At this point, it is rather ridiculous how easy it is to steal someone's avatars. If you can get someones avatar ID, which you can easily do through a variety of ways be it through the API or just looking through logs, you can easily download their avatar prefab through the api.vrchat.cloud site which will give you a VRCA. Usually these would be pretty difficult to unpack, but people nowadays have methods of easily unpacking these which give the person the avatar prefab file that they can easily re-upload through unity under their account with little to no work needed to fix the avatar as it uses your avatars prefab that is made when you upload to the servers.
Honestly, would it be that difficult to either disallow unauthorized downloads of avatar files through the site or just encrypt avatar IDs to prevent theft?