# Spotting the risks that sink fintechs before the market notices
In May 2024, roughly 100,000 Americans woke up unable to access their own money. Their funds sat in accounts branded by fintech apps like Yotta and Juno, but the actual dollars lived at partner banks, routed through a middleman called Synapse. When Synapse collapsed into bankruptcy, nobody could agree on whose ledger was correct. Some depositors are still missing money, more than a year later. No hack occurred. No fraud was proven. The system just failed to answer a basic question: whose money is this, exactly.
That question, and two others like it, are what this lesson trains you to ask before a fintech's problems become public.
Fintech failures rarely come from one dramatic villain. They come from three recurring, boring-sounding risk categories that compound quietly:
Synapse was a custody and concentration failure. Wirecard was a compliance failure disguised as a growth story. Learning to tell them apart is the actual skill here, not memorizing definitions.
Compliance risk
Wirecard, once a DAX-listed German payments giant worth over €24 billion at its 2018 peak, collapsed in June 2020 when auditors discovered that €1.9 billion supposedly held in Philippine bank accounts didn't exist. The company had fabricated a large share of its Asian business through fictitious "third-party acquirer" partnerships for years. BaFin (Germany's financial regulator, the Bundesanstalt für Finanzdienstleistungsaufsicht) was criticized afterward for defending Wirecard against short-sellers' fraud allegations instead of investigating them.
The lesson isn't "audit your auditors." It's that compliance risk hides in plain sight in growth metrics that seem too smooth. Wirecard's Asian revenue growth was inconsistent with the size and maturity of those markets. Nobody who wasn't looking for it noticed.
Where compliance risk lives in fintech today:
Custody risk is the danger that customer funds aren't held the way customers believe, aren't legally protected, or can't be traced back to them individually.
Synapse was a Banking-as-a-Service (BaaS) middleware provider: it connected fintech apps to FDIC-insured partner banks (the Federal Deposit Insurance Corporation insures US bank deposits up to $250,000 per depositor, per bank) without being a bank itself. Many customer-facing apps advertised "FDIC insured" accounts. But FDIC insurance only protects against bank failure, not against a middleman's ledger being wrong or its bankruptcy freezing fund flows. When Synapse folded, reconciling which end-user owned which dollar, across multiple partner banks and the failed Synapse database, became forensically difficult. As of 2025, some funds remain unrecovered, an outcome regulators and consumer advocates have called a preventable failure of oversight.
The custody question to always ask: if this middleman disappeared tomorrow, could my money be identified and returned by end of week?
For crypto platforms, custody risk is even sharper: are customer coins held 1:1 in segregated wallets, or commingled with the firm's own trading capital? FTX's 2022 collapse was fundamentally this failure. The CFTC (Commodity Futures Trading Commission) and SEC (Securities and Exchange Commission) have since pushed harder on proof-of-reserves disclosures, though standards remain inconsistent industry-wide.
For a plain-language regulatory primer on BaaS risks, the Consumer Financial Protection Bureau's guidance on bank partnerships is a solid free starting point.
Concentration risk is over-dependence on one entity, whether a partner bank, a single large client, a funding source, or a geography.
Synapse again illustrates this well: dozens of fintech apps depended entirely on one middleware provider with no backup plan. When it failed, there was no orderly transfer path. Regulators have since pushed partner banks toward direct oversight of BaaS relationships rather than fully outsourcing compliance to intermediaries.
Concentration risk also shows up as:
A quick worked example. Suppose a fintech lender's revenue comes from three partner banks, split 70/20/10. If the 70% partner exits (a real, recurring event as banks reassess BaaS risk appetite post-2024), the firm doesn't lose 70% of revenue gradually, it can lose it within a regulatory notice period, often 90 days. Run that math before assuming a growth chart is sustainable: 70% of a $50 million run-rate is $35 million gone in a quarter.
Vérification des acquis
1. A fintech's collapse leaves customers unsure whose ledger correctly reflects their account balances, because their money passed through a middleman connecting the app to partner banks. Which risk category does this best illustrate?
2. A company fabricates evidence of business activity and assets that don't actually exist, to appear compliant and financially healthy to regulators and investors. This is best classified as which risk?
3. Why is it useful to distinguish compliance, custody, and concentration risk as separate categories rather than treating 'fintech risk' as one general concern?
4. Select ALL correct answers about concentration risk in fintech.
Sélectionnez toutes les réponses correctes.
5. A fintech app displays customer balances, but the actual cash is held at a partner bank and routed through a middleman processor. Select ALL correct answers about how to assess this situation.
Sélectionnez toutes les réponses correctes.
You don't need a compliance license to run a first-pass check on a fintech, whether as an investor, partner, employee, or informed customer.
Compliance checks:
Custody checks:
Concentration checks:
🎬 [VIDEO: "How Wirecard's $2 Billion Fraud Unraveled" - youtube.com - a concise breakdown of the accounting mechanics behind Europe's biggest fintech fraud, useful for seeing compliance risk in action]