Were you using a VPN or something? I’m curious if this was tripped by setting off impossible-travel flags or something. It seems plausible that this is just anti-account takeover logic working as-expected, but with a false positive alert.
From the audit log in my email no new keys were added before this was tripped.
I am not using a VPN and as far as I know I am not doing anything unusual. I might be committing the crime of having a Linux Firefox user agent but I somewhat doubt that was the problem, that's not that unusual.