I keep telling my bank SMS 2fa is bad but they say it is not. Many banks replaced tokens with SMS unfortunately.
Just tried it myself, it works.
One way to help protect you is to visit your carrier's retail store and have them turn off online access to your account and require all changes to your account to be done in person with a valid government ID. This should make it more difficult for number porting attacks but they can still sniff the SMS message when goes over the cell network. As far as I know, mobile network control messages aren't protected.
Like this: https://c7.alamy.com/comp/CYGATP/online-banking-security-chi...
Wells Fargo supports RSA SecurID tokens.
Source : I have one.
However, they also support SMS as an alternative. I'm not sure if SMS can be disabled..