Isn’t the point of vulnerability in the initial account creation? The witness that creates accounts sent the keys out via email. That email containing the keys may still be in their sent folder.
Normally this can be done offline with most cryptos, but not the case with HIVE.
I am not sure they get the keys but it is a good idea to often reset the keys anyway.
Posted Using LeoFinance Beta
How do you reset keys?
You change your keys using your owner key.