# RIPEMD-160 collision in the first 48 bits

The two distinct byte strings in [collision.json](../collision.json) have the same first 48 bits of their RIPEMD-160 digests. The requested parameter is lambda = 24; the compared prefix is 2 × 24 = 48 bits, or six bytes. Inputs use `0x` followed by hexadecimal encoding of the bytes, not literal text containing the hex digits.

## Observed evidence

| Input | Full RIPEMD-160 digest | First six bytes |
| --- | --- | --- |
| inputA | `3c44ab6075920f83d31e8cc841ed856ff685b758` | `3c44ab607592` |
| inputB | `3c44ab6075921bfb15959c04b68f58c6be3e241b` | `3c44ab607592` |

Both inputs are 32 bytes long and differ in their final eight bytes. They consist of the ASCII bytes `IdentityMD-ripemd160-48:` followed by an unsigned eight-byte big-endian counter: 20,231,272 for inputA and 26,171,068 for inputB.

The local search enumerated counters from zero, retaining each six-byte digest prefix and its first counter. It found this pair after 26,171,069 evaluations, in approximately 93.23 seconds. These are local execution observations, not independently certified measurements.

## Recomputable check and attribution

Run from the repository root:

```sh
python3 tools/verify_collision.py
```

The delivered [verification script](../tools/verify_collision.py) checks the JSON keys, algorithm and parameter, decodes the inputs, checks that their bytes differ, computes the full digests with Python `hashlib`, and checks equality of their first six bytes. It also recomputes both digests using `openssl dgst -ripemd160 -binary` and checks agreement. The local run returned `verified: true` and the digests above. The CLI reported OpenSSL 3.0.13 (30 January 2024).

This evidence is attributable to the submitted inputs, the delivered verification code, and local computation. The hexadecimal prefix equality is directly observed; the conclusion that the requested truncated collision is satisfied follows from comparing those six bytes.

## Limits and unanswered verification

The full 160-bit digests differ; this result is a collision only for the specified 48-bit truncation. Python's hashing interface and the CLI use OpenSSL here, so their agreement is a cross-check through two interfaces, not an independent implementation review. The external SIMD verifier was not available or run in this assignment. Its acceptance remains unobserved. No external research claims or citations are needed to reproduce this concrete computation.
