Second, if that happens you are in the same situation as with the phone authentication -> so the disadvantage is the same.
It's easy to transfer from one to the other but that doesn't remove the single point of failure.
Solution is to have back up codes for each account.
But of course, keeping emergency codes is a good idea too.
It's worth also noting that Authy also has no official way to export your secrets, although there are workarounds: https://tij.me/blog/migrating-your-one-time-passwords-from-a...
Otherwise you’re going to lock a lot of people out of their accounts which is not acceptable.
Ultimately this typically ends up with a reset scheme that depends on phone numbers or email addresses which means the protection, which is as strong as the weakest link, is worthless.
If you work for an organization with their own PKI then there’s probably also an automated self service reset mechanism using a complicated process.