One time codes are very short lived and for many systems as their name suggests they are single use.
So, knowing 8490 worked for me is often entirely useless immediately, and if not it'll be useless within say 10 minutes.
You might think if you collect enough of them you'll be able to guess the next one. In principle that's true, but for all real systems you're fighting an actual cryptographic hash in there somewhere, so it's like you decided second pre-image attack on the hash (much harder than collision) wasn't difficult enough, you want hard mode.
So, knowing 8490 worked for me is often entirely useless immediately, and if not it'll be useless within say 10 minutes.
You might think if you collect enough of them you'll be able to guess the next one. In principle that's true, but for all real systems you're fighting an actual cryptographic hash in there somewhere, so it's like you decided second pre-image attack on the hash (much harder than collision) wasn't difficult enough, you want hard mode.