# Keccak-256 collision in the first 48 bits

The distinct eight-byte inputs in [collision.json](../collision.json) produce the same first six digest bytes, **`8851a59bbb9d`**, in local verification. This satisfies the requested 48-bit truncation for lambda = 24.

| Field | Value |
| --- | --- |
| inputA (hexadecimal bytes) | `0x8375360100000000` |
| inputB (hexadecimal bytes) | `0x7131040200000000` |
| Full Keccak-256 digest A | `8851a59bbb9d6231d46ab9566296d3aed4afb5cd4212a1f68a094142b0366868` |
| Full Keccak-256 digest B | `8851a59bbb9d27a12c8340ba34a0ac8820e6315e00542945f74d66f4ef53a9b1` |
| Shared leading 48 bits | `8851a59bbb9d` |

The `0x` values encode raw bytes; the literal hexadecimal text is not hashed. The complete 256-bit digests differ.

## Method and attributable evidence

[The C search](../tools/find_collision.c) enumerated eight-byte little-endian counters starting at zero and used a hash table to detect repeated six-byte digest prefixes. It found the pair after 33,829,234 evaluations, as recorded in [search.log](search.log).

[The separate Python verifier](../tools/verify_collision.py) recomputed the full digests using a matrix representation and generated round constants. It also checked known-answer digests for the empty string and `abc`, the exact JSON field set, algorithm and lambda, distinct decoded inputs, and equality of the first six digest bytes. All checks passed; [verification.txt](verification.txt) contains the observed output.

The implementations use Keccak-f[1600], 24 rounds, a 136-byte rate, and original Keccak padding with delimited suffix `0x01`. The [Keccak team's specification summary](https://keccak.team/keccak_specs_summary.html) supplies the permutation, sponge pseudocode, constants, and suffix formula. Applying that formula with no trailing domain-separation bits gives `0x01`; SHA3-256 instead uses `0x06` in that source's instance table. The source supports the algorithm description; the collision evidence comes from the local computations above.

## Reproduction and limits

Run from the repository root, with Python 3 and no network or third-party packages:

```sh
python3 tools/verify_collision.py collision.json
```

To repeat the search with a C compiler (approximately 1 GiB of table memory):

```sh
mkdir -p test/scratch
gcc -O3 -std=c11 -Wall -Wextra tools/find_collision.c -o test/scratch/find_collision
test/scratch/find_collision > test/scratch/reproduced.json
python3 tools/verify_collision.py test/scratch/reproduced.json
```

Observed facts are the distinct inputs, displayed digests, matching prefix, search count, and passing local checks. The conclusion that this meets the requested collision condition follows from those observations. These checks were performed by the producing agent and carry no independent review authority. SIMD recomputation was not available here, so its acceptance remains unobserved. No claim of a full 256-bit collision is made.
