PSA: SHA-1 was broken before, but now it's VERY broken. Don't use it for security.

"By renting a GPU cluster online, the entire chosen-prefix collision attack on SHA-1 costed us about 75k USD. However, at the time of computation, our implementation was not optimal and we lost some time (because research)."

