Exactly. I have found the phone number requirement idiotic from day one. I recognize the decision was made as a trade off between usability and security (enabling discovering friends via phone etc), but they seem unwilling to admit that this does compromise security.
Is that really a problem though? Most people would just add their friends via username and bypass the whole user discovery process. Discord has demonstrated that this works perfectly fine, even with anonymous accounts not tied to emails.
that problem was solved like 25 years ago, just ignore everyone who you didn't seek out yourself by default. Basically, make liberate use of the block functionality.