Evolve is an otherwise obscure bank chartered in Arkansas but headquartered in Tennessee (a little sketchy) that has over-leveraged itself. This is why it was hit with a Cease and Desist from the FDIC. The C&D also probably contributed to them becoming a target for LockBit.
Evolve is also the underlying bank for Stripe Treasury, although to my knowledge, their have been no new partnerships with them. I have heard the number 2 thrown around. Of note, Shopify is the main person for whom this was built and uses this.
Consequently if you have submitted KYC/KYB information for Shopify, Mercury, Yotta, Dave, any other past Synapse partners, or some Modern Treasury partners your data was breached. This seems to be the primary information shared along with account and routing numbers. This becomes problematic especially as part of the check involves external account and routing numbers along with SSN of any UBOs.
Fintechs do not partner with small banks because of debit card fees but because of Dodd Frank regulations (primarily).
Their email made it sound much less serious.
(Apropos nothing, sorry about your motorcycle accident — I hope you’ve recovered well. Thank you for this comment; the severity of this breach wasn’t apparent till now.)
Thanks for pointing that article out. It made me reconsider whether it’s wise to keep money in Mercury.
EDIT: this rabbit hole goes deep. https://techcrunch.com/2024/05/16/a-us-trustee-wants-trouble... "San Francisco-based Synapse, which operated a platform enabling banks and fintech companies to develop financial services, was founded in 2014 by Bryan Keltner and Pathak. It was providing those types of services as an intermediary between banking partner Evolve Bank & Trust and business banking startup Mercury, among others."
Mercury is by far the best bank I’ve ever used. But they’re not actually a bank, just a partner to one, and the foundations seem shakier than they appeared.
I hadn’t really stopped to consider "what if Mercury goes out of business?" till now. Silicon Valley Bank seemed like a one-off disaster, but now I’m not so sure.
Is there any bank that isn’t awful? Even just reliable wire transfers was beyond the capabilities of US Bank, for example, and it was a business account.
The majority of the banking industry is built on Cobol. Open Banking is the only real path forward. The issue of the US vs EU open-banking is the number of community banks.
The, unfortunate, most reliable banks from a technology/data perspective are ones that are large enough to be loathsome to deal with. Think JP Morgan, BoA.
Even banks of that size, Comerica, have had massive ledgering issues recently, so they are not immune.
Some reputable players in the BaaS industry are Unit, JP Morgan, Jack Henry, Moov(Massive plug for them), VGS (works with Visa and MC btw). If your neo-bank works with them, I would trust my money there. I do trust my money with one of those partners.
How is it not false advertising on the part of Mercury to describe their accounts as FDIC-insured if this is the case?
Regarding regulators and obligation -- in any of these relationships the bank is ultimately responsible/liable for any AML/TFL, money, etc... irregularities. A BaaS provider can effectively do everything wrong to the point its underlying bank is shut down, and switch to a different partner bank.
Ugh. The bankruptcy court has to bring in forensic auditors, they try to reconstruct who owns what, and it takes a long time to sort things out. The bank's responsibility is only to have the total amount on deposit available to the bankruptcy court.
This is a really good argument for not using such a service.
"The collapse of middleman Synapse has revealed fintech’s promise of safety as a mirage. More than 100,000 Americans with $265 million in deposits have been locked out of their accounts."[1]
Evolve has problems: Fed report on Evolve: "Examinations conducted in 2023 found that Evolve engaged in unsafe and unsound banking practices by failing to have in place an effective risk management framework for those partnerships. In addition, Evolve did not maintain an effective risk management program or controls sufficient to comply with anti-money laundering laws and laws protecting consumers."[2]
The combination of a collapse on the fintech side, bad risk management on the bank side, and a "hack" looks bad. It also raises the possibility that the "hack" might be an inside job to cover up theft. We've seen that happen in crypto land more than once.
[1] https://www.cnbc.com/2024/07/02/synapse-fintech-fdic-false-p...
[2] https://www.federalreserve.gov/newsevents/pressreleases/enfo...