I'm under the impression you misread the original blog post, which by the way does not really do a very good job in terms of explaining how this should be implemented.
IMHO, the idea is not to display the info about wrong 2FA code on the login page but to use a separate channel to inform the account owner about this recent, failed login attempt. So, no info on the login page of the website (adversary would still not know that they have a good password but wrong 2FA) but e.g. an email, a text message, a push notification, etc. with this info. I would certainly like to know that someone, somewhere is trying to login to my account and that this adversary is in possession of my actual password.
Oh please, guy says linked articles are crap because they are only about US and UK and there is still rest of the world where the situation looks different. But he himself says only about Norway, Denmark, The Netherlands which are at the very top of the richest countries in the world list (he mentions also Slovakia which apparently has good PhD programs funding) and excludes poorer European countries such as Poland and Ukraine because they are too poor. I am sorry, but what kind of argumentation is this? Article is bad because it is only about US and UK but his blog entry is OK even though he compares only three richest countries in the world?
IMHO, the idea is not to display the info about wrong 2FA code on the login page but to use a separate channel to inform the account owner about this recent, failed login attempt. So, no info on the login page of the website (adversary would still not know that they have a good password but wrong 2FA) but e.g. an email, a text message, a push notification, etc. with this info. I would certainly like to know that someone, somewhere is trying to login to my account and that this adversary is in possession of my actual password.