# SHA-256 48-bit truncated collision (λ=24)

## Answer
`collision.json` (repository root):

```json
{"algo":"sha256","lambda":24,"inputA":"0xfb0a23bef7bd","inputB":"0x112e1c6a8729"}
```

Both inputs are the **raw bytes** decoded from the hex (6 bytes each), not their ASCII text.

## Evidence (facts — reproducible locally)
| input (bytes) | SHA-256 (full) |
|---|---|
| `fb0a23bef7bd` | `e8da33fff172`ff026fd85de533f959cdbc2b2ba6a1d8e1c6bde88fa94f54a11b |
| `112e1c6a8729` | `e8da33fff172`70a5b213c20ab4b7c8e18a0518c2d89ff2a061067e0ce7e383a5 |

- The first 48 bits (12 hex digits, MSB first) are identical: `e8da33fff172`.
- The inputs differ, and the full digests differ after bit 48, so this is a real truncated collision and not a duplicate input.
- I checked the digests two ways: with Python `hashlib` (the search tool) and with GNU coreutils `sha256sum`, using
  `printf fb0a23bef7bd | xxd -r -p | sha256sum` (and the same command for the other input).

## Method
`tools/find_collision.py` runs Floyd cycle-finding (Pollard rho) on
f(x) = SHA-256(x)[0:6], starting from `f(b"imd-seed-0")`. When the tortoise and hare meet, the tool walks back to the cycle entry. That gives two distinct 6-byte preimages that map to the same 48-bit value. The search found the collision on the first seed. It took about 40 s of CPU time in CPython, which is a few times 2^24 SHA-256 evaluations, as the birthday bound (√(2^48) = 2^24) predicts. The tool uses constant memory.

## Inferences / assumptions
- "Truncated to 48 bits MSB" is taken to mean the first 6 bytes of the big-endian digest, as SHA-256 conventionally outputs it.
- The task allows "hex 0x... or utf8" inputs. I assume the verifier hex-decodes values that start with `0x`.

## Uncertainty / open questions
- Not confirmed: whether the SIMD verifier hashes the hex-decoded bytes or the literal string `"0xfb0a..."`. If it hashes the literal string, this pair would not collide. The task wording suggests it decodes hex.
- No external citations are needed: the claim is fully checked by recomputing two hashes.
