I agree that it would be nice if Pi images were more easily configurable “offline”, but even as somebody who knows all about the linuxes I would rather they moved more in the direction of taking good security out of my hands. Every time I re-image a computer I get a little bit lazier.
I feel like given the most common threat model for the average hobby project, a good default would be if the Pi gave you a reasonably strong random password and told you to stick it to your Pi on a post-it.
Worm as advertising? It’s unfortunately plausible, especially given that anything that raises the profile of an iffy, second-rate cryptocurrency will hugely increase its value.