That argument is circular nonsense.
They couldn’t have realized the full scope of the lack of mod tools until someone made it a problem.
So your argument seems to be based on Beehaw being at fault for not being able to see the future?
The fact that other instances aren’t moderated to the same standard means that Beehaw is at fault?
It’s a start, but 2fa can’t stop spam.
If one can automate account creation including saving totp secrets, you suddenly have 2fa authenticated bots able to send spam.
Maybe you could get around that to some extent by leveraging sms verification during account creation, but how do you set that up to prevent burner numbers? Or smishing?
These are hard problems to address