I'm not sure why you believe this is a security flaw. I have actually added the words "In my opinion" so as this is not misleading and alarming to others.
What this actually would be, is a feature you would like, but its certainly by no means a security flaw. In fact, we actually have items to mitigate these issues, but of course, they depend on being used. You would simply enable 2-factor authentication on your site, which is created to prevent people from accessing others accounts.
The locked accounts does indeed work, however, if they have the correct password for some reason then indeed they will get in. See my point above on this, which would resolve that issue completely.
It's also worth noting these are not always bots. If there is a list somewhere that has a password on that someone uses on multiple sites, you wouldn't have to be a bot to simply log in with those details. Again, 2-factor authentication would solve that issue.
I mention the above, as it depends on it being used, of course. We can prevent many things, and of course the request of such features would be taken into account if you post this up as feedback. But as with 2-factor authentication, it would depend on it being used.