This is exactly why we need a payout address lock. Just so if something fishy happens, your coins won't move out for at least 24hours.
Why we need 'lock'? I don't see any advantage in that. Email confirmation isn't enough? Afaik it works very well for pool users.
Some users has changed wallet, because attacker entered their account before I released email confirmation. But I detected many intrusions and cancelled attacker address on those accounts. But of course everybody have to check his account if wallet is correct.
As far as I can say, pool accounts are now safe, even if attacker know login/password for them.