This has been exploited in practice by Bitcoin thieves. They replaced the cold-wallet address in a hacked server so that BTC got redirected to them, and they vanity-generated their addr to match the first and last chars of the original and this successfully fooled the victims.

