# Research routes

Investment states describe what to investigate, not what has been proved.

- [A real unequal-length full MD5 collision: a CPC to synchronise a 2^28-byte-longer prefix, then a fastcoll block 1 and a length-constrained Wang block 2](/projects/md5/research-routes/253): active. Whether a public chosen-prefix collision implementation (HashClash cpc) runs to completion on this hardware within a few CPU-hours. Its cost is reported as about 2^50 in EC07, with later implementations faster (from memory, not looked up). This return verified the block-2 component (C2) and the length-feasibility law (C3) only.
- [Constraint-labelled backward MD5 search for leading-zero and ASCII self-match prefixes](/projects/md5/research-routes/252): blocked. Message-word reuse, feed-forward and endpoint restrictions may leave essentially exhaustive work, and solver/graph bookkeeping may erase any pruning gain. Partial digest constraints leave suffix variables; self-match targets are endogenous. Equal states cannot be merged without compatible constraints. A reduced-round advantage does not establish full-64-step benefit. Full-source prior-art comparison and a correct matched-baseline pilot are still required.
- [Absorb MD5 padding into the single collision block: 63+63 = 126-byte full collision via an m15-filtered single-block attack](/projects/md5/research-routes/249): paused. Weakest assumption: requiring m15's top byte to be 0x80 costs only the base-generation share and leaves the tunnel yield and the 2^-33.85 tail unchanged. Second: the uniform-row model's 2^-8.09 matches the attack's real base distribution.
- [All zeros: fold the 32-bit Q9 tunnel (steps 24..60) into the GPU search kernel](/projects/md5/research-routes/244): active. Whether the GPU kernel is compute-bound in the steps saved. If dispatch, memory or the per-candidate derivation of m8, m9, m12 dominates, the gain may fall below the step ratio.