| |||||||||
Share Nicely … Or Be Forced To | |||||||||
| 3 news stories, 2 reading recommendations, & 1 question. | |||||||||
| |||||||||
| | |||||||||
Happy Monday, Fintech Takers! And happy Labor Day to all of you laborers out there! All we can really hope for is to find work that (mostly) engages and delights us and co-workers who make the non-engaging, non-delightful parts of our jobs (an unfortunate reality for all laborers) more bearable. I hope you have that. If you don’t and you need help finding a new opportunity, feel free to drop me a note. I’m happy to put out feelers on your behalf. People in the fintech ecosystem have a wonderful way of taking care of each other. Speaking of which, if anyone out there has an opening for a DevOps engineer (or knows of one), I’ve got a great guy to recommend. He has more than 15 years of experience working in heavily-regulated industries, including financial services and healthcare. - Alex Was this email forwarded to you? Sponsored by Fundbox Fundbox is built around a simple idea: the platforms that serve small businesses aren't one-size-fits-all, so their financing shouldn't be either. A restaurant and trucking company don't need the same things, and with Fundbox's modular infrastructure, a platform doesn't have to choose between them. With an extensive suite of capital products, platforms can offer the right form of financing for their customers from day one and expand as their customer needs evolve. That flexibility already powers distinct financing experiences across SoFi, Relay, and Stripe, with each serving different customers, use cases, and capital needs. With more than $7 billion in capital delivered to over 190,000 small businesses, Fundbox shows what embedded lending looks like when the product adapts to the platform, not the other way around. New post office & proposed Broadway underground railway from Illustrated description of the Broadway underground railway (1872) by New York Parcel Dispatch Company. 3 FINTECH NEWS STORIES#1: Share Nicely … Or Be Forced ToWhat happened?Amazon unveiled a new self-service tool for its U.S. customers:
So what?U.S. consumers lost at least $15.9B to fraudsters in 2025 (the real number is much, much higher … victims frequently choose not to report fraud). Of that $15.9B, $3.5B went to the perpetrators of imposter scams, in which the bad guy pretends to be someone legitimate in order to trick the consumer into sending them money. There are many different imposter scams out there, but nearly one third of the losses from imposter scams come from fraudsters pretending to be businesses, and Amazon (the largest online retailer in the world) is one of the top impersonated brands. So much so that 360,000 people contact Amazon customer service to check whether a message they received is actually from Amazon. I’m sure y’all know what I’m talking about. I certainly have received plenty of them over the years. The con opens with a fake "there’s a problem with your Amazon order" and (if it’s successful) ends days later with the victim wiring their life savings to "keep them safe." For the most part, these scams eventually end up hitting the banking system, because the banks are the custodians of the money that the scammers are trying to steal. And while it’s fairly easy for the banks to predict that a specific ACH push transfer or wire transaction is the result of a scam (you’re sending $60,000 to an account you’ve never been associated with before … come on, man), it’s very difficult for the bank to stop the customer from going through with it at that point, given that the scammer has already put days, weeks, or even months of work into convincing the victim to trust them. Simply asking, “Are you sure you want to proceed with this transfer?” doesn’t work at that stage. And, unfortunately for the bank, after the consumer realizes that they were tricked, they (and their congressional representatives and any New York Times reporters they know) will be pretty mad at the bank, and saying, “you authorized the transfer, we’re not liable,” won’t mollify them. But you know what might stop the consumer from pushing send on the scam payment? The bank being able to engage the customer in a quick self-service chat about why they’re making the payment, and, when the customer says it’s to keep their money safe due to their Amazon account being compromised, the bank can definitively reply, “We just checked with Amazon, they never sent you that message." In order to more efficiently deal with its own customer service problem, Amazon has built a deterministic, first-party communication origin oracle — a way to answer "did this really come from us?" with certainty instead of probability. If banks could pipe Amazon's oracle into their payment-interdiction flow, they could upgrade a soft warning into hard evidence. Of course the problem with this idea is that Amazon isn’t very nice when it comes to sharing. In fact, when it comes to sharing its first-party data — even directly to its own customers or to agents that the customer has given permission to — Amazon is downright unfriendly. The company recently gutted its own order-confirmation emails, stripping itemized detail so receipts show only vague categories. This move has been framed as a privacy-enhancing feature, but it seems motivated, per The Verge, by the desire to keep external AI agents from harvesting purchase data out of your inbox. And Amazon has been engaged in a protracted legal dispute with Perplexity, relating to the AI company’s consumer-permissioned (but not Amazon-sanctioned) access to Amazon shoppers’ accounts (Amazon’s argument is that Perplexity is violating anti-hacking laws by using its agentic browser to access Amazon’s site on behalf of its users … the Ninth Circuit rejected that theory and vacated the injunction). In my humble opinion, Amazon would be wise to proactively reach out to the banking industry and set-up a consumer-permissioned data sharing infrastructure focused on scam identification and prevention. There’s nothing proprietary about Amazon’s new “did we actually send you a message” lookup service. It wouldn’t be giving away any super valuable first-party data or trade secrets, if it were to make this service available to banks (again, with end user permission). I know it’s not standard operating procedure for Amazon, and it would probably feel a bit weird, but I’m telling you: The level of scam activity that we are seeing is unsustainable. Policymakers are going to do something about it, at some point, and, if it gets to that point, their solution is likely to involve a significant redistribution of liability. Banks are prepared for this eventuality, and I’m quite certain that they will argue that a significant portion of that liability should fall on the platforms that sit upstream of them. Amazon, Meta, and the rest of those platform providers should do what they can, now, to head that possibility off at the pass. #2: Deposit Insurance May Be The One Banking Primitive You Can't DecentralizeWhat happened?Firelight, an on-chain "cover" protocol for DeFi, raised some money:
So what?Recently, a crypto/defi guy on Twitter posted this “genius” idea:
[Narrator: It is not, in fact, a genius idea.] For traditional neobanks leveraging BaaS, the FDIC insurance layer for neobanks is … the FDIC (facilitated through pass-through insurance). That’s a solved problem (though the solution could use some tweaks). For neobanks built on top of DeFi infrastructure, the problem looks a bit different and those differences make coming up with a solution much harder. Now, to be fair, the need for a solution is great … and growing. Smart contract exploits happen a lot in DeFi. Just recently, Rain had an outdated Solana contract with an authorization flaw drained for ~$1.1M across Avici, Tria, and others, with funds pushed through Tornado Cash and never recovered. Rain reimbursed every cardholder. But here’s the important part: It ate the loss off its own balance sheet. That's not insurance. That's a well-capitalized issuer absorbing a small, contained hit. The problem is also likely to get quite a bit bigger. We've spent a year watching the banks (ABA, BPI, ICBA) battle the crypto industry over whether stablecoins can pay yield. GENIUS banned issuers from paying it, and the banks want the Clarity Act to shut the "exchange loophole" so platforms like Coinbase can't pay rewards either. But that entire fight assumes the yield lives on the stablecoin. It doesn't have to. Coinbase already allows users to hold non-yield-bearing USDC as the settlement asset, route idle balances into a yield-bearing DeFi “vault,” and collect the interest. The company recently partnered with Ethena to create a High Yield Vault, which routes USDC deposits into higher-risk, Ethena-linked synthetic-dollar (USDe) markets for higher returns. This DeFi-shaped loophole isn’t exclusive to big platforms like Coinbase. It is increasingly being turned into infrastructure (so-called “yield-as-a-service”), so that other, smaller companies (consumer crypto apps, fintech neobanks, etc.) can offer high-yield “savings” products, funded by non-yield-bearing stablecoins. To be useful to the mainstream, non-degen audiences that those consumer crypto apps and fintech neobanks cater to, insurance (or “cover” as it’s called in DeFi) has to be broad and forgiving (we've got the scary stuff handled … don’t worry). But broad-and-forgiving is an insurance underwriter's nightmare, because smart-contract risk breaks every assumption insurance rests on. It's correlated (flaws live in shared contract code across multiple deployments — one bug, many victims), adversarial (attackers actively hunt the precise thing you're covering), and novel (you can't price a once-a-decade catastrophe from three years of data). Insurable risk is independent, idiosyncratic, and well-historied. In TradFi, deposit insurance works because it's centralized and permissioned. You can't get coverage without a charter, capital requirements, and ongoing supervisory exams. The FDIC controls who's in the pool, supervises the risk it insures, can resolve a failing bank before losses spiral, and sits on an insurance fund (paid into by all insured banks) with a Treasury backstop. Every one of those is a pricing-and-mitigation lever. DeFi throws them all out: Anyone can deploy code, no one can impose risk standards on the code, the riskiest protocols are the ones most desperate for cover (adverse selection), and the backstop runs only as deep as the collateral posted. It’s ironic. The permissionless composability that lets fintech and crypto companies dodge the stablecoin yield ban is the same property that makes the resulting risk nearly impossible to insure broadly. The feature and the bug are the same thing. #3: Embedded EWA for BanksWhat happened?Immediate, an earned wage access (EWA) provider, raised a small Series B:
So what?Immediate has deep ties in the community bank space. The company just added BankTech Ventures (a venture fund backed by community banks) to its cap table, and Castle Creek Launchpad (another venture fund backed by community banks) led Immediate’s last fundraise in 2023, in addition to participating in this most recent round. Given this, it’s not shocking that the company has — in addition to its core employer-integrated EWA business (which seems to be doing well … 625 employers nationwide) — created an embeddable EWA product for banks to offer to their customers. This strategy isn’t unheard of. DailyPay partnered with PNC to create an EWA product (EarnedIt), for PNC to offer to its customers. DailyPay also has similar deals with Santander, BMO, and TD Bank. The distinction is that through those DailyPay partnerships, the banks are offering EWA as a product for their commercial customers to offer to their employees. It’s B2B2B2C. The last ‘B’ in that chain (the employer) really matters because the employer is the one with the time and attendance data that earned wages are advanced against. Without that data, you are doing what’s referred to as “consumer-direct EWA,” in which you are making an educated guess about the employee’s earnings, using signals like bank transaction data. This is a riskier form of EWA, closer to short-term lending than true wage advancement. Immediate’s embedded EWA strategy for banks isn’t like the strategy that DailyPay has been pursuing. It’s not B2B2B2C. It’s B2B2C. Immediate wants financial institutions to offer EWA to their consumer customers by embedding it directly within their apps:
That’s a fundamentally different product than the one that Immediate sells to employers (and payroll and workforce management platforms), with different required integrations (you’d need the bank’s first-party deposit data in order to estimate earned wages), and a different credit risk profile (because the data is of a lower fidelity) and compliance risk profile (regulators are much more skeptical of consumer-direct EWA than employer-integrated EWA). Now, of course, some percentage of the consumers utilizing Immediate through their banks might already be covered, from a data perspective, by Immediate’s integrations with its employer customers. However, in that case, Immediate would be creating channel conflict between its bank customers and its employer customers, which might lead to more problems than it solves. Selling to banks always sounds like a great idea (and it often is … I’m a huge proponent of it, generally) but it can create some complexities. Sponsored by MX Personalization used to be a differentiator in banking. In this Data Takes spotlight, MX finds consumers treat it as the baseline. 61% expect their financial provider to know them and understand their needs. These figures are up slightly from MX’s Q2 report last year. That miss gets more consequential as banks layer AI into the experience. The top providers will be those who understand their customers best, because that guidance is only as good as the data underneath it. 2 READING RECOMMENDATIONS#1: Art, Science, and Large Language Models (by Tim Bates, The Stochastic Term) 📚Tim does a great job in this piece explaining the distinction between art and science in credit risk modeling and how he views LLMs fitting into that division. Subscribe to his new newsletter — The Stochastic Term — if you haven’t already! #2: A love letter to whimsy (by Kristen Anderson, Skeptical Optimism) 📚I really do sincerely want a Cash App wand! In my heart of hearts, I’m all about whimsy. Kristen makes a wonderfully compelling case for why this attribute should be more prized, and more sought after, by product designers in fintech. Subscribe to her new newsletter — Skeptical Optimism — if you haven’t already! 1 QUESTION FROM FINITYThere are a TON of interesting questions being asked in Finity (our digital community for fintech and banking nerds). I’ll share one question, sourced from the community, each week. However, if you’d like to join the conversation, please apply to join! How many new national banks (full-service and trust) do you think we will end up with by the time Comptroller Gould’s tenure at the OCC wraps up? By my count, we’re at about 34 approved so far. Where do you think we settle out at? If you have any thoughts on this question, reply to this email or DM me in Finity! Thanks for the read! Let me know what you thought by replying back to this email. — Alex | |||||||||
|