The point is they have a lot more than a minute or two. As long as you keep logging in on the effected computer your login will fail. So they have untill you get feed up and call Blizzard, maybe an hour maybe a day.

And each time you try to log in you give them another authenticator code to do more damage to your account with.

Likely they use the first one to change your password so you can't log in via the Internet.

Then the next time you try to log onto your account they use that auth code to log into the game and start clearing your account out.