Correct. Use a registrar with 2FA using authenticator or hardware key. No SMS 2FA. Rolling 5 year renewals will work for not letting the domain expire, but not for this scenario.
I mention registering for 5 years in the future because if something like this happens, there will be no question as to whether or not you lost the domain because it expired.
.name domain isn't available in some of these, decide to use inwx.com
What I'd like to see a lot more of is WebAuthn specifically, rather than "hardware keys" generally. It's frustrating to me that the outfits I deal with only have OTP and not WebAuthn.
I don't see why offering MFA hasn't been made a requirement in order to be an accredited domain registrar.