Say I have for my blockchain wallet 2nd factor, very complex pw, second very complex pw. Someone breaks into my email account that has the backup, what can they do?
That is AES encryption, so you are pretty safe unless you happen to operate on a compromised system (e.g., with keylogger malware) or that person that broke into your e-mail account was your friend and instead of texting someone with her phone while sitting next to you she was instead filming you as you entered your two passwords.
Second passwords are not a form of two-factor authentication (2FA).