I would not say pay to pubkey isn't safe at least currently too, but, yes, bc1q is either P2WPKH (pay to witness public key hash) or P2WSH (pay to witness script hash), so has the same security as 1... (P2PKH) and 3... (P2SH) addresses.
clearly pay to pubkey is still currently safe or there would be 4 million bitcoin getting stolen out from those vulnerable addresses :)
The cost to attack vs the value of the target is the most important metric. If the shitcoins have enough swappable value, they will be attacked as well--and actually maybe easier targets because most people won't care if some random crypto gets hacked--the bitcoin crowd won't necessarily think we've hit a point where these attacks are possible, so if I were an attacker, I'd probably start liquidating alts before hitting bitcoin.
reply