2FA via SMS requires a private channel, but SMS wasn't built to be end-to-end encrypted (although it could be, using the SIM's processor, such a proposal will be shot down by the state actor members of the relevant standards body. See the less-than-perfect security profile of 5G), and so whenever a message is diverted within the system, somebody else can take over.
M-Pesa requires message to be trustworthy, and the SIM app can sign them with a key that resides only on the chip. The transactions are probably not very private (so it might be possible for an eavesdropper to figure out that user A sent X currency units to user B) but that's not a make-or-break requirement for the system to do its job (unlike for 2FA via SMS).
M-Pesa simply has quite high fees to cover fraud losses.
If so, wouldn't it be possible for criminals to social engineer this recovery process, similar to how they use social engineering to steal numbers in the US?
Even if you don't get to recover your SIM card early enough, anyone with access to your phone must know your wallet PIN code to be able to make transactions
It's "secure" because the system requires a pin to authenticate the USSD session. So a SIM swop won't provide an attacker access to the victims account.
I suppose there's a possibility for doing a MITM attack but you'd have to do it between the tower and phone (GSM I think) or between the telco servers (SMPP or SS7), none of which I think are trivial or even possible in some cases
In all case there's some amount of authentication going on, and they all allow retrofitting additional lines of defenses if necessary.
2FA SMS is helpless as long as it's layered on top of plain old SMS (which for political reasons won't become secure).
This was for the Dutch ING bank.