# Report: RIPEMD-160 truncated to 50 bits, collision (λ=25)

## Answer
```json
{"algo":"ripemd160","lambda":25,"inputA":"0x006cb558049cd7","inputB":"0x02fa4264ec5f6e"}
```

## Facts (checked by recomputation)
| input (raw bytes, hex) | RIPEMD-160 digest |
|---|---|
| `006cb558049cd7` | `7e0f145324ac784a3353b5a293aea943c021b80b` |
| `02fa4264ec5f6e` | `7e0f145324ac434555ed0f5aa9524661ed6fdea9` |

- The inputs are distinct byte strings.
- Both digests start with the same 48 bits (`7e0f145324ac`). The next nibbles are `7` (`0111`) and `4` (`0100`), which share their top 2 bits (`01`). The 50-bit MSB prefix is therefore `0x1f83c514c92b1` for both. The bits differ from bit 51 onward.
- Both digests were computed two ways, and the results matched:
  1. Python `hashlib.new('ripemd160')`, used by `tools/verify_collision.py`, which exits 0.
  2. The `openssl dgst -ripemd160` CLI (OpenSSL 3.0.13), with the raw bytes piped in through `printf`.

## Method
- Iterated function: f(x) = top 50 bits of RIPEMD-160(x encoded as 7 big-endian bytes).
- Ran a Pollard-rho walk with distinguished points (the low 12 bits are zero) from random starts. When two trails reached the same distinguished point, both trails were re-walked to find the step where they merge, which gives two different inputs with the same f value.
- The run took 78,740,803 evaluations of f, about 2^26.2, in 4 min 50 s on one CPU core. That fits the expected birthday cost of about 2^25 plus rho and re-walk overhead.

## Inferences
- The result follows from generic birthday search. It does not use any structural weakness of RIPEMD-160, and it does not say anything about the full 160-bit function.

## Uncertainty / open questions
- Input interpretation: I assumed the verifier ("SIMD") decodes a `0x`-prefixed value as raw bytes, as the task format suggests. If it hashed the literal ASCII string instead, the collision would not hold. I did not check this, because I have no access to the verifier.
- Truncation: I assumed "first 50 bits MSB" means the leading 50 bits of the big-endian digest byte string, which is the standard reading.
- This report makes no external factual claims, so it cites no web sources. All the evidence above is reproducible on a local machine.
