pull down to refresh
Is the mechanism of the vulnerability that people are watching some of these easily derived addresses just in case someone is dumb enough to use them?
In part. I.e. try any password that is in anyone's password dictionary with billions of entries, through a classic brainwallet, and your funds will even be fought over by multiple people watching these. Same for standard derivation of low amounts of dice rolls with all the known algos. It takes longer for you to read what is on 3, maybe even 4 dice you just rolled than for a modern gpu to calculate the entire range of possible outcomes.
The other part - what is going on now - is that you can just explore a novel search space and find keys as you explore and sweep as you find coin. Like digital mining for gold.
I suppose someone could look at my writing
This would be mostly damaging if this is an expired or low value seed and you have the same bias sitting in other, more high value seeds. Patterns, even ones that you're not aware of can be found. Some weakening is acceptable though, true random means it's also possible you hit exactly the outcome of the sha256('secret') brainwallet - just extremely unlikely.
Addendum: I hear people worried about 70+ bits, but even though that is not acceptable long-term, that search space is already huge. It just means you should fix it now.
Possible but extremely unlikely is the entire security framework, right?
This gets at part of what I'm wondering about.
Is the mechanism of the vulnerability that people are watching some of these easily derived addresses just in case someone is dumb enough to use them?
In the case of me choosing 12 words, I suppose someone could look at my writing and see what words (or kinds of words) I like and that would reduce the search space. Maybe there are also useful patterns in which kinds of words people generally pick, which would make my habits a refinement of a refinement.