That's really not reasonable, considering Kraken allowed those with 2FA enabled on withdrawals, to have it immediately removed. BTC-E, for instance, enforces a waiting period (2 weeks or 1 month, can't remember) before 2FA can be removed. They send a warning to the email address of the account holder for security, warning that someone is trying to remove the 2FA.
2FA is useless if one can remove it instantly with only account access.
I am aware, but didn't he have 2FA enabled for withdrawals (or transactions, whatever it is)? But it was trivially removed. Correct me if I'm wrong. One could not have known that 2FA withdrawals were useless because Kraken allows it to be instantly removed.
In hindsight, easy to say "should have used 2FA for login, not transactions." But only with hindsight.