Fair enough, supercomputers + cloud was optimistic. They can’t do 40 zettaflops.
Half of that, worst case, we could, though not triviallt. For bursts at a time. (Worst case because the math supercomputers designed to break encryption do is similar to that required to break Bitcoin.)
Practically speaking, were we to do this, we’d procure the ASICs. (And target in-jurisdiction mining, lowering the hurdle.) No private party is particularly incentivised to launch such an attack de novo. We may never need to actually attack: a law appropriating tens of billions to create a crypto deterrent would crash prices on its own.