Every DSA signature requires a random nonce/key k. If k is predictable, DSA falls apart. We demonstrate that here:
http://cryptopals.com/sets/6/challenges/43/
The same problem occurs in elliptic curve DSA, which is just the DSA construction implemented on the elliptic curve discrete log.
What's also true is that if part of the nonce is predictable (or leaked), DSA falls apart --- albeit over more than just a couple signatures. With tens of bits leaked, you might needs hundreds of thousands of signatures.
How would you ever leak part of a nonce over thousands of signatures? One easy way is to generate a nonce that appears cryptographically random, but doesn't fill the modulus. For instance: a 128 bit random number sure seems strong, but if it's filling a cryptographic parameter that's meant to be 256 bits long, fully 128 bits of that parameter are predictably zero.
Here, though, you have a predictable nonce bit leak that can occur purely by accident even given a reasonably sound implementation!