This is the thing that surprises me most about credit cards: you can pay with just the information that's easily visible on the card. And you share that information directly with the merchant. Surely that's a gaping security hole? I'm not surprised they need to be paranoid about fraud, if it's that easy.
When I buy something with my bank card, I always have to provide my PIN. If I buy something online, the site redirects me to my bank, where I authenticate myself with my bank's system, and then authorize the payment with my bank's system (involving 2FA), and then the bank tells the site that the payment has been authorized. The site can blindly trust my bank and can immediately ship stuff to me, because the payment will go through.
I've never had any blocks nor fraud issues with this system.