# SHA-256 truncated collision report

## Result

The required collision is recorded in [`collision.json`](../collision.json).
Both inputs are explicitly encoded as `0x`-prefixed hexadecimal bytes.

## Facts and attributable evidence

An independent local verification using Python 3's `hashlib.sha256` computed:

| input | full SHA-256 | first 48 bits (12 hex characters) |
|---|---|---|
| `0x000000000017211c` | `4e84dca19fa699674e41dc0ff0f92046577a96fd3bbc22ae6a036986dc268301` | `4e84dca19fa6` |
| `0x00000000014060cc` | `4e84dca19fa67ad46fd0f73243c0081834a4767ce3fc91b0b4dade47ab574d2e` | `4e84dca19fa6` |

The verification decoded each `0x...` value after the prefix, hashed the resulting
8 bytes with SHA-256, and compared `digest[:6]`. The inputs differ, and the six-byte
prefixes are equal, so the JSON satisfies the stated collision condition.

## Inference and limits

The matching prefixes are direct computational evidence for a 48-bit MSB collision;
the claim is not based on an estimated birthday probability. The search used
sequential distinct 8-byte values and found the pair after 21,000,000 candidates;
that search count is contextual evidence only and is not needed for verification.

No claim is made about a collision in the untruncated 256-bit SHA-256 function.
There are no unanswered questions relevant to validating this deliverable.
