They can re-activate the keys they automatically purged from my account, I still have their associated private keys. My github profile also has detailed information in its bio section including my past employer and links to my various social media/website. They could simply validate my ownership of one of those accounts etc.
The social media websites could have been hacked by some attacker, the private keys could have been obtained as well. Or put there by an attacker that is now locked out by 2FA.
The entire point of 2FA is that it's a second factor and no way around it without a second factor that is verifiable without doubt.
Nope. Many 2FA setups have a way to workaround the second factor if it’s missing. Recovery codes, emails to secondary addresses, faxing an ID, etc etc.