# SHA-256 truncated to 48 bits: collision found

The requested collision is in [collision.json](../collision.json), with exactly
`algo`, `lambda`, `inputA`, and `inputB`. Lambda is 24; the comparison covers the
first 48 most significant digest bits (the first six bytes).

## Observed results

| Input | Hex-encoded bytes | Full SHA-256 digest |
| --- | --- | --- |
| A | `0xe8f1380000000000` | `67171c0eb1922b1b1e7b76dd2213a661d3542f3c6b00e39279800abaaf50b502` |
| B | `0x23f68e0000000000` | `67171c0eb192a147eff93d18c3adf2a803bba554778ef76416669125a3a46e19` |

The two eight-byte inputs are distinct. Both digests begin with **`67171c0eb192`**.
The `0x` prefix denotes hex decoding; it is not hashed as text.

## Method and attributable evidence

A local C search hashed successive unsigned integers, starting at zero, encoded
as eight bytes in little-endian order. It used OpenSSL 3.0.13 SHA256 and a hash
table of six-byte digest prefixes. The matching integer values were 3731944
and 9369123, found after 9,369,124 candidate evaluations. The search
also rehashed the earlier candidate to confirm the match.

The delivered [verification script](../tools/verify_collision.py) independently
recomputes the submitted inputs with Python's standard-library `hashlib`, checks
the exact JSON key set, algorithm, lambda, distinct decoded bytes, and equal
six-byte prefixes. Run from the repository root:

```sh
python3 tools/verify_collision.py
```

Its successful output
is preserved in [verification.txt](verification.txt). A separate invocation of
`openssl dgst -sha256` on each decoded input also matched both full hashes.
These are local computational observations, not external citations or independent
review. Python and the OpenSSL command may share the same underlying hash library.
The verifier requires only Python 3 and its standard library, with no network or
third-party installation.

## Conclusion and limits

The measured bytes satisfy the requested 48-bit prefix equality. The complete
256-bit digests differ; this is not a full SHA-256 collision. No probabilistic
inference is needed to establish this particular equality. The external SIMD
verifier was not available in this session, so its acceptance remains unobserved.
