Time-constrained 2FA codes can be broken with sim swaps or targeted phishing which are less widespread than a wide-net spam-based phishing campaign.
Now don’t get me wrong I hate SMS 2FA with a passion but still :)
It's literally a worse version of regular TOTP. And they're in the minority even having 2FA!
You best audit the shit out of that code if you actually use it. Every. time. they. update.
Everything based on username + password alone today should be replaced by passkeys. The problems they don't solve are 2FA and account recovery.
Unfortunately one can claim to "forgot my password" and use SMS OTP to reset it. Now it becomes a single factor authentication with a compromised phone.
Password + SMS OTP is strictly worse than a password. At least you cannot SIM swap your password.