After all this is patched and fixed, Badspot, I want to propose an idea. I've got a good resolve for the victims of the BL Key theft stuff. I don't know how possible this is but please take it into consideration.
Badspot, perhaps you could setup a "BL Key re-roller" for the accounts who had theirs stolen. Have it be an email verification thing, so that you have to supply your original purchase email address (and maybe your original key), and then you have to click a verification link through an email to that address (or perhaps be emailed a verification code), and only then will you get a new BL Key through email, or something. It should also register the old one to be invalid, and never utilized again, perhaps added to a blacklist. I think this could resolve the issue once the exploit is completely patched.
(Also I didn't read many of the other posts, so sorry if somebody already thought of this.)