The thing that makes me a bit jumpy about hardware 2FA with things like this or a Yubikey is around what happens if I lose it or it breaks. It's not so much a problem in a corporate setup (like internally at Google) where you could go to a central admin team to revoke/replace the key. But if you're a home user using this for a wide variety of sites and the token fails then the failure mode seems to be "go figure out…
Indeed, I was recently locked out of some of my accounts: I used some "one-shot backup codes", but some sites didn't deliver them (and so, required involvment of admin/support by mail+phone).