Earlier quoted context omitted.
I can't understand your position. OF is designed in such a way that it perpetuates certain types of behaviour. You can't hand wave away TOS transgressions when the whole system is setup for weirdo's to easily and repeatedly break the TOS.
It's not just TOS violations. Accounts getting hacked, unless there was a vulnerability on the company's side, is totally nonsensical to blame on the company. They have the ability to set up MFA but the creator didn't use it. And this happens on non-adult platforms, too.
Maybe onlyfans does these things (i have no idea) and its not 100%, people will still get hacked but things that come to mind:
* have educational material on how to secure your account (they probably have the only audience in the world that would actually read something like that)
* rate limits/login captcha/etc
*Handle suspicious logins (diff geoip) differently
* password requirements (not the stupid one symbol thing, but the ban every password that has ever appeared in haveibeenpwnd version)
*making it easier for people with hacked accounts to get meaningful help. Response is just as important as prevention.
*mandatory 2fa (people who willingly use 2fa are usually people who have strong passwords and benefit the least)
Onlyfans is in an industry with a higher threat profile than average tech company, they should have a higher account security standard.