It is important to distinguish between active and passive attacks.
The verification code generated is valid only for a very short time - so unless the hacker phishes the code, and uses it within 10s of seconds, the code is not valid.
The verification code generated is valid only for a very short time - so unless the hacker phishes the code, and uses it within 10s of seconds, the code is not valid.
And you get a lot more seconds if you log in within those 10 seconds.