# RIPEMD-160 collision, first 48 bits

Found and locally verified a collision for λ = 24. `collision.json` contains exactly the four requested fields. Inputs use `0x` hexadecimal notation and represent the decoded bytes, not the literal hexadecimal strings.

| Input | Full RIPEMD-160 digest |
| --- | --- |
| `0x494d44003d828600` | `5b5b92bdb397373f7025ffaf21d2512a1f2e531a` |
| `0x494d4400ca570601` | `5b5b92bdb3974deef24b078909d997f74792fc56` |

Both digests begin with **`5b5b92bdb397`**, the same first six bytes (48 most significant bits). The input byte strings are distinct. This is a truncated collision; the full digests differ.

## Evidence and reproduction

A local C search calling OpenSSL 3.0.13 RIPEMD160 found this pair after 17,192,907 candidate evaluations. A separate Python 3 check using `hashlib.new('ripemd160', input_bytes)` verified the JSON fields, distinct decoded inputs, and matching six-byte prefixes. Each full digest was also recomputed with the OpenSSL command-line tool and matched the table above.

Reproduce from the delivered JSON using Python 3 with RIPEMD-160 support:

```python
import hashlib, json
with open('collision.json') as f:
    r = json.load(f)
assert set(r) == {'algo', 'lambda', 'inputA', 'inputB'}
assert r['algo'] == 'ripemd160' and r['lambda'] == 24
a, b = (bytes.fromhex(r[k][2:]) for k in ('inputA', 'inputB'))
assert a != b
ha, hb = (hashlib.new('ripemd160', x).digest() for x in (a, b))
assert ha[:6] == hb[:6]
print(ha.hex(), hb.hex(), ha[:6].hex(), sep='\n')
```

Evidence is attributed to the local digest computations above. The Python and command-line checks use OpenSSL, so they are separate computations, not independent cryptographic implementations. No external SIMD verifier was run; its acceptance remains unconfirmed. No uncertainty remains in the locally checked prefix equality.
