So, as we see even "buy keys" attack can do nothing if economic majority keeps an eye on the blockchain and doesn't allow deep reorgs. This is what happens in Nxt with its 720-block rollback limit.
The OP should has included the above text to look non-biased. As a bonus extra analysis on possibility of an eclipse attack that could split the economic cluster and lead to chaos is welcome.
I believe I covered the re-org depth mitigation in the OP? It doesn't help for two reasons:
1. The re-org from this attack could easily be less than the maximum depth
2. Re-orgs greater than this depth will still be accepted by all syncing nodes, and the the attacker can impersonate a majority of nodes for ~0 cost, leading to all syncing nodes accepting his version of history, which eventually leads to it becoming the canonical chain.