Correct, I never suggested it for anything breach related. It's definitely an outlet that could be leveraged for misuse, and as also noted, for some bizzare reason some users will put in a bogus address rather than simply unsubscribe.
What you suggested is not practical, because many times users no longer have access to the old email account to approve the change.