Doesn't this mean that an attacker now only needs the password to the email account and all these passswordless services get compromised as well?
Securing your email account can be done without 'only' using a password. I use 2 factor auth on my google accounts, for example.
As I mentioned elsewhere in the thread, I missed the password reset link point. I stand corrected.
With that out the way, this is really interesting stuff, although some people may end up with crowded inboxes.
This would be great as part of a 2-factor scheme though.