You made a good point. Someone's acount can also have weak password.
But isn't there any difference between passwords locking common users accounts and these unused with NXTs sent there by mistake? Isn't it different format of password like random string + ending with string of zeros?
If there is a difference we can simply create a standard for treasure hunting of only these lost NXTs.
If u use SHA256(Curve25519(Random256Bits)) instead of SHA256(Curve25519(SHA256(RandomChars))) to hack the accounts then u still will be a good guy.