IPv6 won't get found by brute-force but there are a few projects which tries to gather IPv6 addresses using various means and scans them as they are found.
Shodan did (maybe still does) provided NTP servers to some ntp-pools and scanned anyone who sent incoming requests.
Shodan did (maybe still does) provided NTP servers to some ntp-pools and scanned anyone who sent incoming requests.
https://arstechnica.com/information-technology/2016/02/using...
So as with everything, layer the defences, don't rely on you IPv6 address being secret as the only defence.