When the merge happens, the PoW software (the "execution client") will keep running transactions, but instead of choosing blocks by looking at miner hashes, it will look to the beacon chain to choose them. So stakers will run both the PoS client, and the execution client with the mining function turned off.
There's just too many escape valves. If you're a miner, you don't care about what network you're mining, you care about getting the most profit out of your hardware. There are several EVM PoW chains that are established, have been around and are listed and traded somewhere already, and have functioning contracts in them, and beyond that there are other non EVM PoW chains to direct your hardware at if you're running GPUs. It just doesn't make sense for a miner to take the risk of backing a new chain over moving their hash power over to an existing one.
At some point I'm sure they'll remove the legacy mining code, I just don't know whether they've done it yet.
Yes, definitely, and I'm sure all malicious actors made sure to disclose their exploits before it goes live, right? :)
Note that the current Ethereum consensus protocol does not support 100% decentralised staking pools yet.