If all 6 impacted CAs stop signing MD5 signed certs today and no new CAs started, is the risk reduced to the possibility of prior discovery?
I have root certificates in my browser that are valid from 1998 to 2018. It's not so easy to verify that this attack didn't already happen 5 or even 10 years ago.
Personally I think it's extremely unlikely, especially since the chosen prefix collision attack they used has only been public for less than two years, but how could you know for sure?
We're also focusing on the algorithm, but not really accounting for the fact that simply owning a cluster of PS3s doesn't give you the optimized math code that generates the birthday bits during the weekend window. That code is itself presumably harder to write than any zero-day exploit.