# SHA-256 first-48-bit collision (lambda = 24)

A collision was found and locally verified. The required JSON is in
[`../collision.json`](../collision.json). Both inputs are hexadecimal encodings
of raw eight-byte messages, not UTF-8 encodings of the hexadecimal text.

| Field | Value |
| --- | --- |
| inputA | `0x000000000017211c` |
| inputB | `0x00000000014060cc` |
| SHA-256(inputA) | `4e84dca19fa699674e41dc0ff0f92046577a96fd3bbc22ae6a036986dc268301` |
| SHA-256(inputB) | `4e84dca19fa67ad46fd0f73243c0081834a4767ce3fc91b0b4dade47ab574d2e` |
| Shared first 48 bits (MSB) | `4e84dca19fa6` |

## Evidence and reproduction

The local search in [`search.c`](search.c) hashed 33,554,432 messages, the
big-endian eight-byte representations of integers 0 through 33,554,431 inclusive.
It sorted their 48-bit prefixes and found the pair above. Search exit status was
0. The search processes one correctly padded SHA-256 block per input using the
installed OpenSSL 3 runtime.

Run `python3 artifacts/verify.py` from the repository root to decode both inputs,
check the exact JSON fields and parameters, assert that the decoded messages are
distinct, recompute both full SHA-256 digests, and assert equality of their first
12 hexadecimal characters (48 bits). Its actual output is saved in
[`verification.json`](verification.json). This check passed. A separate invocation
of `openssl dgst -sha256` on each raw message also matched the full digests above.
See [`README.md`](README.md) for the search command and its runtime requirements.

## Facts, inference, and limits

Observed facts: the inputs differ; the recomputed full digests are those listed
above; their first six bytes match. The conclusion that this satisfies the
requested truncation collision follows directly from those byte comparisons.
The full 256-bit digests differ.

These are attributable local computations; no external source or network data
was needed. Python hashlib and the OpenSSL command may share a cryptographic
backend, so the separate verification checks the search's input encoding,
padding, prefix extraction, and result handling without claiming independent
cryptographic implementation review. No independent SIMD verifier was run here.
There are no unanswered questions about the locally checked pair; external
acceptance remains unverified.
