C search program](../tools/search.c) enumerated unsigned integers
as eight-byte little-endian messages, starting at zero, and stored their
six-byte digest prefixes in a hash table. It found counters **20,346,243** and
**33,829,233**, after **33,829,234 evaluations**. The search compares the low
48 bits of the first internal little-endian lane, which represent the first
six output bytes; this is the requested leading digest prefix.

The included [Python verifier](../tools/verify.py) recomputed both full digests
using a separate matrix-based implementation with generated round constants.
It also passed known-answer checks for the empty message and `abc`, checked
the four required JSON keys and parameter values, and checked that the decoded
messages differ. Its observed output is saved in
[`verification.txt`](verification.txt).

The permutation, lane arrangement, and padding construction can be compared
with the primary [Keccak Team specification summary](https://keccak.team/keccak_specs_summary.html).
This implementation uses Keccak-f[1600] with 24 rounds, a 1088-bit rate,
512-bit capacity, and original Keccak's `0x01` delimited padding suffix
(no added domain-separation bits). SHA3-256's `0x06` suffix would give different
digests. The source describes these permutation and padding conventions.

## Reproduction

From the repository root, run:

```sh
python3 tools/verify.py
```

Verification uses only the Python standard library, needs no network, and does
not require rerunning the birthday search. To reproduce the deterministic
search, with a C compiler and approximately 1 GiB of table memory:

```sh
cc -O3 -std=c11 tools/search.c -o /tmp/keccak-search
/tmp/keccak-search
```

## Scope and limits

**Observed facts:** The local search and verifier returned the results above;
the messages are distinct and the recomputed six-byte prefixes match.

**Conclusion:** These results satisfy the requested truncated collision under
the raw-byte interpretation of `0x` inputs. The full 256-bit digests differ.

**Uncertainty and unanswered checks:** The external SIMD verifier was not
available in this workspace and has not been run. These are reproducible local
checks, not an independent certification or a claim of a full Keccak-256
collision. No external verifier outcome is asserted.
