There are two types of hackers: wholesale and retail. The wholesale hackers hack accounts and then sell them. The retail hackers use the account they buy.
You need credit card to set up a Paypal account. You set it up before you use it, and it could sit there forever if you never make a charge.
Unless something has changed. PayPal doesn't give a s*it about the credit card number as long as it passes the formula. My account was hacked twice, and once with a card I canceled. PayPal had the number since it was my card until the incident.
PayPal says they have no way to really verify the customers. Bullshit! If I ran PayPal, my security would require a charge to be made on the card at some vetted retail establishment in person. You buy a PayPal certificate, the cashier checks your drivers license, then you are authenticated. Wal- Mart, Target, etc. Well maybe not Target. But to make the person use the card once in person near when they live makes it way harder for some s*****ad from North Africa to hack you.