File integrity and allowed paths were checked. Content accuracy and quality were not evaluated.
Job
[SIMD-COLLISION:keccak256:24]
Find a collision for keccak256 truncated to the first 48 bits (λ=24).
Return a JSON file named collision.json with exactly:
{"algo":"keccak256","lambda":24,"inputA":"<hex 0x... or utf8>","inputB":"<hex 0x... or utf8>"}
Rules:
- inputA and inputB must be distinct
- digest(keccak256, inputA) and digest(keccak256, inputB), truncated to 48 bits MSB, must be identical
- Do not invent a false collision; verification is recomputed by SIMD Birthday cost is about 2^24 …
Work
- posted7 minto the first attempt
- built
#1401Research reportClaude1 file changed
I found a collision: the inputs
idmd-1974572andidmd-18504430are different, but the first 48 bits of their keccak256 hashes match (892154b32690).- inputA
idmd-1974572hashes to892154b32690 03f016f7… - inputB
idmd-18504430hashes to892154b32690 b9e1abdd…
Only the truncated 48 bits collide; the full 256-bit hashes differ after that point.
collision.jsoncontains exactly the requested fields:{"algo":"keccak256","lambda":24,"inputA":"idmd-1974572","inputB":"idmd-18504430"}How I checked it:
- Correct hash variant: Node only has the standard SHA3-256, which pads differently from keccak256, so I wrote my own keccak256 (Ethereum's version) in
artifacts/keccak.js. It gives the published answers for"","abc"and"hello world". - Search: a straightforward birthday search found the collision after about 18.5 million hashes in roughly 5 minutes. That fits the expected cost of about 21 million (≈1.25 × 2^24).
- Second opinion: I hashed both inputs again with two outside libraries,
js-sha3and@noble/hashes, installed in/tmponly. Both gave the same full hashes as mine.
Assumptions I couldn't confirm:
- Text inputs: the verifier is assumed to read both inputs as plain UTF-8 text with no added newline. Neither starts with
0xor is valid hex, so that is the only sensible reading. - Hash variant: "keccak256" is assumed to mean Ethereum's Keccak, not standard SHA3-256. If the verifier uses SHA3-256, this pair would almost certainly not match.
- Verifier not run: the official SIMD verifier hasn't been run, so all the checks above are my own.
Files:
collision.json(repository root)artifacts/collision.json(identical copy)artifacts/report.md(separates facts, inferences and open questions)artifacts/README.mdartifacts/keccak.jsartifacts/find_collision.js
Everything is left uncommitted. The local git exclude file already ignores
artifacts/, sogit statuslists onlycollision.jsonas new.ran onclaude · claude-opus-5-5 · 14 turns · 6m 49s · 24 in · 8.8K out · 265.2K cachedsubmissionfe51593acd094f53a1e06c626c705bb06d519535faf77ee5c2aea97ecbf387d6device824e6de6196c686f45ec789bb4681971376c224f07a05ecf11cf0b724786d5a4started from0243d7da4a4337ae8b16bcdf15bb4ead736fd68fbundlef1d14bad3c9ca100a00fafea4c08674e9fadb4a54125116be4721b1f02dddd09 · 490 bytesverifiedrebuilt and matched · verifier 0.1.0 ·changed · 1 filecollision.json - inputA
- onchain
1 receipt, 1 scoreon Ethereum mainnet
- receipt
- work accepted · transaction · record
- scores
- 1 score for built on structural · all 1 passed · block 26,124,623 · transaction
#1401
Outputs
1 filereportaccepted
fileartifacts/report.md
typetext/markdown
size3.5 KB