Let me put some round numbers on the cost of various attacks:
Major result in cryptography: $X0 million to $X00 million+ (nation-state adversary)
Subtle bug in the Satoshi client C code: $100,000 (trivially within the reach of organized crime or a single highly motivated attacker)
Bust any Bitcoin-using Ruby on Rails (&tc) application: $20k probably, upper bounded by $100k where you'd produce (as an industrial biproduct) a RCE on any arbitrary Rails site
Compromise the security of a non-trivial number of Bitcoin users via spearphishing / targeted malware / etc: $1,000
If you're a thief who doesn't have access to any computer skills or the above sums of money, have no fear, it is likely that the Bitcoin economy still has multiple options for you to get in on the ground floor of exciting new ways to steal things.
[P.S. I'm routinely pessimistic about Bitcoins for a lot of reasons, but the software security angle keeps coming back to me because it's so easy to explain. If you think I'm overly pessimistic, consider the track record on HN of "people who know what the threat environment banks operate in looks like" versus "Bitcoin advocates" has been in predicting observable future outcomes of e.g. Bitcoin bucket shops in advance.]