# SHA-256 collision for a 48-bit prefix

The two distinct eight-byte inputs in [collision.json](../collision.json) have identical first 48 bits of their SHA-256 digests. Here `0x` denotes hexadecimal byte encoding; it is not part of the hashed message.

| Item | Input bytes (hex) | Full SHA-256 digest |
| --- | --- | --- |
| inputA | `000000000017211c` | `4e84dca19fa699674e41dc0ff0f92046577a96fd3bbc22ae6a036986dc268301` |
| inputB | `00000000014060cc` | `4e84dca19fa67ad46fd0f73243c0081834a4767ce3fc91b0b4dade47ab574d2e` |

The common six-byte (48-bit MSB) prefix is **`4e84dca19fa6`**. The requested parameter is `lambda = 24`. The full digests differ.

## Method and attributable evidence

The local [search program](../tools/find_collision.c) implements SHA-256 for eight-byte big-endian counters, enumerates counters starting at zero, and stores digest prefixes in a hash table. It reported a collision after **20,996,301 evaluations**. No external data or dependencies were downloaded.

The search was compiled with `gcc -O3 -Wall -Wextra -Werror` and exited successfully. Its candidate was separately recomputed with Python 3.12.3 `hashlib.sha256` using the delivered [verification script](../tools/verify_collision.py):

```text
inputA SHA-256: 4e84dca19fa699674e41dc0ff0f92046577a96fd3bbc22ae6a036986dc268301
inputB SHA-256: 4e84dca19fa67ad46fd0f73243c0081834a4767ce3fc91b0b4dade47ab574d2e
Shared first 48 bits: 4e84dca19fa6
PASS: distinct inputs with equal 48-bit MSB prefixes
```

OpenSSL 3.0.13 `openssl dgst -sha256`, with each decoded eight-byte input passed directly on standard input, also returned exactly the full digests above. These are local observed results, attributable to the included inputs and code. Python and the OpenSSL command may share a cryptographic backend; they are separate recomputations from the custom search implementation, not two guaranteed independent cryptographic implementations.

## Conclusion and limits

The byte inequality and matching first six digest bytes establish the requested truncated collision under the specified hexadecimal decoding. This is not a full SHA-256 collision. No SIMD verifier or external reviewer was available or run; its eventual acceptance is unobserved. These local checks provide reproducible evidence, not independent certification. No unresolved uncertainty remains in the locally checked prefix equality.
