Some days I feel like this:
Teacher: “Can anyone find the flaw in this security system?”
Student: “The keys hide a secret that can be used to decrypt all the data if they are compromised.”
Teacher: “Excellent! Exactly right, but if these keys are compromised then the whole system is probably already lost.”
Duh. At least the weather was nice for a ride.
Hmm… I hope this was not me. If it was, I meant that the compromise of the “well known” part of the key, not the static part, could be guessed as in the cypher process for some Cisco passwords.
The other answer, being the one you noted, is that if the key-encrypting-key was ever compromised, then we have a problem — probably that the application itself was decompiled, etc.