A OTP is active for a little while, so if you put all your details onto a phishing site, they can use a script to quickly log into your account whilst the OTP is active before it changes. From there they can change what they want.