Thanks for that explanation, Ilseum.
As Concerto noted, changing a four digit PIN is perhaps not worth the effort. If the hackers know I have 100,000 points (I don't), then they can just crack the new PIN.
It seems like another solution, which might be even easier than changing to a real password, would be to put a delay on a repeated entry of a PIN. For example, if I enter the wrong PIN, I can try again immediately. If I enter the wrong PIN a second time, there is a one second delay before I can try again. After the third time, it's 10 seconds, and so on. At least that would slow down the bots.