And I wouldn't use Authy as my 2FA mainly because of the same reason you described above. I remember reading a story on reddit about someone who lost $8k worth of bitcoin from his Coinbase account because a hacker got access over his phone number by social engineering Verizon.
But if you still want to use Authy and want to be safe from this kind of attacks, you can turn off "Allow Multi-device" on your account.
Just go to Settings > Devices > and turn off "Allow Multi-device".
I've never used Authy before. So when I used it for the very first time, download the app, and to my knowledge there was a bunch of Bitcoin services that I have used in the past like CEX or Cryptsy. So I am worried that maybe someone already has my Authy control and when I register for a new service like Coinbase my 2FA will appear.
Is there any way how to reset all of this? Or is the only safe way to just buy a burner phone and make sure no where in my emails I mention that number?