To be fair to Mercury, they are quite open about this fact.
As an example: fintech builds front end that takes deposits from user, but not much more. The deposit passes to an intermediary that pools deposits and puts them in FBO accounts at a real (FDIC) bank. Intermediary collapses. Now neither the bank nor the fintech know who had what.
This is exactly what happened when Synapse collapsed (which impacted Mercury at the time too)[0]
[0] https://www.yalejournal.org/publications/the-synapse-collaps...
https://www.retailbankerinternational.com/news/occ-grants-co...
https://www.linkedin.com/posts/mercuryhq_big-news-not-a-bank...
Are ACH returns really that difficult to initiate in the US? I've fortunately never had to do one, but in SEPA land, it's usually a single click in online banking, or at worst a simple message to customer support.
Fraudulent ACH transactions would be a federal crime if you found a pathway to do them, and you'd probably be tracked down pretty quickly because unlike crypto, ACH transactions are fully trackable and auditable between accounts that have identified owners.
To be clear, this fraud happens similarly to credit card fraud: Fraudster F gets accountholder A's account and routing number, opens an account with merchant M and racks up a bill; M charges A, A reports an unauthorized payment to their bank. Usually M ends up eating the loss.
No, ACH authorisation is an entirely different matter. I could agree to show you the check I wrote to my landlord, but I'm not willing to give you my check book with my signature — and no other data — on all the blank checks.
ACH authorisation is an analog of the latter, not the former.
You can then easily dispute them, but I'd still call that "access to your account".