You get a unique long pin code when you freeze the account. You need that to unfreeze it. There is some "recovery" procedure, I think you need a notary or something
At this point it's about doing that one thing the other 1 million won't. It might be surmountable but do you figure the adversary is going to have the incentive to surmount it?