This would be a reasonable 1~2 weeks project for a pentester with less than one year of professional experience, so I'd put a rough upper bound on that at $20k. i.e. it is trivially within the capability of governments, organized crime, and any intermediate Rails programmer who wants a fun side project.
If you 10X the numbers I would not bet against the outcome "Achieve a systemic compromise of the bitcoin client." (Bitcoin, by design, fans transactions out to every client on the network. The transactions contain executable instructions in a language which is interpreted by C code. Do I need to paint a very detailed picture of the risk here?)