Fwiw 2FA* saved my ass once, many years ago, when someone hijacked my domain**, set an email forward and reset the Github password.
* = and the hackers lazyness, they could have done way more damage
** = where I forgot to set 2FA AND probably reused a password, despite having stopped reusing passwords years before the hack - forgot to change that one