# Keccak-256 collision in the first 48 bits (λ = 24)

**Result: a locally verified collision was found.** The required four-field object is in [`../collision.json`](../collision.json). Inputs are hex-encoded byte strings, not the UTF-8 characters of their hex representations.

| Value | Input A | Input B |
| --- | --- | --- |
| Input bytes (hex) | `8375360100000000` | `7131040200000000` |
| Keccak-256 digest | `8851a59bbb9d6231d46ab9566296d3aed4afb5cd4212a1f68a094142b0366868` | `8851a59bbb9d27a12c8340ba34a0ac8820e6315e00542945f74d66f4ef53a9b1` |
| First 48 bits | `8851a59bbb9d` | `8851a59bbb9d` |

The inputs differ, while the first six digest bytes agree. The full 256-bit digests differ; the claim is exclusively a collision under 48-bit MSB truncation.

## Method and attributable evidence

The local C birthday search ([source](../tools/search.c)) enumerated eight-byte little-endian integer encodings starting at zero. An open-addressed table stored six-byte digest prefixes and their input counters. It found counters **20,346,243** and **33,829,233** after **33,829,234 evaluations**, including counter zero. These counts are recorded in the [search log](search.log).

The search uses Keccak-f[1600] with 24 rounds, a 1088-bit rate, 512-bit capacity and original Keccak padding. The algorithm background is the Keccak team's [reference specification](https://keccak.team/files/Keccak-reference-3.0.pdf) and [specifications summary](https://keccak.team/keccak_specs_summary.html). The verifier calls the generic sponge with delimited suffix `0x01`, producing original Keccak-256 rather than SHA3-256.

Verification uses the independently authored [Keccak Team implementation from XKCP](https://github.com/XKCP/XKCP/blob/4affab454735d54e78156880b3b44e38dcbf765c/Standalone/CompactFIPS202/C/Keccak-readable-and-compact.c), vendored unchanged in [tools/keccak-reference.c](../tools/keccak-reference.c), retaining its attribution and public-domain dedication. Its SHA-256 file checksum is `7d25b518f28b4b9be141495dde205621fdb528e880596ef9507d30ba1b937dc9`. The downloaded file was compared byte-for-byte with that pinned revision.

The [offline verification script](../tools/verify.py) checks exact JSON keys, algorithm, integer λ, distinct decoded inputs, full digests and matching first 12 hex digits. It also checks the reference implementation against Keccak-256 known-answer values for the empty message and `abc`. Its recorded output is [verification.json](verification.json).

Reproduce from the repository root with Python 3 and a C compiler:

```sh
python3 tools/verify.py
```

No network, package installation or external library is needed. The C reference is compiled into a temporary directory during verification. The search itself need not be rerun to validate the collision.

## Findings and limits

**Observed facts:** local search and separate reference recomputation produced the digests above; the schema, distinctness and prefix checks passed. **Inference:** this satisfies the specified mathematical collision condition under the stated hex decoding and first-six-byte interpretation. **Unverified:** the external SIMD evaluator was not available in this session, so its acceptance is not claimed. These are local checks using a separate implementation, not an independent review or certification. No cryptographic conclusion beyond this truncated collision is asserted.

The supplied previous-attempt failure was a model-capacity runtime error and supplied no surviving candidate or code. This deliverable was generated and checked afresh.
