Exceptions to that rule include sites that do things like what GitHub calls "sudo mode", where you have to confirm certain security-sensitive actions with another U2F confirmation. This would require more effort on the attacker's side, as they'd have to trick the victim into performing a U2F confirmation. More effort, but far from impossible: simply display a fake login prompt for the victim, but instead of logging in, perform whatever malicious action you want to perform. Session keys might also be less persistent (they're limited to something like 30 days on Gmail, for example), so that's another small advantage if the attacker wants to keep their access over long periods of time.
Still, for the vast majority of sites and threat models, hardware keys aren't a whole lot better. If it's easier to get adoption for soft keys, that might be a worthwhile trade-off. Natively supported TPM/SEP-backed keys would probably hit the security/UX sweet-spot.