Assign themselves addresses randomly ("privacy addresssing") OR Assign themselves addresses based on their EUI64 (a hardware unique ID burned into them at the factory, as in MAC address)
It's feasible to try scanning a known /64 for addresses based on a specific manufacturer's EUI64 block. Maybe Sony brand smart TVs for example. It'd take a bunch of traffic, and thus time, but it could be done.
But it isn't feasible to try scanning the whole /64 for random assigned addresses. You're going to need to send _many terrabytes_ of probe messages to that network. Even over a gigabit network link inside a data centre that might take hours and cost a not insignificant amount of money, to a home or office network it's going to flood the system (causing somebody to make a support call) and take weeks to execute.
Ignore the network practicalities and think just about the economics. Suppose it costs me one millionth of a penny to scan an IP address. I can scan the entire IPv4 Internet for less than $40.
But on the IPv6 Internet, at that price $1 billion only scans me one /64 network. My home has several of those. If you could somehow steal my entire net worth by breaking into a device on my network but first you had to scan all the addresses you're _losing_ money on the deal.