# RIPEMD-160 first-48-bit collision

The requested collision is in [collision.json](../collision.json), with exactly the four requested fields. Each `0x` value denotes decoded hexadecimal bytes, not the literal text of that value.

| Item | Input A | Input B |
| --- | --- | --- |
| Eight input bytes (hex) | `0000000000de27bb` | `000000000162a52d` |
| Full RIPEMD-160 digest | `18573a938b62f83d5fd18457e6667947098926a1` | `18573a938b62ac143bea6201e8a91fb007aa02ad` |
| First 48 bits (six leading bytes) | `18573a938b62` | `18573a938b62` |

## Evidence and method

The local [search program](../tools/find_collision.c) hashes successive eight-byte big-endian counters using the installed OpenSSL libcrypto RIPEMD160 function. Its hash table detects equal six-byte prefixes and rehashes a stored candidate to confirm equality before reporting a result. It found these distinct inputs at candidate 23,242,029, reporting 18.47 CPU seconds. This is a measured search result, not an estimated or invented collision.

The [verification script](../tools/verify_collision.py) separately loads the delivered JSON, checks its exact field set and parameter values, decodes the inputs, checks byte inequality, and compares the first six digest bytes. Run from the repository root:

```sh
python3 tools/verify_collision.py
```

The recorded successful output is [verification.json](verification.json). Additional local checks passed each decoded input through `openssl dgst -ripemd160`; OpenSSL 3.0.13 printed the same full digests shown above. No network access or downloaded dependencies were used. The search requires a C compiler and system libcrypto; the verifier requires Python with a RIPEMD-160 provider. Search build and execution commands are included in its source.

## Conclusion and limits

Observed facts: the inputs are distinct, their full digests differ, and their six leading digest bytes match. These facts establish the requested 48-bit truncation collision, with the task's lambda value of 24.

The checks are local and attributable to the provided source and recorded output. Python and the OpenSSL CLI may share the same cryptographic implementation; they are not independent cryptographic implementations or an independent review. The external SIMD verifier was not available or run here, so its acceptance remains unobserved. No claim of a collision for full RIPEMD-160 is made.
