Suppose a hacker got my BW credentials

So your phone would need to be in range for auth to work, even if you don’t need to scan a QR code each time or read the code off your phone screen?

My bank sends the 2FA code to my email. AFAIK my phone is not part of the equation.