I'd hardly say people routinely bypass Google's two factor authentication (using the smartphone application), which is what I'm suggesting here.
I'm aware of one incident (the Cloudflare hack), but that seemed to be more a vulnerability in the password reset functionality than the authentication mechanism.
SMS verification is less than ideal, though.