I think the bank failing risk is eliminated, if it fails the forwarded payment is unlocked so bankA gets their money back.
Bank failing in this context would be the bridge (EDIT: contract) gets hacked. Hence mitigated, but not eliminated.
Correct, but in its place is a new systemic risk with a real-world nonzero probability: the contract itself getting hacked. There isn't analogy for this in modern banking since the equivalent issue would either (a) get rolled back or (b) fold into the bank failing envelope. (There is analogy in pre-modern banking, though it largely revolved around debasement and invasion.)