What you want is that the happy path for security is zero hassle, but the unhappy paths should also drop dead with zero hassle.
This is the UX I really like for WebAuthn / U2F.
All the interactions on the happy path are very smooth. Need a second factor, tap, go. Almost frictionless. On my phone for example you tap the same fingerprint sensor that would ordinarily unlock the phone. Short of not having a second factor at all it couldn't be smoother.
But if this is actually a phishing site or you're a crook who doesn't have the hardware token, it just doesn't work. Still low friction in a sense, but low friction failure. There is no way forward, no override, no "I'm sure", nothing - it just won't work.