It's so easy, a bot can do it. (The joke, for those who don't know, is that bots will instantly redeem any invoices that are posted publicly.)
Would be interesting to see a trial, but would public invoices ever be an option? Eventually the bots will be able to scan images and then that protection option will be gone.
I have limited experience with eNuts, but I have my Nostr contact list loaded into it and I can see DMs working for payments.