TLS certs for IP addresses for providers who change them?

This thread reminds me a lot of the discussion ten years ago about the 90-day cert lifetime, where people would invent increasingly-improbable scenarios to illustrate why those certs just couldn't be used for them. With ten years' history behind us, it's evident that the vast majority of those concerns were, at best, exaggerated.

Similarly here--it seems the "vulnerability" you're envisioning would require a pretty strange series of coincidences. Most significantly, someone hosting a service on a dynamic IP address, advertising that dynamic IP address as its address, while knowing that IP address wouldn't be very stable. People do foolish things all the time, but this still seems like a bit of a stretch.