Silly, I know.
So if you post your account numbers I can pull all your money out. Now you'll likely get it back if you file a fraud claim, but that's an extra Hassel, and your out finds until they give you a provisional credit.
Here in the UK while it's super easy to set up a fraudulent direct debit on someone else's account details, it's equally easy to claim those payments back (and the scheme guarantees you the right to be able to claim a payment back for any reason, doesn't even have to be fraud - the merchant can of course still chase you if you've declined a legitimate payment you owe them).
I don't know if something really happened or if he was just being cautious, but so the Bank of San Seriffe was born: https://www-cs-faculty.stanford.edu/~knuth/boss.html
E V E R Y german company has their SEPA information on almost every piece of writing that leaves the company (in the footer) and thus far i think widespread misuse/fraud is not really a thing.
But what you say must be impossible in SEPA too - to fake a sub registration you'd have to register with a corporation ID as a subscription receiver in the SEPA area. I'd suppose at least you fraud one person you're immediately found. But it's also that you probably can't even register without at least a sort of reputation check.
To withdraw in both continent you'd need a pin or a signature + a tamper-proof ID card. The web app in Hong Kong has 2 passwords + 2 private key phone checks + insta SMS sent on any output. My French bank resets the private key every 3 months and require a strong re-auth (SMS or postal mail).
To direct debit, in HK you can only trigger it from the source account by registering the target online, it can't be done the other way around, while in France you need a signed authorization - but I suppose that can be faked if you have a target entity already registered and fake signatures to a bank.
And you're telling me in the US I know your target bank account to wire you pocket money at your birthday, I can also just withdraw ? That can't be right sorry.
Yes, it can be and it is right.
Despite getting free transfers (UK), I prefer middlemen.
I've had one transfer via Revolut, it was significantly more effort than I'd expected, but I'd do it again if explicitly asked for.
General security advice is to not share your bank details. I'd rather take the hit from PayPal fees or someone not donating rather than worrying about fraud. [0] for example.
Patreon (etc..) is recurring revenue, which builds confidence that what you're doing is sustainable long-term. When an OSS project opens for donations, it typically has an established userbase. The first "ask" will bring a comparatively large amount of money compared to the next "ask", and it raises the question of whether one-time donations will dwindle to zero. Recurring revenue hedges against that (and also allows more community building).
Banks and credit unions in the US usually have a bill pay system to send checks or e-checks for free. Some people do use it to contribute to projects, sometimes even as a recurring donation, but it's rare. I'm not sure it would be so cheap if it weren't rare.