In Europe your liability for Card Misuse is capped at 50€ for things that happened before you blocked it.
Also how would someone misuse it? You need a PIN Code for every transaction anyway, and the EMV Chip can't be cloned like Magstripes.
Online Payments need a mandatory 2 Factor Authentication
I have always heard that the 2fa verification really depended on the vendor actually doing that auth so I always scrape the 3 verification number (what is it for anyways ?) at the back of my card. It's just 3 numbers after all.