With your suggested approach, the attacker is free to use the account to impersonate the victim until they get a new SIM card, which could easily take days or weeks.
This seems like a degredation compared to the current abuse potential which is mostly limited to logging you out.
>This seems like a degredation compared to the current abuse potential which is mostly limited to logging you out.
I think it depends on who you ask. IIRC there was a stat that showed a substantial % of people only use WhatsApp rarely and they might not notice the deactivation and/or miss the 30 days deadline, getting their accounts deleted.
1. Identify to your carrier and get a new SIM, deactivate the old one. 2. Put the SIM in another phone and take back your WhatsApp account.
Isn't this the standard recovery method for apps that rely on your phone number?
Getting a new SIM takes longer than sending an email, but at least you don't have this easy abuse potential.