Assuming that the attacker generated the constants used in Dual EC pseudorandom number generator it has been known for several years that an attacker generating these constants and seeing a long enough stretch of Dual EC output bits can predict all future outputs. This could be a problem since in the very early days of Bitcoin it was common to pay to public keys (P2PK) directly?