Sorry, couldn't resist. Shameful self-promotion, but this is why companies shouldn't implement their own two-factor authentication. Getting everything right is hard and chances are that you aren't reading or informed of the latest attacks.
At Authy we are obsessed with Two-Factor Authentication and spend a huge amount of time looking at whats happening in the ecosystem, which new attacks do we need to be aware of etc. It might look easy to build a quick two-factor authentication system, but history will repeat itself, and like passwords we'll see lots of bad and insecure implementations because its harder than what people think.