Same question: Ok we may not be able to brute-force it today for less than $1bn, but tomorrow, may a vulnerability in the algorithm make it possible to regenerate the private key?
- Generate private keys at a rate in which you will be able to produce it in a reasonable time
or
- Outright reverse engineer the private key from the public key or other metadata
Then Bitcoin is broken and that 1bn is worth next to nothing.
They could also short Bitcoin before intentionally crashing it.