just implement a confirm by email code feature on password change and problem solved: only real account creator will ever be able to change the password and that's it.
This won't change the chance, anyway, that the "scammer" could just trade shits directly in game, without being in need to...