How about never using sms as 2FA.
I think that not using sms is more possible now, but there are some services that still lag in that regard. Of course, google authenticator and authy provide additional protection, but there is also an issue if you have an account, and you don't set any of that up, then a hacker who gets into your account could set such security up in your name. So the solution is not completely simple, and hackers are both sophisticated and more specialized, these days, because bitcoin (and other cryptos) brings a certain amount of getting away with it value (difficult to trace and not reversible once successful).
In other words, sometimes you might not recognize some certain security holes that you might have until they get exploited... and it is kind of fucked, too, if you have a lot of passwords and devices and you end up losing your device and/or access and have to verify yourself to get reset on the systems. There's no easy solution and personal security in cryptolandia (we talking about bitcoin, right?) remains an evolving target.