A 15 Min Bank & Other Bad Ideas
Happy Wednesday, Fintech Listeners!
Yesterday afternoon, I was on a call with someone and I referenced what I wrote about OpenAI opening up access to its personal finance capabilities to all ChatGPT users and I said, “In the newsletter I published earlier this week,”
Earlier this week … or what a normal person in a normal state of mind would have described as “yesterday.”
This week is going sloooowwww.
But I’m getting a lot done (as you’ll see over the next few weeks) and my family is happy and healthy, so nothing to complain about.
I hope your week has been going well and you have some time to listen to a podcast. I’ve got a good one for you today.
— Alex
MONEY 20/20 IS IN 11 DAYS
If you’re looking for something fun to add to your Money 20/20 agenda this year, I’ve got just the thing.
I’m hosting a low-stakes basketball tournament at UNLV on Sunday, Oct 18.
The teams are full, but you can sign up to be a sub or just come and hang out with other fintech nerds.
The more the merrier! RSVP here.
3 BIG IDEAS FROM THE PODCAST
.png?sig=3595fe540272a07d76b0a5721606276a9fd956e4fae49cd686d044d3e237a9bd)
Jason Mikula and I may need a new recurring segment: Geriatric Millennials Use AI Assistants and Report Back (GMUAARB?)
We opened this month’s Fintech Recap comparing notes on our very cautious experiments with AI assistants1. Among other things, Jason asked an AI assistant to file six FOIA requests across six different government agencies and portals; it successfully filed five and stopped at the sixth when it encountered a box requiring Jason to certify something under penalty of perjury.
Honestly? Encouraging!
Which brings us to our first story, filed under what Jason calls "things you can do with AI that maybe don't turn out well." Exhibit A is a Build-A-Bear-Bank Workshop, where anyone can launch a neobank in 15 minutes.
We also discuss the Revolut “hack,” which technically wasn’t a hack at all, and raises some unsettling questions about crypto, privacy, and whether Revolut is ready to become a bank.
And speaking of becoming a bank (!), we explore Chime’s decision to buy Stride and finally become the thing it spent years explaining it wasn’t. And as always, we end with a few topics that we can't let go of, including one dating back to some long ago FOIA requests …
Tune in for the full conversation here
And read below for my three big ideas...
#1: Whop! (There It Is)Copy anchor linkCopied
Recently, Whop tweeted that neobanks are great businesses that are easy to run, and that today you can create your own in 15 minutes.

As someone who has studied Whop from a distance for a few years, and who thinks a lot about how easy and profitable neobanks are to run (JK!), I had to engage with this story.
Whop, founded in the halcyon days of 2021, is a social marketplace platform where creators sell digital products, private communities, software access, and online courses. Its newer feature is "blueprints," which are pre-built business templates anyone can clone, kinda like a franchise for the digital economy.
One creator built a neobank blueprint from Whop's financial services primitives. It lets users load and store balances in fiat or USDT, swap USDT into other crypto tokens (including a Tether-affiliated one that tracks the price of gold), spend funds on a Visa card issued by Ramp, and transfer money across 140 countries using various payment rails. Any creator can copy it as their own neobank through Whop's AI assistant with a few natural language prompts. They can then market it however they want and set their own fees on top.2
Jason saw Whop’s (now removed) tweet and thought it looked too dumb, even for him (this is a direct quote). Then he read my recent newsletter and realized it was worse than he thought. So he built his own neobank.
It appears two folks have signed up (he’s hoping they're industry colleagues in on the joke). As the creator, Jason can look at their accounts as if he were them. Back in his days at Goldman Sachs, Jason couldn't see any Customer PII. That data was (of course) highly compartmentalized.
He also tested the guardrails. Whop's AI let him call the product a bank and tell customers their deposits were "super safe and FDIC insured," even though you’re not allowed to falsely claim that stored funds are FDIC insured and both the terms "bank" and "deposit" carry specific legal definitions. When Jason reached for the FDIC logo, Whop's AI finally balked. As he recalls it, the AI told him the logo was reserved for "legitimate banks" or "real banks."
Jason drew a nice contrast with the Synapse/Evolve era of mostly well-intentioned, if inexperienced, founders. This, he said, is "several orders of magnitude crazier and worse than that." This is true, but it’s also the natural end state of the journey we’ve been on with BaaS and fintech infrastructure. Every neobank founder wanted to move fast, cheaply and easily, without dealing directly with a bank or its core systems. Middleware abstracted the bank away. And in some cases, a bank's inability to impose risk and compliance standards on its partners became part of the appeal.
Fast forward a hundred years on BaaS Island, after all the plants and animals have withered away, and all that's left is a little point of rock in the sea.
That rock is a “neobank” built in 15 minutes through a series of AI prompts.
#2: Hacked Sans HackCopy anchor linkCopied
If you haven’t read about Revolut’s “hack"3 yet, that could be because you’re behind on your servings of the Fintech Takes and Fintech Business Weekly newsletters. Or because only about 680 users were affected, which is a drop in the bucket next to hacks that leak 150 million driver's licenses. But those 680 users were crypto whales, and they were specifically targeted.
As Jason reported, the group behind it, which goes by the "perhaps inaccurate" pseudonym IAmNotAVillain, appears to have used a login tied to an Italian municipality that leaked on the dark web. That login opened Italy's Posta Elettronica Certificata (PEC); their official certified email service used by the government, companies, courts, and citizens. Through it, the group sent European Investigation Orders directly to Revolut. The orders named specific wallet addresses.
For about six months, Revolut complied. It turned over names, addresses, passport or residence permit images, verification selfies, and full transaction histories.
Early chatter assumed this ran through an AML channel. Jason said AML-related requests tend to go through goAML, a UN-run system. An EIO is a different tool, a way for one EU government to send a legal request involving a company in another member state. Jason's understanding (who is not a lawyer) is that said request should go to an executing authority in the other country, which then serves the company. That doesn't appear to be what happened here.
On the consumer side, we distinguish between fraud, where someone breaks into your account, and scams, where you authorize the transaction yourself. This was something like the enterprise cybersecurity equivalent of a scam: Revolut was tricked into handing over information it shouldn't have handed over. And in retrospect, there were clues you would hope it could have caught.
Then there's the timing. Revolut is in the midst of getting approval to charter a bank in the U.S., and part of that approval process involves developing an information-security program. It has conditional approval from the OCC, but it still has more steps to clear, including with the FDIC and the Federal Reserve.
There's also history. Years ago, when Revolut operated in the U.S. through a partner bank, there was a weird difference between how its European and U.S. systems processed chargebacks or disputes. In the U.S., the system would return money when it wasn't supposed to. Bad actors figured out that loophole and exploited it to the tune of about $20 million. Revolut didn't even detect it. MCB, its partner bank, eventually alerted them.
Which for me, leaves one question (at the worst possible moment for a company awaiting its U.S. bank charter): Is Revolut really ready to be a bank?
#3: Too Big to SponsorCopy anchor linkCopied
There’s another part of Chime buying its bank partner Stride that Jason flagged, and I hadn’t really thought about it this way: What happens when a fintech partner gets so large that the balance of power between it and its sponsor bank flips?
Chime has had both Bancorp and Stride as bank partners. But if you’re Stride and you’re negotiating an acquisition with Chime, you’re at a bit of a disadvantage. Chime can basically say, if we can’t come to a deal we like, we’ll take our customers, take our deposits, and go find someone else.
In other words, Chime had the leverage.
That complicates one of the standard pitches for BaaS. For community banks, fintech partnerships were often portrayed as a kind of silver bullet: Find successful fintech partners and grow alongside them.
But Jason’s point is that the silver bullet can become a Trojan horse if one partner grows disproportionately large relative to the bank. At that point, the partnership itself can start to create strategic risk.
And Stride is a particularly interesting example because it landed a great winner in Chime. Yet once Chime became big enough, Stride became the smaller and less powerful party in the relationship.
And the eventual outcome? Stride gets acquired at roughly 1.5x tangible book value. That’s decent, but hardly extraordinary. So maybe the BaaS risk isn’t just picking the wrong fintech partner. Maybe it’s picking the right one, and having it outgrow you.
WHAT I'M LISTENING TO
#1: Banks Are Going Onchain on Weekends (Tokenized) 🎧Copy anchor linkCopied
Cuy and Simon are great in this episode (as always) and I’m a huge fan of Christian Catalini. He always seems to have a really well-calibrated take on the news of the day (which, in this case, is OpenUSD and AI agent risks in banking).
#2: Talking Consumer Sentiment with CBA President Lindsey Johnson (Bank Nerd Corner) 🎧Copy anchor linkCopied
Kiah Haslett and Lindsey Johnson. That’s all you need to know!
*Bonus: Collections Conversations, Episode 1: Fintech’s Next Test Across the U.S. and U.K (by me, with C&R) 🎧Copy anchor linkCopied
Fintech spent a decade perfecting onboarding. The real test, says Credit Strategy CEO Luke Broadhurst, comes after a missed payment. In the Season 2 opener of Collections Conversations, we dig into what Consumer Duty taught U.K. lenders about owning the consequences of AI decisions, and why U.S. fintech hasn't internalized that lesson yet.
*This rec is brought to you by one of our fantastic brand partners.
Thanks for the read! Let me know what you thought by replying back to this email.
— Alex
