That sounds nice. But while using U2F/FIDO for a few years (with two HyperFIDOs, one for "daily" use attached to my key-chain, the other as a backup in a safe), I found the most common problem was that websites/services don't tread these keys as first class citizens. For example GitHub: I have my two keys setup there, but I can't opt-out of SMS authentication. If I knew I could use my keys at more services, I would a…
I'm surprised that you can't remove/disable the fallback SMS number. One thing you can do to mitigate that problem is to create a Google Voice number. Those are harder to port as long as you created it on Google Voice.
1. It should just be plain unnecessary to apply such a hack.
2. There is still a single weak point for all services.
3. While this prevents against the run-of-the-mill "attacker activates another SIM card for my mobile number and steals my crypto cash from $online_wallet" coming up here every few month, a more sophisticated attacker can just route the SMS to himself via SS7 (I suppose the SIM variant is easier to pull off with less traces, and obviously requires much less technical expertise).