The chronology of the robbery is like this:
1. Email - 19:27 2FA was updated
2. email - 19:28 withdrawal address added - confirmation needed
3. email - 19:29 withdrawal address deleted
4. email - 19:29 withdrawal address added - confirmation needed
5. Email - 19:45 withdrawal request made
We're assuming the attacker logged in before updating the 2FA, right? Meaning the login 2FA was compromised, whether from Kraken or you. The first email you list says the 2FA was updated -- did they send you an email about a successful login prior to that?
Kraken-Chase, there's absolutely no way to remove login 2FA
without being logged into the account, is there?
Also, is there no email confirmation required for withdrawals on Kraken? That's typically a very basic security requirement that all exchanges employ. The OP says their email account was not compromised.