How to Break and Repair a “Provably Secure” Untraceable Payment System