If you care about MFA that can survive leaks, you want WebAuthn. As with phishing this known problem was considered in the design of WebAuthn and so your WebAuthn credentials aren't designed to need to be secret.
In fact here you go, here are WebAuthn credentials for a vanity system I own, copied out of its authentication database:
ID: AXnUJ920FfJlRjZtocN+9Bc9IP6gvsBiWA3GfJxckh3nQ/KekQ6xB2byfI2GM7IcGS2MpzxZs6IHmAxvgAcE/Mw= Public key: pQECAyYgASFYIFf0iDSfNpYNA5Br9zXSIUH69BqyvFcgbqy6tWC8rsLwIlggCDqury9UOzI1DnOFyE3aYwaBLvP0NyNez98v0TcieKs=
That's all the backend needs to check I'm really me, and yet it's also completely useless to an attacker, they can't even use it to compare across sites and "unmask" me.
What happens if you lose that device, or if it fails?
Keep passwords on browser, and MFA on phone.
If my browser / desktop got compromised, someone would still need my phone to access my accounts.