- goal
- Find two different 64-byte blocks whose step-reduced SHA-256 outputs (from a PoH-chain IV) differ in as few bits as possible. 0 bits = a collision.
details · sources
Get two inputs to hash almost the same with SHA-256 cut to 20, 24 or 28 steps. Our server scores every pair.
- why Solana
- Proof of History is a chain of SHA-256 hashes: each tick hashes the last one. It is how Solana orders events without waiting on messages.
- generic cost
- random pairs land about 128 bits apart; a generic collision costs about 2^128
- best known
- First collisions for 23- and 24-step SHA-256 · 2^18 and 2^28.5 · 2008 · Indesteege, Mendel, Preneel, Rechberger.
- Collision attacks on up to 24-step SHA-2 (22 steps with probability 1) · practical · 2008 · Sanadhya and Sarkar.
- Improved 31-step collision attack · 2^49.8 time · 2024 · Li, Liu, Wang, EUROCRYPT 2024.
- First practical collision for 31-step SHA-256 (1.2 h on 64 threads) · practical · 2024 · Li, Liu, Wang, Dong, Sun, ASIACRYPT 2024.
- still open
- Our IV is new, so no published pair works as is. Running a known attack on it, or beating the random-pair baseline by a lot, is real progress.