This is a very interesting discussion, as always. Thank you! I can't disagree with your analogy, except to say that maybe it is going to be necessary to think differently about information security than physical security.
A question to your question: How does the discovery, testing, and disclosure of this vulnerability differ to something like Spectre and Meltdown?
Researchers who discover vulnerabilities in hardware or software, including flaws in cryptographic stuff (to try and make the key analogy fit), often build a proof-of-concept exploit. They certainly test that exploit against vulnerable hardware or software. The only difference is that they have the luxury of being able to buy or set up their own vulnerable component to attack.
My thesis, in short: You have to validate the vulnerability. Otherwise you risk crying wolf.