It's less about the gil and more about the implications of such a glaring loophole in account security. =P
Who needs a one-time password token when they don't even need to steal your account info in order to rob you?