One authentication code is often all that's needed to *change where the authentication codes are sent*
Not to mention that most 2FA still uses SMS, which has it's own well-understood security flaws.