# RIPEMD-160 collision for the first 48 bits

The search found two distinct eight-byte inputs whose RIPEMD-160 digests
share the first 48 bits. The requested machine-readable result is
[`../collision.json`](../collision.json). Values prefixed by `0x` represent
decoded hexadecimal bytes, not the UTF-8 bytes of the displayed strings.

| Field | Input A | Input B |
| --- | --- | --- |
| Input bytes, hexadecimal | `0000000000de27bb` | `000000000162a52d` |
| Full RIPEMD-160 digest | `18573a938b62f83d5fd18457e6667947098926a1` | `18573a938b62ac143bea6201e8a91fb007aa02ad` |
| First six bytes (48 bits, MSB) | `18573a938b62` | `18573a938b62` |

## Method and attributable local evidence

The submitted [search program](search.py) enumerates positive integers encoded
as eight-byte big-endian messages and stores their six-byte digest prefixes
in an open-addressed table. The run found the match after 23,242,029 digest
evaluations, in approximately 74.71 seconds. These are measurements from
this local run, not performance guarantees.

On 2026-10-05, running `python3 artifacts/verify.py` from the repository root
produced:

```text
inputA: bytes=0000000000de27bb digest=18573a938b62f83d5fd18457e6667947098926a1 prefix48=18573a938b62
inputB: bytes=000000000162a52d digest=18573a938b62ac143bea6201e8a91fb007aa02ad prefix48=18573a938b62
PASS: distinct inputs; equal first 48 digest bits; both interfaces agree.
```

The [verification program](verify.py) checks the exact JSON key set,
algorithm and lambda, distinct decoded inputs, and equality of the first
six digest bytes. It recomputes each full digest through Python `hashlib`
and `openssl dgst -ripemd160 -binary`. The installed CLI reports OpenSSL
3.0.13 (30 Jan 2024). Verification requires no network or installed extras
beyond those existing system tools.

## Conclusion and limits

The locally observed digest equality establishes the requested 48-bit
prefix collision under the stated hexadecimal decoding. The full digests
differ; this is not a full 160-bit collision. Python and the CLI may share
the same OpenSSL implementation, so agreement is not independent
cryptographic implementation evidence. No SIMD verifier was available or
run in this assignment; its acceptance remains unobserved. The local
checks are reproducible evidence, not independent certification.
