Phone or SMS based 2FA is inherently insecure. Can be intercepted at carrier level (and it is quite cheap to do it — some political targets in Russia and Turkey were attacked this way).
It's important to remember that availability is an important aspect of security. If you protect a user primarily concerned with mass-account takeover attacks from a low-probability threat (people intercepting their SMS channel) but introduce a high-probability threat (dropping their phone in the toilet and being locked out of their account forever) you may not have made a good security tradeoff.
What other failure mode is there? A solution that's considered to be actually perfect? Regardless, you have to account for Godel.
The correct mode of operation is to always be prepared, without relying on the "perfect" system too much. If system is actually good, "chaos monkeys" may be employed to keep everybody prepared.