Toggle in the dev options would only be one more instruction step for the scammers, defeating the purpose of hiding OTP from screen sharing in the first place.
Serious idea - add a warning on enabling dev menu it's often used by scammers.
If user still gets scammed through this path, then there was probably no helping them anyway.
Or, serious idea too: only allow it through ADB and only get the adb toggle with warning but no explanation as to how to use it behind the 5 taps on version number.
I'm pretty sure as soon as the instructions to get a banking app involves downloading stuff on a computer, connecting the phone, getting into cli...most people would have gone on to find the real app.