Quote from polpolik:
I'm not sure if it's a requirement with IB but I think it can only be wired to an account that has your name on it. So Joe Schmoe cannot go into Joe Blow's account and setup instructions or account that will go to Joe Schmoe's account.
This seems right. IB's protections against withdrawals are reasonable and within market best practices IMHO. (Also the RSA gadget required for > 100k.)
Another risk might be an intruder trading a security at adverse prices with the intruder's other account elsewhere -- I'd imagine this would take a thinly traded security and hidden orders on an ECN somewhere....
When the RSA gadget is extended to cover normal logins, this form of attack would be better protected against.