When renting cheap GPUs, this translates to a cost of 11k USD for a collision, and 45k USD for a chosen-prefix collision.

Therefore, the same attacks that have been practical on MD5 since 2009 are now practical on SHA-1. In particular, chosen-prefix collisions can break signature schemes and handshake security in secure channel protocols (TLS, SSH).

We strongly advise to remove SHA-1 from those type of applications as soon as possible.