If users decide not to use it, then there's nobody to blame but them.
Thinking up ever more complex schemes, to offload all the responsibility on the services, won't solve any of this.
At the end of the day user error overrides it all and massive database breaches even affect those that should know how to properly secure their stuff [0].
2FA is not perfect, it's not convenient but it's one of the last remaining effective defenses when massive breaches have become so normalized that known pwned accounts outnumber people alive on the planet [1].
[0] https://krebsonsecurity.com/2019/10/briansclub-hack-rescues-...