# RIPEMD-160 collision, first 48 bits (λ = 24)

The distinct eight-byte inputs in `collision.json` have identical first six digest bytes. Hex strings represent decoded bytes, not literal UTF-8 text.

| Field | Value |
| --- | --- |
| inputA | `0x19bef10000000000` |
| inputB | `0x1022730100000000` |
| RIPEMD-160(inputA) | `902e5fc86be47b1e2a17de2aab65d4e765623a05` |
| RIPEMD-160(inputB) | `902e5fc86be4a99253faddc650510cb85e77233d` |
| Shared 48-bit MSB prefix | `902e5fc86be4` |

## Evidence and method

These values were computed locally, not inferred from published claims. The delivered `artifacts/search.c` enumerates eight-byte little-endian counters and stores candidates in an open-addressed table. Every candidate match compares the first six RIPEMD-160 digest bytes. It found counters 15,842,841 and 24,322,576 after searching 24,322,577 distinct inputs, starting at zero.

The delivered `artifacts/verify.py` reads the actual JSON, checks its exact keys, algorithm, lambda and distinct decoded inputs, recomputes both full digests using Python `hashlib`, compares them with OpenSSL CLI results, and asserts equality of the first six bytes. Running it completed successfully and printed `"verified": true` with the hashes above. OpenSSL on this machine reports version 3.0.13.

## Reproduce

From the repository root, verify the delivered result without repeating the search:

```sh
python3 artifacts/verify.py
```

To repeat the deterministic search on Linux with GCC and OpenSSL 3's system `libcrypto.so.3` installed:

```sh
mkdir -p test/scratch
gcc -O3 artifacts/search.c -Wl,-l:libcrypto.so.3 -o test/scratch/search
test/scratch/search > test/scratch/reproduced.json
cmp collision.json test/scratch/reproduced.json
```

The search uses a 256 MiB table. No network, secrets or external data are used. No packages were installed. System GCC, Python and OpenSSL are runtime prerequisites, not vendored dependencies.

## Limits

The full 160-bit hashes differ: the demonstrated collision applies only to the requested first 48 bits. Python and the CLI provide separate checking paths but may share the same underlying OpenSSL implementation; this is a local self-check, not an independent cryptographic implementation or SIMD attestation. SIMD verification has not been run here. There are no remaining unknowns about the locally computed prefix equality.
