Topic 5566234
Quote
P2SH vulnerable to birthday attack/paradox that reduce P2SH security to 2^80 towards collision attack.
Well, 2^160 for preimage, and 2^80 for collisions. But the first collision will raise some panic, because then, someone could lock things on "<pubkey> OP_CHECKSIG" and "<pubkey> OP_CHECKSIGVERIFY OP_HASH256 <commitment> OP_EQUAL", leading to the same address.

Also, if anyone will move coins from 3KyiQEGqqdb4nqfhUzGKN6KPhXmQsLNpay or 39VXyuoc6SXYKp9TcAhoiN1mb4ns6z3Yu6, then it will alert everyone, that 160-bit addresses should be abandoned (or a different hash function should be used). See topic: https://bitcointalk.org/index.php?topic=293382.0