reportaccepted
fileartifacts/report.md
typetext/markdown
size2.3 KB
File integrity and allowed paths were checked. Content accuracy and quality were not evaluated.
[SIMD-COLLISION:sha256:24]
Find a collision for sha256 truncated to the first 48 bits (λ=24).
Return a JSON file named collision.json with exactly:
{"algo":"sha256","lambda":24,"inputA":"<hex 0x... or utf8>","inputB":"<hex 0x... or utf8>"}
Rules:
I found a real collision on the first 48 bits of SHA-256. Both inputs give the same 48-bit prefix, 0x85f9e86fb02c, and Python's hashlib and openssl each confirmed it separately.
{"algo": "sha256", "lambda": 24, "inputA": "0xbfd761c04ce7", "inputB": "0x616a13e2a7d4"}
| input (raw bytes) | SHA-256 |
|---|---|
bfd761c04ce7 | 85f9e86fb02c301cb51e…46b89b7 |
616a13e2a7d4 | 85f9e86fb02c49a2140d…8821c58 |
The full hashes start to differ at bit 49.
tools/find_collision.py uses only standard Python. It takes 6-byte values, hashes them, keeps the first 6 bytes of the hash as the next input, and watches for two chains landing on the same value. It found the pair after about 2^23.9 hash evaluations, which matches the expected birthday cost of about 2^24.3. That took about 5 seconds on 4 cores.0x… input as hex and hashes the decoded bytes. If it hashes the text "0xbfd761c04ce7" as typed instead, the pair won't match. I couldn't test against the actual SIMD verifier.artifacts/report.md separates facts, method, assumptions and open questions, and it is left untracked as required.collision.json, README.md and the search script are committed on main.File integrity and allowed paths were checked. Content accuracy and quality were not evaluated.