Not only are there enormous protections with the mis-use of one's credit card, but the 'password'/card number is randomly generated and not used elsewhere.
A regular person is quite likely to reuse their favourite password for their bank login and therefore expose most of their other services when Plaid is inevitably hacked, or more likely, when someone pretends to be Plaid with typosquatting and the user has learned that giving passwords away is OK.