Don't complain about things not working properly then, cookies have legitimate uses as well.
Anyone with half a brain in this day and age runs a non-spyware ad blocker and Greasemonkey at a bare minimum in every browser.
I wasn't going to weigh in on this 2FA move until I had to authenticate for the third time today, just now; and that might be because I first checked the Codex on my laptop personal computer, then on my cellular telephone while I was at a barbecue this evening, and now I'm on my laptop personal computer once again, having authenticated for the third time in fewer than sixteen hours.
My forum, which I own and administrate and which receives traffic similar to yours, and which is often the target of bad actors, also runs on Xenforo—but over there, we manage not to fuck shit up like a bunch of cartoon clowns.
I'm sorry you've been literally hacked by Russians, and I'm keenly aware that you're all volunteers working absolutely for free (so are my own slaves), but making your site obnoxious to use for a significant portion of your user base as a form of damage control probably isn't a viable long-term or even medium-term solution.
Finally, other Codex cookies are able to function on most users' browsers, or the site would be obnoxious for them to use. Basic, simple logic tells us that the problem here lies with your 2FA functionality.