I have unleased them multiple times. Everytime was almost instant.
Either way, leasing is not going to secure your coins.
The point is, they "instantly" cancel lease but you cannot send them for 10 hours. So it gives you a 10 hour cushion to find out you are hacked. Unless they did an update, this was always the case.
That such a great "feature"

if it is true. I would only need to be able to somehow get notified when the lease ends, ie if someone cancels the lease this would trigger an email notifying me.
I wouldn't actually need 2fa if they could increase the freeze time from 10h to 24h (or custom time) and of course i would have to be notified by mail when a lease is canceled. This should be much easier to implement than their custom 2fa, is there anywhere one could ask the team if they could prfioritize this?