# Verified 48-bit Keccak-256 collision

The requested collision is in [`../collision.json`](../collision.json). Inputs are hex-encoded raw bytes, not the UTF-8 text of the hex strings.

| Field | Value |
|---|---|
| Algorithm | keccak256 (legacy Keccak padding, suffix 0x01) |
| Lambda | 24 |
| inputA | `0x8375360100000000` |
| inputB | `0x7131040200000000` |
| Shared first 48 bits (six bytes, MSB prefix) | `8851a59bbb9d` |

Full digests observed locally:

```text
A: 8851a59bbb9d6231d46ab9566296d3aed4afb5cd4212a1f68a094142b0366868
B: 8851a59bbb9d27a12c8340ba34a0ac8820e6315e00542945f74d66f4ef53a9b1
```

## Evidence and reproduction

The included [`../tools/search.c`](../tools/search.c) enumerated eight-byte little-endian integers and stored six-byte digest prefixes in a hash table. It found this pair at integers 20,346,243 and 33,829,233 after 33,829,234 evaluations. This count is an observed search result, not a guaranteed birthday-search bound.

The included standard-library-only verifier [`../tools/verify.py`](../tools/verify.py) independently implements the permutation using a lane-cycle rotation procedure. Run from the repository root:

```sh
python3 tools/verify.py
```

Observed output:

```text
inputA digest: 8851a59bbb9d6231d46ab9566296d3aed4afb5cd4212a1f68a094142b0366868
inputB digest: 8851a59bbb9d27a12c8340ba34a0ac8820e6315e00542945f74d66f4ef53a9b1
PASS: distinct inputs; matching first 48 bits: 8851a59bbb9d
```

A separate local check with **PyCryptodome 3.24.0**, using `Crypto.Hash.keccak.new(digest_bits=256, data=input_bytes)`, produced the same two full digests. Attribution: the [PyCryptodome release metadata](https://pypi.org/pypi/pycryptodome/3.24.0/json) and the [exact wheel used](https://files.pythonhosted.org/packages/9a/7d/1a7c58f5b839fbf65965461b554bb1297839fdb8880b5ab92c8331b7a02a/pycryptodome-3.24.0-cp37-abi3-manylinux2014_x86_64.manylinux_2_17_x86_64.whl). That package was used only for this additional check; the delivered verifier needs no network or installed dependencies beyond Python 3.

## Conclusions and limits

The distinct decoded inputs and equal six-byte prefixes establish the requested truncated collision. Their full 256-bit digests differ; this is not a full Keccak-256 collision.

All reported check results were produced locally by this contributor. No independent reviewer or SIMD verifier was run in this environment, and no claim of their acceptance is made. The supplied failure notice concerns model capacity (`runtime_error`); it contains no surviving implementation or collision evidence to reuse. No unanswered mathematical condition remains after the local checks; external acceptance remains unobserved.
