I would make it optional (just like token request is optional). If you want that extra layer of security of being email verified over BTT verified then you send Patmast3r / xtester a message containing your email.
Just a reminder that, once you send out that message, that you delete your sent outbox (so if your BTT is compromised then whoever has your account can't find out what email you gave Patmast3r / Xtester)
Such a pm could also come from an overtaken account so there is really no way to know if the email will be legit.
My advice is to store the token (I hope we can send out really soon) somewhere other than btt and then delete the pm. After that you can do with your btt account whatever you want
It's an individuals responsibility to report their account being compromised as soon as possible (ASAP). NEM has been in pre-release for a long time now. Hasn't there been two previous breaches prior to the current one? Seems like if you had an account compromised for months and didn't report it then it was probably a forgotten account to begin with.