You are changing the goal. The point of this is to provide THE USER with a solution where they don't have to give away their personal information to the Government or the 3rd Party site. We do not care about situations where users commit crimes as that means our focus is on the Government's needs which they would already have met by just implementing a "Show us your ID" solution.
Now you could make the pin be a biometric so it's physically connected to the user. But part of the solution needs to be that the token is not identifiable with the user. If I pull of my wrist band no one will know it was mine. If you throw out your token someone could go around testing everyone's fingers and find out it was yours.