Hackers and scammers do terrible things, but the paradox is that this is precisely how they can force gambling site owners to stop being careless.
True, the poorly secure ones can be weeded out in this manner, but there is something called white-hat hacking for this purpose, where the hacker reveals to the owners/whisteblows the owners that the site is having some problems and need to be looked into. This can also be put under penetesting or bug bounty.
Most the correctly caught exploits get rewarded by the owners to such responsible hackers and no legal process comes in. But here they are stealing the money and hence punishment will follow once they get caught.
There can be so substitute for securing the devices when running such a casino, even then some or the other problems will arise.
I've discussed about this exact idea in the past, you can't start an online business without test running it, with massive bruteforce from the help of people who are good at jailbreaking platforms like whitehats, it's just a good way of knowing how strong your setup security wall is, also it's good to always upgrade security from time to time, I heard that sticking with one security measure on a website for too long is not a good idea, I think only Binance exchange is practicing this right now, they don't stand on a security update for too long so that hackers won't find a way through, casinos only need to do something similarly.