SIM-swaps are easy but do not scale. This means that they don't actually affect a lot of people. The improvement in security posture from SMS 2FA to TOTP is actually fairly small, because both lose to phishing and phishing is orders of magnitude more common that SIM-swaps or malware that steals SMS codes.
As a solo recovery option, it is indeed a more meaningful risk. But we also observe that people just lose their accounts all the time if they don't have a phone-based recovery option so I do understand why the option is offered.
To be clear, 2FA != account recovery.
I only used that account for communicating with one friend, [our mail hosts were blocking each other in some kind of spam war tit-for-tat] now deceased, so it was no great loss to lose the account, but rather annoying that they pretend harvesting phone numbers is some type of "authentication."