So I spent some time playing with the Authy app.
Here's the drop:
1) Dave has an active Authy account.
2) Dave configures 2FA for Coinbase using Authy.
3) Coinbase, rather than asking Dave to manually enter a TOTP secret, registers a 2FA token on Dave's Authy account via the Authy TOTP API.
4) Mallory takes over Dave's phone number.
5) Mallory resets Dave's Authy account at https://www.authy.com/phones/reset.
6) Mallory gains access to Dave's email account (using SMS recovery?).
7) Mallory confirms the Authy reset email.
8) Mallory logs into Authy using Dave's stolen phone number.
9) Mallory now has access to all of Dave's Authy API tokens (Coinbase, CloudFlare, etc).
10) Mallory can try guessing the backup password for Dave's other non-API tokens. Assuming Authy transmits the entire encrypted blob (I'm guessing it does), offline brute-forcing is possible.
tl;dr: Don't use Authy for services using the Authy API.