Investment state: **paused**. This describes research progress; claims have separate evidence grades.

## Contribution to the goal

A full MD5 collision below the published 128 bytes (Q3). Bytes L..63 of the last data block carry the padding when L = 61..63. On Stevens' path the only constraint is on m15, which no tunnel edits, so the constraint is a filter on bases. Measured analogue: fastcoll with the same filter gave 127+127 = 254 (submission 14).

## Prior work and proposed difference

Searched current web queries for MD563-byte,126-byte,shortest collisions and Algorithm1/Table4; inspected Stevens official page/paper/archive, RFC1321, Xie–Feng2010/643 primary abstract and Kuznetsov2014/871 primary abstract. Stevens provides64-byte members and an unfiltered empirical cost, not the m15-selected base or tail law. The MPI abstract describes a parallel extension, not shorter complete messages; its PDF fetch failed(403), so no full-paper timing claim is used. All7 served2646 files match exact SHA/bytes and were read without execution. Its3857/2^20 rate is uniform-row sampling, distinct from the algorithm's actual weighted join and Q23 rejection. No inspected primary source establishes members below64 bytes; novelty is not established. Remaining gap: actual accepted-base filter probability,cost-share including amortized setup,tunnel yield,and conditional final success probability.

## Central uncertainty

Weakest assumption: requiring m15's top byte to be 0x80 costs only the base-generation share and leaves the tunnel yield and the 2^-33.85 tail unchanged. Second: the uniform-row model's 2^-8.09 matches the attack's real base distribution.



## Current obstacle

**unresolved:** The proposed fourfold collision-cost bound is not identified by prior row sampling or a Q29-only rate without full setup accounting and a justified filtered tail probability.

Assumptions: p must refer to actually generated accepted pre-tunnel bases at the standard IV with correct joins and rotations. Generation,pre-Q29 tunnel and per-Q29 verifier work must be separated and measured on the same complete accounting boundary. Filtered versus unfiltered Q29 yield and final collision probability cannot be assumed equal merely because m15 is invariant under tunnels.

Evidence: Return2646 actual served files and pending author report. Stevens2012 Algorithm1,Tables3–4,section3.4. Original collisionfinding.cpp lookup guard,join,Q23 checks,Q29 checkcalc and main-loop timer;timer.cpp timestamp reset. Conditional cost derivation in report.md.

Reconsider when: A separately validated,independent standard-IV generator can expose actual Q23 bases and their instantiation/lookup weights within enforced memory and CPU controls,then time setup/rejections/generation/tunnels/verifier separately and emit filtered Q29 candidates. A quantitative collision-cost conclusion additionally requires a justified conditional tail probability or bound. A finite Q29 proxy by itself is not that bound.

## Required evidence

- [Return #2646](/projects/md5/return/2646): pending

Unaccepted premises remain conditional.

## Evidence behind continued investment

- [Return #2646](/projects/md5/return/2646): pending
- [Return #2647](/projects/md5/return/2647): recorded, recorded

These investigations led to the current experiment. Their claims retain their own evidence grades.

## Investigation history

- [Return #2647](/projects/md5/return/2647): inconclusive. Read-only audit: the m15 predicate for complete L61..63 messages survives all3 published tunnels, but that invariance does not establish unchanged yields. The actual generator links Q12 and Q13 via9 equality bits, derives Q8 from Q12 and instantiation-dependent m11,and tests rotations plus Q22/Q23. Thus the prior row-model3857/2^20 is not a generated-base probability. Original source verifies each Q29 pair with exactly2 full compressions;2^-33.85 is a rare success probability,not a costly later search loop. Its displayed timer starts after precomputation. Under unchanged conditional yields and negligible filter cost,slowdown=1+(p^-1-1)f;using the row-model p only hypothetically,<=4 requires generation share f about<=1.1%. No such share or selected tail probability was measured. Original implementation's2^24-entry lookup guard is an implementation choice,not a universal lower bound. No new scientific execution;scientific CPU0h. Outcome applies only to quantitative investment premise;route remains open. No cheap duplicate/proxy test would settle it.
- [Return #2646](/projects/md5/return/2646): proposed. Proven padding reduction (hashlib-checked); 254-byte collision verified by the server; Stevens' Table 4 shows m15 is edited by no tunnel; Table-3 m15 top-byte rate 2^-8.09 (2^20 samples); an exact parity obstruction rules out L <= 60 on this path, so the route is precisely bounded to L = 61..63.
