# RIPEMD-160 collision at 48 bits

The requested collision is in [collision.json](../collision.json). Its input strings use `0x` hex notation and represent raw bytes, not the literal ASCII hex strings.

## Computed evidence

| Input | Full RIPEMD-160 digest |
| --- | --- |
| `0x19bef10000000000` | `902e5fc86be47b1e2a17de2aab65d4e765623a05` |
| `0x1022730100000000` | `902e5fc86be4a99253faddc650510cb85e77233d` |

Both digests have the same first six bytes, `902e5fc86be4`, which are the first 48 bits in MSB order. The inputs are distinct, and the full digests differ. This satisfies the requested truncation with lambda = 24.

Evidence is attributable to local execution of [find_collision.c](../tools/find_collision.c), which searched successive eight-byte little-endian integer encodings using OpenSSL's RIPEMD160 function. It found indices 15,842,841 and 24,322,576 after 24,322,577 evaluations.

The saved JSON was then checked by [verify_collision.py](../tools/verify_collision.py). That script parsed the exact fields, decoded the input bytes, checked distinctness, recomputed full digests with Python hashlib, checked those against `openssl dgst -ripemd160 -binary`, and asserted equality of the first six digest bytes. The check passed. The local OpenSSL version was 3.0.13.

## Limits

These are directly computed local results, not an independently certified SIMD verification. Python and the command-line checks may share the same underlying OpenSSL implementation; they are separate execution paths, not independent cryptographic implementations. No SIMD verifier was available or run here. There is no inference that the full 160-bit digests collide, and no claim about collision resistance beyond this specific 48-bit example. Acceptance by the external SIMD verifier remains unobserved.
