any attempt at cashing out these coins will immediately reveal who it was
Nope. That's only true if every single exchange, ICO, etc that supports NEM is MANUALLY tracking the stolen XEM and manually blacklisting in real time which is simply not going to happen. Even if so, many exchanges don't require verification so it wouldn't reveal who attempted to cash out.
Even with the tagging system, chances are there will be some exchanges that won't utilize it.