Even without, accidentally getting one password leaked is a lot more likely than two. For whatever reason, shoulder peeking, keylogger, wrong input field, brute forced, and so on.
In my mind the email is the second worst 2FA since it's used for registering everywhere on the web and more prone to be compromised. Phone number is the worst.