Biggest issue is single point of failure for total access to all devices. Get\guess\beat out the master password and its game over on all connected devices.
Requiring existing devices to be actively involved in provisioning a new device prevents all of this.
So in Keybase, what does device to device provisioning look like? "Hey, you've just set up this device - a message has been sent to all your other devices, OK the message and come back here and you'll be good to go"
And if it's not a 2FA device, the victim can use 2FA to push a disavowal of the old keys and set up new keys. That's an ugly and server-centric solution, but "halp I got hacked" is going to be an ugly case no matter what.