For you people who haven't gone through the Google presentation today, you should really watch it. It addresses many of your "possible scenarios"
Phone lost: not able to log into phones, data can be remotely wiped.
NFC mining machine: NFC controller is not powered without the user actually activating it. No use for receptors trying to make phony transactions.
Google data mining: opt-in by users for coupons/offers. Stay out if you don't want your privacy to be breached.
Credit Card data extraction while phone not in possession: Google does NOT store any of your card and banking data. Those data will never be routed or shared in anyway. Google wallet connects to your banks for permission. But does NOT store the actual info. All data are handled by separate companies, making a one-hack, all-data almost impossible. The only thing Google have any sort of control is on the app and NFC controller.
Feel safer with your wallet in hand: How is this so different than having your phone in hand? Your CC/Cash in your wallet is not any safer than your cell in your pocket. As a matter of fact, to use Google wallet, you need a PIN. If anyone got your wallet, it's free gas before you cancel your CC. But I guess all power to you.
Last but not least, if you really don't want to use your CC but want to take advantage of NFC, you could always get a prepaid google wallet... so you will always know how much money is in there.