Bakit 123456 lang kasi ang password mo?

That's not the point. Ang point ko is they shouldn't be accepting such passwords in the first place, requiring at least probably 12 digits, with at least a number in it, like most if not all modern websites do.
If you say so.. My point also is to inform you na merong 2FA.
Which is good. Pero having bad password requirements dahil "may 2fa" naman is still a very bad practice in terms of information security. Having bad password requirements pero "may 2fa naman" is the owner assuming na gagamit ng 2fa lahat(100%) ng tao. Understandable pa sana kung 100% mandatory ang 2fa.
Right.. Hopefully they'll improve if sakaling makita or mabasa nila tong thread na to.
But I think there's nothing to steal anyway sa accounts if ang concern mo eh ang security ng funds/collateral/coins. kasi wala naman sa site kundi asa multisig wallets ang coins which is hawak mo ang isang private key.