# SHA-256 collision at 48 bits (lambda = 24)

A collision was found and locally verified. The requested record is in [collision.json](../collision.json).

Both inputs below are literal UTF-8 strings, each 26 bytes, with no trailing newline:

| Field | Input | Full SHA-256 digest |
| --- | --- | --- |
| inputA | `simd-collision-24:00323c57` | `d6c55f48631fe30f818a23de105a11f30da02bb4fde8a02628ac331e5e6f6c62` |
| inputB | `simd-collision-24:0074aa2f` | `d6c55f48631fde93a45b83b9f77e3a8cd15c608da7b5d5d7f3c8b4837f2bd34e` |

The first six digest bytes, equivalently the first 48 most significant bits, are identical: **`d6c55f48631f`**. The input bytes are distinct. The remaining digest bytes differ; this is not a full SHA-256 collision.

## Attributable local evidence

The local search enumerated strings of the form `simd-collision-24:%08x`, starting with counter zero. It used OpenSSL 3.0.13's SHA256 function and a table indexed by the first three digest bytes, retaining the latest candidate for each index and comparing all six leading bytes on a hit. It found the pair after 7,645,744 candidates (13 seconds reported locally). This candidate count does not include repeat hashing of stored candidates.

The delivered [verification script](../tools/verify_collision.py) recomputed both digests with Python's standard-library `hashlib`, checked the exact JSON field set, algorithm and lambda, checked distinct decoded input bytes, and compared the first six digest bytes. Run:

```sh
python3 tools/verify_collision.py
```

Observed result:

```text
PASS: distinct inputs share the first 48 bits: d6c55f48631f
```

A separate command-line check reproduced both full digests shown in the table:

```sh
printf %s 'simd-collision-24:00323c57' | sha256sum
printf %s 'simd-collision-24:0074aa2f' | sha256sum
```

## Conclusion and limits

The locally observed digest equality establishes the requested truncated collision under the stated UTF-8 interpretation. Verification requires no network or third-party Python packages. These are self-checks, not an independent review; Python and OpenSSL may share a cryptographic backend. The external SIMD verifier was not available here and its acceptance has not been observed. No claim about a full SHA-256 collision or general SHA-256 security follows from this result.
