How would a key compromise look like? A server-side key compromise just gives you public key material, which is useless. A client-side key compromise gives you an encrypted private key, but you've completely owned the client at that point so you've won already regardless of how weak or strong the authentication method is.
Traditional server-side 2FA (e.g., "give me a password and a 1-time code") is superfluous in a passkey world, because it's ultimately just a hack to make up for the fact that password-only auth is weak. Key auth is incredibly strong, so a server-side 2FA challenge doesn't buy you much.