2FA best practices?

Bitwarden auth stores codes on your phone locally. It does not ask for the yubikey after your first login. If someone swiped your phone while it was unlocked, the attacker would only need the bitwarden password.