A very easy way to avoid this type of trick is to contact the friend over the phone, ideally when other accounts have been hacked. If they don't understand what you say, you already know what is wrong.
Also, knowing exactly who brought you to the Trusted Contacts list will also help to avoid being surprised.
When you can't log in, Trusted Contacts doesn't just send you a recovery code, each of them sends a part of the code. You will need all the parts to get your account back. So the code they get from you is not enough to access the account.