Agree. If Google and Apple can do per-app passwords for apps or websites that don't work with 2-factor authentication it seems like Visa should be able to kick out a per-merchant number for Comcast, Netflix, etc.
If the underlying credit card number is compromised, just change that and leave the virtual in place.
Just a quick chime in here - our system does in fact do that, and though I can't speak with authority about others, my understanding is that they do the same.
If the underlying credit card number is compromised, just change that and leave the virtual in place.