These use FIDO-based public-key cryptography, which is immune to traditional OTP bypass methods.
Modern bypasses are increasingly rare because PayPal and other providers have moved toward and Risk-Based Authentication (RBA) .
Exploiting legacy or mobile-specific API endpoints that allow session tokens to be generated with only a username and password, skipping the secondary verification required by the main web interface.
PayPal OTP Bypass (Hypothetical/Historical) Impact: Critical (Full Account Takeover)