The last problem for a zerocoin implementation is the generation of an RSA modulus for which no one knows the factorization. This is hard, and deserves more analysis.
If someone finds out the factorization, what are the implications? All the anonymous transactions become public?
No, but they can use the key to create fake zerocoins. (basically they can fake the proof that they added a zerocoin to the accumulator)