A Small Subgroup Attack on Bitcoin Address Generation