I recognize this as a possibility and I would definitely take it down if the bank requested it.
On the other hand, if anything, I exposed that they did a good job. They could have rolled out their own crypto, or some flawed form of code generation, in which case I would have disclosed it to them through proper means. But they adhered to standards (TOTP, RFC6238) and protected their data as well as possible. This article should be seen as praise.
Then again, corporations aren't always that understanding, which is why I would be happy to comply.