I'm unfamiliar with AirDrop, but is there any reason it _has_ to work with phone numbers? Would sending nonce+hash(AppleID+nonce) work? I suspect an email address would have significantly more entropy than a phone number (36^6 * 4 ~= 10^10, so six alphanumerics plus four common email domains has about the same entropy (assuming random distribution-you could make better guesses)).
One downside is that it may be make targeted attacks easier (if you can guess the approximate form of someone's email address, you can easily confirm it), but that doesn't seem like much of a leak if you can already guess sufficiently closely. Sending hash(nonce+AppleID+phone number) might be an option, but that feels more limiting.