It appears that 2 factor authentication on Paypal can be bypassed if an attacker has just your email and password, ie 1 factor authentication. Usually 2 factor needs a code from an SMS sent or from a number generating card/app.
Paypal informed a month ago but apparently not fixed. A fix might not be so easy for them without making it harder to link Ebay/Paypal accounts.
http://blog.internot.info/2014/06/pa...n2fa-good.html