However, recently two-factor authentication (2FA/OTP) has been added, creating a new possibility for account traders, where account ownership can change by the new owner changing the OTP. The password and email can theoretically stay the same.
This 2FA feature for accounts in Bitcoin forum has disadvantage that you did not know.
If you use the forgotten-password function, then there's an option to remove the 2FA. So 2FA does not provide any protection in case of a compromised email. Make sure that your email address is secure. If you don't want to set an email address, use something like yourUserName@invalid.bitcointalk.org; don't use a random nonsense email like y@x.com, since somebody might create that domain/email.
However if account sellers and buyers deal well, it's not big problem for account sellers to give buyers all necessary information of sold accounts: from email address, email password, account information and password as well as 2FA activation code. So if they did everything well, they won't have to use forgotten-password function and no need of removing 2FA.