Unfortunately Im not sure if the passkey specification allows for those extra validation steps or not.Apple could implement an additional security layer to change anything by having the person verify something that the thief would not know like a emergency contacts full name and phone number.
Sucks for the original poster that Apple didn’t have additional security measures in place.
Hopefully 🤞 Apple fixes this at WWDC with iOS 17.
Apple quickly fixed the iCloud exploit with 2FA that exposed so many celebrity private photos
This authentication method is the new industry standard.