So, this doesn't look like they've actually broken any new ground here that you can't achieve with existing commercial products like Okta or Auth0. They're taking an extra step of asking you to store hashes of their hashes. Which actually feels less secure since if hackers get their hashes, that as good as getting clear passwords to login directly your site? I'm not actually clear on that.
But either way, the diagram says they're hashing phone numbers, so presumably that means they authenticate by typing in their phone number which is a terribly password since you give you phone number out to people so they must also send a TOTP via SMS which is better, but not great. NIST has started recommending not to use SMS for out-of-band authentication. Either way, this whole chain of events just delegates authentication your mobile carrier. Same thing if you send a TOTP to an email address. It feels more seamless, but really you're just delegating auth to their email provider. No different that using OAuth.