Earlier quoted context omitted.
Can you explain how this hack would work ? Would someone need to steal two of your devices ? I was under the assumption that you need to be logged in with touchid/faceid/pin code to get the unlock code
The attack in this case would be somebody shoulder-surfing your PIN and grabbing your device. They then have everything they need to take over your iCloud account (kicking you out of it in the process by resetting all other devices capable of resetting it) and can see all your passwords stored in it, as well as use all of your WebAuthN passkeys. I'm not sure if having a recovery code would improve that situation, but…
Hard to mitigate somebody looking over your shoulder, this is the case with most password managers, but I understand why this is a more likely scenario.