I don't see much sense using U2F. If you just need a 2nd factor, then TOTP based solutions do it cheaper and easier. FIDO 2.0 is the way to go if FIDO is required.
1. sharing a secret (which is bad, and possibly already compromised by the time it reaches your device (phone))
2. permanent attention to the domain. Remember similarities between the cyrillic a and latin a? (phishing, etc.)