There's a new version of the "Cerberus" Trojan horse for Andoid phone which is now able to steal your one-time codes form Google Auth. App.
Stay alert.
Anyway, we should use high reputed exchange where ask for multiple verifications. For example, Binance requires me 3 step verification during withdrawal, Google 2FA, mobile, and email verification.
As times goes new security protocolos shows up , just as new form of attacks.
The most secure method is still the old cold storage... note down the seed in a piece of paper, and keep it safe.
And the second most important thing:
safe habits online. Don't download shit, don't watch porn, don't crack software, etc and you will have a much safer computer/internet experience.
For exchanges, even email + 2FA +password falls with this new attack. If the attacker has the 2FA in his phone, he can certainly get his hands on the email which is in the same phone as well.
Personally, there are so security problems in exhcnages that I leave only a few hundred bucks (at the most) in all of them. I think binance is the best basically in every aspect, but even so I wouldn't trust more than a few hundred dollars there.