WebAuthn is generally about device authentication with credentials that can’t leave the device, though that could change depending on where and how the hardware gets/stores it’s tokens. Or if you rely on a third-party, like Apple, to store the tokens for you and use OAuth with an mfa indicator in the attestation?
General advice: If worried about losing a device, try to register more than one. Even iCloud Keychain requires other hardware for authentication... same problem applies.
Only way out is having a backup like taking ID to an Apple Store as a way to regain access... that varies right now by provider, but who knows. Maybe Login with Apple will go WebAuthn-compatible in future? (Haven’t watched this video yet.)
If you’re an enterprise and worried about key authenticity or varying WebAuthN standards, you can look for specific types of keys or even request specific serial numbers of FIDO2 dongles from the web browser, etc.