I've used it (not for abuse). It's simply volunteering to maintain the package after previous maintainer(s) have explicitly disowned it, knowing they no longer have time for it or don't care because they stopped using it, etc.

Problem is that there is no KYC process before someone can adopt any orphaned package

Yeah, I don't disagree there should be more of a barrier, I remember being surprised I could just adopt things. Just explaining the intended use.

There's also no KYC process for creating one.