Using your logic, doesn't the ability to social engineer access to a password make passwords less than 1 FA as well?
To me, a second factor that can bypass the first factor is exactly the same as this situation. Being able to hack your way into an account is a different issue.
If an attacker could access your account without knowing any of your secrets, then it's really 0FA.