I recently calculated the cost of 50% hashing power in ASICs, and it was something like $1M.
Even if the hash rate grew 10-50x it would cost less than $50M. Well within reach of governments or large corporations.
That said, as adoption and thus the value of Bitcoin increases, the incentive to mine and thus secure the network rises, so there's a nice feedback loop.
Firstly, your numbers are off. If the hash rate grew by 50x, we would be at 3.5 Phash/s, so the attacker would need to deploy another 3.5 Phash/s to attack the network. And Butterfly Labs's ASIC price is $50 per Ghash/s. So it would cost $175M.
Secondly, you cannot buy $175M of ASICs from BFL; they are too small of a company.
Thirdly, by the time you design, build, and deploy ASICs yourself (12 months+[1]), the network would have grown again, maybe by another 2x/5x/10x, who knows... you would have needed to account for this by spending respectively $350M/$875M/$1.75B !
So effectively by the time the network reach 3.5 Phash/s, it will be too late.
[1] For comparison it took more than a year for the DOE to deploy the #1 supercomputer, Titan, out of commodity hardware.
Well, my calculations used BFL's Mini Rig SC, which was $20 per GH/s before they increased prices ($30k for 1,500 GH/s).
You would certainly need to fab your own ASICs, and at that volume economies of scale would come into play, so I don't think $20 per GH/s, or even less, is an unreasonable estimate.
Current hash rate is 65,000 GH/s (I think calculated around 40 or 50), so 65,000 * $20 = $1.3M. 50x that would be $65M.
Avalon didn't take 12 months to ship, and I know someone who claims to have one of them making money, so they appear to work. Why butterfly labs is so late, I dunno.
If someone with money wanted to build asics for a 51% attack, it's possible. I'm just not sure anyone with money wants to do it right now.
It's because they originally designed around a QFN packaged chip - later switching to a flip chip BGA (FCBGA) package.
There was (and is) hardware on the market that could be adapted to work - but the folks who sell hardware based AES256 applications tend to deal only in the financial/military circles.
Being 'first to market' in btc ASICs didn't seem to be their top priority (much to many peoples dismay).
You don't need to build more hardware than everyone else if you combine a denial of service attack at the same time. The block chain has already had issues, perhaps it will never happen again but don't assume it's impossible.
Rumor has it that Butterfly has been sitting on their preorders and using it to build a massive ASIC fleet. Whether or not these are true, as you suggest, building a 51% fleet is not out of reason if you take the right path and keep your mouth shut. There has already been forks of the blockchain due to powerful miners.
These forks are not caused by powerful miners. They are caused by miners mining 2 blocks almost at the same time. And the fork of March 14 was caused by a bug.
Even if the hash rate grew 10-50x it would cost less than $50M. Well within reach of governments or large corporations.
That said, as adoption and thus the value of Bitcoin increases, the incentive to mine and thus secure the network rises, so there's a nice feedback loop.