Good catch! This was indeed an issue with the way we implemented 2-factor auth. Although it would have been very difficult for an attacker to exploit this, it was definitely still worth fixing promptly. We have remedied this issue, so now OTP's are truly one-time use. I've also comped your account with another quarter-BTC bonus. Keep the bug reports coming!
Thanks for the bonus.
I just tried logging in with a OTP and saw the following:

My 6 digit code was only 4 digits: 7709
Do I have to type the leading zeroes?
Oh, I tried again with a 6 digit code, but get the same error code. I'm now completely unable to log in.