I think most of the suspicions so far have been pointing to a sim swapping attack.
It's less like a 2nd factor and more like a poor man's password-protected private key authentication, but it's way better than just a password.
U2F is "great".
TOTP can be phished, whereas U2F is virtually impossible to phish.