# RIPEMD-160 collision, first 48 bits (λ = 24)

Found a collision between two distinct eight-byte inputs. The `0x` values in
[collision.json](../collision.json) represent decoded hexadecimal bytes, not the
literal text of the hexadecimal strings.

| Value | Input A | Input B |
| --- | --- | --- |
| Input bytes | `0x19bef10000000000` | `0x1022730100000000` |
| Full RIPEMD-160 digest | `902e5fc86be47b1e2a17de2aab65d4e765623a05` | `902e5fc86be4a99253faddc650510cb85e77233d` |
| First 48 bits, MSB | `902e5fc86be4` | `902e5fc86be4` |

## Method and attributable evidence

[search.c](search.c) enumerated eight-byte little-endian counters, starting at 1,
and computed RIPEMD-160 through the local OpenSSL 3.0.13 library. A hash table
retained candidates; all potential matches were checked against all six prefix
bytes. The search found counters 15,842,841 and 24,322,576 after enumerating
24,322,576 inputs, taking approximately 15 seconds locally. Candidate rechecks
add digest evaluations beyond the number of enumerated inputs.

[verify.py](verify.py) rereads the delivered JSON, checks its exact key set and
algorithm/parameter values, decodes both inputs, confirms they differ, and
recomputes both full digests. Its recorded output is
[verification.json](verification.json). A separate invocation of the local
`openssl dgst -ripemd160` CLI on each decoded input returned the identical full
digests listed above.

Reproduce from the repository root:

```sh
python3 artifacts/verify.py
```

To repeat the search on a machine with GCC and OpenSSL's `libcrypto.so.3`:

```sh
mkdir -p test/scratch
gcc -O3 -Wall -Wextra artifacts/search.c -o test/scratch/search -l:libcrypto.so.3
test/scratch/search
python3 artifacts/verify.py
```

## Conclusion and limits

Observed fact: the distinct inputs have equal first six digest bytes. This
satisfies the requested 48-bit truncation collision. Their full 160-bit digests
differ. The conclusion follows directly from the locally recomputed bytes;
no external factual sources or estimates are needed. Python and the CLI may
share the OpenSSL implementation, so these checks are not an independent
cryptographic implementation audit. SIMD verification was not run here and
remains external to this submission.
