Could Send links be crawled?

Send links can be accessed by anyone, so I had a thought, would it be possible to create a bot that looks for them?

If so, then if it finds a working link, if it’s not password protected, it could just scrape that data.

Does the security of this simply rely on the fact that the number of possible Send IDs + encryption keys is SO large that it’s effectively impossible to brute-force them?

Is there a way that a bot could find working Send URLs without having to straight brute-force them?