# RIPEMD-160 collision in the first 48 bits

The requested collision was found. The machine-readable result is [collision.json](../collision.json), with exactly the four requested fields and lambda 24. Hex inputs represent raw bytes, not the text of their hex encodings.

## Observed evidence

| Field | Input A | Input B |
| --- | --- | --- |
| Input bytes (hex) | `494d444366ba5300` | `494d4443179ea601` |
| Full RIPEMD-160 digest | `7c2c007245ffcded466ee588803a217d37a2852b` | `7c2c007245ff824e8d05454bce6028fc908f2528` |
| First 48 bits (first six digest bytes) | `7c2c007245ff` | `7c2c007245ff` |

These values were recomputed locally on 2026-10-06 using [verify.py](verify.py), via Python's `hashlib.new('ripemd160', input)`, and separately via the OpenSSL 3.0.13 command-line command `openssl dgst -ripemd160`, receiving each raw input on standard input. Both checks returned the full digests above. The Python check also asserted the exact JSON key set, algorithm, lambda, distinct decoded inputs, and matching first twelve hexadecimal digest characters. It exited successfully with `verified: true`.

The search used OpenSSL's RIPEMD160 function on eight-byte messages: ASCII `IMDC`, followed by a four-byte little-endian counter starting at 1. A hash table identified candidates, and all six leading digest bytes were compared before accepting a match. Counters 5,487,206 and 27,696,663 produced this pair; the search stopped at counter 27,696,663. Candidate rechecks required additional hash calls beyond that number of enumerated inputs.

## Conclusion and limits

The observed byte sequences are distinct, and their observed leading six digest bytes agree. This establishes the requested 48-bit truncated collision under the stated raw-byte interpretation. Their full 160-bit digests differ.

Evidence attribution is to the local search and the reproducible local verification script and OpenSSL invocation described above. These are self-checks, not an independent review: Python and the command-line tool may share OpenSSL implementation code. The external SIMD verifier has not been run here, and its acceptance is unobserved. No claim is made of a full RIPEMD-160 collision or of a weakness beyond this particular truncated collision.
