BofA uses something similar when transferring funds between accounts--a unique code is texted to a registered mobile device to complete the transfer. It seems feasible that they could extend the technology to logins.
Four or five years ago I did some work with a company that provides online banking web platforms to smaller regional banks. I asked the CEO about 1+1 authentication (at the time in the context of a RSAID type keychain fob device) and he said they'd pitched it but there was no interest from the banks. In their defense, maybe those RSA thingies are just too expensive for consumer accounts, I do know Citi now provides them to business accounts.