Improved Collision Attacks on 36- to 39-Step SHA-256
We give two-block differential collision attacks on 36- to 39-step SHA-256 from the standard IV. In the declared cost model their estimated costs are 2^44.6, 2^65.9, 2^83.6 and 2^91.2 reduced-step compression evaluations. The previous best attacks cost 2^57, 2^79.1 and 2^104.3 for 36 to 38 steps, and the characteristic-based estimate for 39 steps was 2^168 (Li et al., ePrint 2026/1120). The 38- and 39-step attacks use a 17 GiB preimage table. The 39-step estimate is below the generic birthday cost 2^128. For each first-block chaining value, we enumerate second-block completions by solving message-expansion equations or matching lists, and we estimate success using modular differences. All costs combine measured rates with stated probabilistic assumptions. The 37- to 39-step attacks remain theoretical. The 36-step attack is practical: it produced 18 new colliding message pairs, all verified independently, where one 36-step pair had been published before. The research, including the attacks, experiments, verification and text, was carried out by AI agents (Anthropic Claude models as researchers, writers and verifiers; OpenAI GPT-6-Astra as reviewer and editor), directed by the author. No human cryptanalyst has yet verified the results independently. The 36-step collisions can be checked with the included scripts. This record contains the paper (PDF) and the complete package: LaTeX source, code, data and reproduction scripts.
Authors
- Omer Goldzweig
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-30
- DOI
- https://doi.org/10.5281/zenodo.23066177
- Primary Topic
- Cryptographic Implementations and Security
- Type
- preprint