I also would love to know how to keep any account secure when there is no 2FA option available.
This will probably sound draconian but I only log in here using lynx text broswer (with only ASCII character support) so I can easily see if somebody is trying to give me a phishing login link.
Maybe your account was phished. Check your browser history for any weird looking domains like "bitcointalk.org.123456.hackers.us".