So you store the password and the TOTP in KeePass? Seems that you have 1FA, hacking your KeePass is enough to own you.
If I was really paranoid I'd keep the TOTP database on a separate device but, frankly, I don't anticipate being the target of a motivated attacker so that's more than I feel is necessary given the threat models I'm concerned about, those being untargeted hacks (service breaches, driveby attacks, etc) and social engineering.