they would still technically have to log in
And your point. If your username is your login, then all I have to guess is the pass, which I could try to scam from you or attempt to guess. Either way, if I get in, I'll be able to get your key. And account hacks have happened before (though they could hardly be called hacks, more like "one password for all" idiocy).
This is apposed to me having to try to find your email, break into it and look to see if it's the one that the key is in. If it is, great, that was time consuming. If not, I have to do the process over again with another suspected email.