Attacker sends request to PoS user for old keys,
PoS user agrees to sell/send old keys to Attacker only upon receipt of payment for keys.
PoS user informs the PoS Dev of sold keys, before the attacker can launch his attack ,
PoS Dev updates checkpoint thru program update, making the attacker purchase of old keys useless.
Now the attacker has the useless keys and lost his payment , and the PoS User & Dev are Laughing at the attacker's attempt.
*What is funny is the attacker whom is attempting to do harm with a dishonest heart, thinks the PoS User will be honest with him.*

This might be the primary reason , no one ever tries to buy old keys.
Because it is so easy to turn the attacker into the Chump.