You have to verify access to the email with a code to do the merge. That solves your issue
If someone has persistent to your main email account you will have all kinds of problems.
The problem statement says this about corrective action:
>I discover the hack and change the passwords on every account I know about
In actuality, the corrective action is to change the passwords and revoke any SSO integrations.
To the original point, this does add more overhead to the process, probably isn't obvious to most people, and depends on the site having clear UI for the topic.