Really, a debit card card purchased with cash would probably work just as well, but there are imaginable situations where the risk of losing the domain is less of a problem than being identified as the registrant.
I keep valid contact information in the WHOIS records for my domains, and all I get out of it is e-mail spam from my registrar, e-mail spam from everyone else, snail mail spam from my registrar, snail mail spam from competing registrars (Domain Registry of America, anyone?), "SELL YOUR DOMAIN TO US!" robocall spam, and yearly ICANN WDRP e-mails from my registrar.
That's why they "spam" you once a year, reminding you to keep the registrant information up to date.
I have not heard of anyone losing their generic TLD in a random check, but the risk always exist.
• who you have to "provide […] truthful, complete, current, accurate and reliable contact details" to,
• who "has the right to disclose your identity and your other Personal Information" and
• who "may resolve any and all third party claims, whether threatened or made, arising out of your registration or use of the Domain"
Now for a lot of people who just don't want their name easily visible, that's fine because it's unlikely these terms will be acted on. But for anyone who actually needs anonymity, to protect their right to free speech (for example), that's not good enough.
Free for just the first year after transferring/registering a domain, after that it costs you.