I think given that you could effectively steal from any account for which you knew the email was worth significantly more than 10k.
If you succeed in CSRF attack him, that is.
I think given that you could effectively steal from any account for which you knew the email was worth significantly more than 10k.