To me, the slippery slope seems to be, how do you know that all the exploit did was obtain the IP address, and not add or alter files on the filesystem, or allow the system to be further compromised by other parties?
I don't think a warrant for specific information changes that calculus; collecting additional information outside the scope of the warrant would be illegal regardless.