when an attacker is trying to access my Find My iPhone feature, I expect Apple to offer a different version of the their 2fa - either by user pre-authed device along with a special secret (those offline password print outs) or another form (landlines, biometrics, knowledge based, etc.).
remote wiping someone's one can a very serious threat if they don't offer something that handles both the usability requirements and the security of the service.