The point of 2FA is challenge-response and the secret key is in the token. If a phishing site asks for 2FA it can get only one valid challenge-response pair, not the secret key.
Require second login to transfer chrome apps to alternate account + 24 hour timer on transfer that sends an email to recovery email/everyone else relevant when extension is transferring.