One possibility is that a criminal added your card to a burner phone. In theory Chase should have mandated 2FA for an "unknown" device, but it's possible that they didn't that time. (Is there a way to look up what devices are associated with your account? I know you can with Discover.)