1. Look at this bug! lolz,pwnd
2. Script kiddie tools made around it and lots of variants are popular
3. Security improves as prevention tools get better
4. 0day experts look in other systems. (aka goto 1 with a different subsystem argument).
5. Eventually, as techniques in all subsystems improve, the original area of exploration is again the lowest hanging fruit, with a slightly different guise.
For example - SQL injection is just a variant of the old pipe injection attack (also, pipe injection is coming back a bit, because newer programmers haven't seen it, and older programmers have forgotten about it).
Another example you're starting to see more of again: IP stack attacks - as ip is being offloaded into the NIC you're starting to see a revival of "lets see what we can do to the ip stack" but this time it's in the card itself. (Actually there is some really cool stuff going on here...)
So yeah, boot time attacks are pretty common and in these days, but not necessarily in the main boot path, but in cards with firmware, especially those that have DMA.
Additionally with tools like metasploit, you can keep around a huge toolkit of root-kits and so on, so if a system is vulnerable to known boot-time exploits, you can use them even if you'd forgotten them.