But then again, you can always reset the password if you made a typo.
- Username and password should enable you to change the email
- Email alone should enable you to reset the password
So there is no risk in removing both duplicate fields. But maybe by now it's expected to type in a password twice. Users might be so used to it that it feels wrong to only insert it once.