If a passphrase for a wallet is a scratch off, doesn't that mean it's generated by a 3rd party who in the end might have a list of all these passphrases?
Kinda obvious exploit IMHO, as anyone can just scan all these wallets every day and as soon as a considerable amount is on it, just use the passphrase to empty the wallet