Physical tokens require physical security
Yep. Which is why e.g. having your password written down on a sticker on your monitor may or may not be a bad idea, depending on your threat model. It's almost impossible to steal a sticker over the network, but a personal visit compromises it immediately.