Changing a certificate check in a binary is just finger exercise for anyone serious about reverse engineering. "Hard-coded" does not mean what you (seem to) think it means...
Also, TPB has trusted uploaders, so you can be reasonably sure you aren't installing malware. I'd wager many of the cracking groups have a higher reputation than EA.
If you will install a crack, you will install a crack, no questions there. But if don't hard-code a CA then people who might otherwise be hesitant to pirate because it involves a crack program would be perfectly happy to follow a couple steps they find in a blog post.
they are already nearly indistinguishable from malware.
your average anti-virus program will flag a cracked executable every time, and you can routinely spot the less savvy users by viewing any torrent comment section and looking for "AVG FLAG AS TROJAN DO NOT DOWNLOAD"