Back to Blog
payments-infrastructureauthority

In the Zelle Lawsuit, Everything Turns on One Slippery Word: 'Authorized'

A New York judge just let the state's fraud case against Zelle's operator proceed. Strip away the headlines and the whole fight, and the billion dollars riding on it, comes down to what 'authorized' means when a person is tricked into sending money themselves.

ByKen Anderson
Published
Read time5 min

This week a New York judge let the state's fraud case against Zelle's operator go forward. Justice Phaedra Perry-Bond declined to dismiss the lawsuit brought by Attorney General Letitia James against Early Warning Services, the company that runs Zelle and is owned by seven of the largest US banks. The state alleges the network exposed users to more than a billion dollars in scams, and that its operator, in the court's summary of the allegations, prioritized convenience and market dominance over consumer safety when it rushed the service to market.

One thing worth saying clearly, because it will get lost in the headlines: the judge did not rule that anyone did anything wrong. Denying a motion to dismiss is not a verdict. It means only that, taking the state's allegations as true for now, there is a case worth hearing. The facts get fought out in discovery. Nobody has been found liable of anything.

I am not writing about who should win. I am writing because underneath this case, and a dozen like it, sits a single word that is carrying far more weight than it can bear. The word is "authorized." And once you see how much rides on it, and how little our payment systems actually put behind it, you understand that this is not really a fraud story. It is an infrastructure story wearing a courtroom costume.

The scam that isn't "unauthorized"

Here is the specific problem that makes these cases hard. In the classic protections for electronic payments, there is a bright line between an unauthorized transaction and an authorized one. If a criminal steals your credentials and moves your money, that is unauthorized, and the bank generally has to make you whole. If you move the money yourself, that is authorized, and you generally eat the loss.

Now consider the modern scam. Nobody steals your password. Instead someone convinces you, through a fake bank call, a romance, a bogus invoice, a spoofed text, to send the money yourself. You log in. You approve it. By the letter of the rule, you authorized it. The system did exactly what you told it to do, and in doing so it helped a fraudster clean you out.

That is the crux of the whole fight. Was a payment the victim was manipulated into sending "authorized"? The word says yes. Every human intuition says no. And billions of dollars of liability, across banks, networks, and consumers, hang on the gap between those two answers.

The rail only knows one bit

Step back from the law for a second and ask what the payment system actually recorded at the moment of the transfer. Almost nothing. It knows that a valid credential initiated a transfer of a certain amount to a certain destination. That is the whole of it. One bit, more or less: authorized, yes or no.

But authority, the real thing, the thing the law is trying to reason about after the fact, is not one bit. It is rich. It has scope: I meant to pay my contractor, not a stranger impersonating him. It has intent: I believed I was paying an invoice, not funding a scam. It has context: this is wildly out of pattern for me. It has provenance: who asked me to do this, and why. None of that context exists anywhere in the transaction, because the rail was never built to capture it. It captured the click.

So when a dispute arises, everyone is forced to reconstruct authority from the outside, months later, from call logs and chat transcripts and behavior patterns, arguing in a courtroom about what the person really meant. We are litigating intent because the infrastructure recorded none of it. The system flattened a rich human act down to a single yes, and now the legal system has to spend years and fortunes trying to reinflate it.

That is the same pattern that shows up all over finance, and it is worth naming plainly: we build systems that record the mechanical fact of what happened and discard the authority behind why, and then we pay for that omission later, in reconciliation, in disputes, and here, in litigation over a billion dollars of other people's losses.

What it would mean to take authority seriously

The team I work on at Conduit builds infrastructure for exactly this problem, so let me be careful to claim only what is true. No architecture stops a determined con artist from deceiving a human being. If you are tricked into wanting to send money, a better system will still, correctly, let you send it. That is not the part technology can fix, and I distrust anyone who says otherwise.

But the part technology created, it can uncreate. Authorization does not have to be one bit. It can be a real object: scoped to a purpose, tied to the principal who granted it and the context in which they granted it, checked against that scope before the money moves rather than reconstructed after it is gone. A payment to a first-time recipient, wildly out of pattern, initiated moments after an inbound call, is not the same act as paying your landlord on the first of the month, and a system that treated authority as more than a click would not have to pretend it was. It would not stop every scam. It would stop erasing the very information that everyone in that courtroom is now paying to recover.

That is the lens I would bring to the Zelle case, and it is bigger than Zelle. The reason "authorized" is doing a billion dollars of work is that we asked one small word to stand in for something our systems chose not to record. Courts will spend years allocating the loss. The more interesting question, for anyone building the next generation of money movement, is why we keep constructing rails that know that a payment happened and nothing at all about whether it should have.