I have to take issue with a "cure that's worse than the disease" reference. I have suggested a simple (a few days coding and testing), easy to understand, and easy to implement with your existing tools fix for one kind of fraudulent purchase.
As some one who has seen firsthand both sides of fraud, I'll tell you that it's not the guy who is going to change PP address or IP addresses that worries me. That takes time. Fraudsters have access to 100's of Paypal accounts true, but due to PP's fraud checks they don't always have a matching IP address, or similar computing environment. When they finally do find a PP account that works, their next step is to milk it for all it's worth, while keeping in mind not to trigger unusual usage patterns.
This is where my suggestion comes in, especially in regards to digital downloads. It would eliminate the effectiveness of a hacked paypal account that has passed these tests and are free for multiple uses. As soon as it works once, it's likely that it will be used again and again until depletion. If they then had to wait 2 6 or 12 hours between jobs, it would make it much less inviting.
Anyway, just a polite nudge to have another think about the idea. I'll leave it at that.