The Bank That Isn’t a Bank: Synapse and the FDIC Mirage
No bank failed, so deposit insurance never paid a cent — and 100,000+ people still lost access to their money. Here’s what actually went missing, why the compensation arrived as a one-dollar penalty, and why the two rules meant to fix this still don’t bind anyone.
This one isn’t a deal teardown — it’s about the cash you park between deals, and a comfortable assumption I used to make about it. I was a YieldStreet investor, and I used their Wallet. When the banking-middleware provider Synapse — an Andreessen Horowitz–backed startup, not some fly-by-night operation — collapsed in 2024, I got the emails every affected customer got: distributions delayed, transfers to and from the Wallet frozen, a promise of updates “by Friday.” Then a second wave: your deposits are “securely held at FDIC-insured partner banks,” we’ve done a “cash infusion” to Synapse, we’re working to get you access. Then a third: funds will be returned “in stages,” bank by bank.
I got lucky. I had no cash sitting in the Wallet when the music stopped, so nothing of mine was frozen. That’s it — luck, not diligence. More than 100,000 people at other apps built on the same plumbing were not so lucky, and some of them are still waiting. And even my clean escape wasn’t total: a few weeks later I got a fourth letter — Evolve Bank, one of the banks behind the Wallet, had been hit by the LockBit ransomware group, and “it is likely your information is impacted” (name, Social Security number, date of birth). That breach swept up roughly 18 million people across Evolve’s fintech partners, YieldStreet among them, and settled for $11.9 million. Spread across 18 million people that’s about 66 cents each; the reason the administrator could estimate roughly $20 per claimant is that almost nobody files. The window has since closed. So I dodged the money freeze, ate the data breach anyway, and the compensation for my Social Security number was a coupon I’d have had to go claim.
That near-miss is why I went and read the whole story. What I found was worse than “a startup failed.”
A very good video making the rounds frames it well — “how millions of Americans got tricked into using a bank that isn’t a bank.” It’s worth ten minutes:
How the Plumbing Actually Works
Most “fintech” cash accounts — neobanks, savings apps, brokerage cash sweeps, and yes, investment-platform wallets — are not banks. They can’t hold your deposits directly. So the money flows through a chain, and each link is a place things can break:
| Layer | Who | What they actually do |
|---|---|---|
| The app | Yotta, Juno, YieldStreet Wallet, etc. | The interface you see. Not a bank. Shows you a balance. |
| The middleware | Synapse (banking-as-a-service) | Connects apps to banks and keeps the ledger of who owns what. Not a bank. |
| The bank | Evolve, Lineage, American Bank, AMG | Holds pooled cash in a single “For Benefit Of” (FBO) account. This is the only FDIC-insured link. |
Your money doesn’t sit in an account with your name on it. It sits in one big FBO account at the bank, commingled with everyone else’s, and the record of “$X of this pile belongs to Jordan Reyes” lives on the middleware’s ledger — not the bank’s. That arrangement is fine right up until the ledger and the bank’s books stop agreeing.
Why “FDIC-Insured” Didn’t Save Anyone
Here is the sentence that should be printed on the inside of every fintech user’s eyelids: FDIC insurance pays out when a bank fails. It does not pay out when the app fails, when the middleware fails, or when the ledger is simply wrong.
In the Synapse collapse, no bank failed. Evolve, Lineage, American Bank, and AMG National Trust were all fine. The insurance fund was never triggered because there was nothing for it to insure against. Yet more than 100,000 people couldn’t reach their money, because when bankruptcy trustee Jelena McWilliams — a former FDIC Chair, of all people — tried to reconcile the ledgers, the math didn’t add up.
It’s worth being precise about what “didn’t add up” means, because “a spreadsheet error” doesn’t make cash evaporate. The CFPB’s own enforcement complaint describes it plainly: Synapse failed to keep adequate records of where consumers’ funds actually were, and failed to make its records agree with the records its partner banks kept. When the banks totalled up what they were holding for end users, it came to less than what Synapse’s records said those users owned. End users were owed roughly $265 million; the partner banks initially identified only about $180 million against those accounts. The banks eventually paid out something closer to $219 million as reconciliation ground on, leaving a genuine hole the CFPB pegged at $60–90 million (the trustee’s range ran slightly higher, $65–95 million).
So the money didn’t vanish into a rounding error. Funds had moved among four banks across multiple program migrations, and the only authoritative map of who owned which dollar was maintained by the company that went bankrupt. No insurance product covers that. Deposit insurance answers one question — “did the bank fail?” — and the answer was no.
The result was the cruelest kind of fine print made real:
- A customer who deposited ~$130,000 was told the bank had $1,182 in her name.
- A Yotta customer with ~$50,000 recovered $1.49.
- A family that parked ~$280,000 in home-sale proceeds was told they’d get $500.
Even the “Insurance” Is Conditional
The coverage fintechs advertise is pass-through insurance: the idea that FDIC protection “passes through” the FBO account to each underlying customer as if they held the money directly at the bank. It’s real — but it isn’t automatic. The FDIC grants it only if three recordkeeping conditions are met, and it only checks at the moment a bank fails:
- The funds are genuinely owned by you, not the fintech.
- The bank’s records show the account is custodial (“FBO”).
- Someone’s records — the bank’s or the middleware’s — accurately tie each dollar to its real owner.
Condition #3 is exactly what broke in Synapse. If the ledger is a mess when the music stops, pass-through coverage can simply fail to attach — and the FDIC’s own guidance says the pooled deposit then reverts to being insured in the fintech’s name, which can leave you uninsured. Every locked-out depositor had, at some point, looked at a screen with an FDIC logo and felt safe. That’s the crux: “FDIC-insured” describes a good outcome under good conditions — not a vault.
The Part That Bothers Me Most: Somebody Did Know
The obvious question is how an ordinary customer was supposed to see this coming. The honest answer is that they couldn’t — but that’s not because the information didn’t exist. It’s because it existed somewhere they had no access to.
Examinations of Evolve in 2023 — a year before Synapse filed — found the bank “engaged in unsafe and unsound banking practices by failing to have in place an effective risk management framework” for precisely these fintech partnerships, along with inadequate anti-money-laundering and consumer-compliance controls. That’s the Federal Reserve’s language, from reports of examination dated August 2023 and January 2024. The resulting cease-and-desist order, issued jointly with the Arkansas State Bank Department, landed on June 14, 2024 — roughly two months after customers were already locked out. It carried no fine, and the Fed took care to note it was “independent of the bankruptcy proceedings regarding Synapse.”
Read that sequence again. The supervisor identified the exact category of failure a year early, in a confidential exam. The customers reading “FDIC-insured partner banks” in a marketing email got none of it. Bank supervision is not a consumer-disclosure system and was never designed to be one — but the practical consequence is that the single most useful fact about Evolve’s fintech program in 2023 was, by design, unavailable to the people whose money was in it. The FDIC logo was public. The finding that the recordkeeping was unsound was not.
The Bigger Trap: Millions Chasing Yield in Apps That Aren’t Banks
A frozen investment wallet is the small version of this problem. The Synapse apps — Yotta, Juno, YieldStreet’s Wallet — were niche. The mass-market version is the tens of millions of ordinary savers who’ve moved cash into “high-yield” fintech apps chasing a better rate. By 2025, roughly 53 million U.S. adults held accounts at digital-only “banks,” and industry research put something like 44% of new checking accounts in 2024 at fintechs and neobanks rather than chartered banks. The lure is the number on the screen: apps advertise 4–5% APY against an FDIC-measured national average savings rate of 0.38%, a figure that hasn’t budged through mid-2026.
Most of those apps are not banks. Chime — the largest, now public — says so in its own SEC filings: “Chime is a technology company, not a bank,” with deposits held at partner banks (The Bancorp Bank and Stride Bank). Chime is a reasonably transparent operator that names its banks, and that’s exactly the point: the structure is the same one Synapse sat inside. Your safety rests on the partner bank’s records being right and the app staying solvent and honest. The logo in the app-store listing speaks to neither.
When the yield is the whole pitch and the plumbing is opaque, people have lost real money — no bank failure required:
- Beam Financial billed itself as “the first mobile high-interest bank account for the 99%,” dangling rates as high as 7% on “FDIC-insured” deposits with “24/7 access.” Customers then couldn’t withdraw for weeks or months. The FTC sued in 2020 and shut it down in 2021, forcing roughly $2.6 million in refunds and banning the founder from the business. The deposits were nominally in an FDIC-insured bank the whole time. It didn’t matter, because the app was the thing that broke.
- Voyager marketed rewards up to ~12% and repeatedly told customers their dollars were FDIC-insured and “safe.” They weren’t: Voyager wasn’t a bank, only its cash at one partner bank (Metropolitan Commercial Bank) was insured — and only if that bank failed — while crypto isn’t FDIC-insured at all. When Voyager went bankrupt in July 2022, customers were locked out; the FDIC and Federal Reserve issued a cease-and-desist over its false FDIC claims, and the FTC later settled with the company and charged its CEO. Fellow crypto-“yield” platform Celsius collapsed the same summer owing customers ~$4.7 billion.
Above-market yield is payment for risk someone is taking. What’s worth noticing is which risk. In none of these cases was the money lost to credit risk or rate risk — the things a saver might reasonably think they were being paid to bear. It was lost to the layer between the customer and the bank ceasing to function. That risk was never disclosed as a risk, because from the inside it doesn’t look like one. It looks like plumbing.
“But My High-Yield Account Is at a Real Bank — Am I Exposed?”
Fair question, and the honest answer is: probably not to this. There’s a world of difference between a high-yield app and a high-yield account at a chartered, FDIC-insured bank — and plenty of legitimate online-first and regional banks pay north of 4% precisely to win deposits. The rate isn’t the tell; the structure is. If your cash sits directly at a named, chartered bank, FDIC covers you directly if that bank fails. There’s no middleware ledger in between to break, and no “is my slice of the pool documented” question. That’s the good version of this story.
The one question that sorts the safe version from the trap: are you a customer of the bank itself, or of a fintech that merely “provides banking services through” some partner bank? A real chartered bank has its own FDIC certificate you can look up. If the entity you signed up with isn’t that insured bank, go find out which one actually holds your money. Clear that, plus the limit and deposit-product checks below, and a competitive APY is just a bank competing for your deposit.
Where It Stands
| Synapse bankruptcy | April 2024 |
| People locked out | 100,000+ |
| Owed vs. eventually paid by banks | ~$265M / ~$219M |
| Shortfall (CFPB / trustee) | $60–90M / $65–95M |
| Civil money penalty against Synapse | $1.00 |
| CFPB relief allocated (Nov 28, 2025) | $46.2M (~half) |
| Distribution to victims | Not yet begun |
| FDIC custodial recordkeeping rule | Still proposed |
| FDIC digital signage rule | Relaxed; binds Apr 2027 |
It’s widely reported as though victims must file, and that’s worth correcting, because it’s the opposite of the truth: there is no claims window, and you can’t apply. The CFPB determines eligibility from its own records and the terms of the court order, then hires an administrator to push money out. The Synapse case still hasn’t appeared on the Bureau’s list of distributions in progress — it isn’t among the ongoing cases or the closed ones — which means the allocation exists on paper and the payments don’t. Nobody harmed here can do anything to speed that up, or even establish where in the queue they are.
The Strangest Detail: A One-Dollar Penalty
Where did the $46.2 million come from? Not from Synapse, which is bankrupt. Not from the partner banks, which had already paid what they could reconcile. Not from deposit insurance, which never applied.
It came from the CFPB’s Civil Penalty Fund — the pot of fines collected from entirely unrelated companies that violated consumer-finance law. And the key that opened it was procedural. In August 2025 the Bureau filed an adversary proceeding against Synapse in the bankruptcy; a stipulated judgment entered September 12, 2025 imposed a civil money penalty of exactly $1.00. That dollar wasn’t a punishment, it was a legal precondition: the statute lets the Bureau tap the Civil Penalty Fund to compensate victims in cases where it has obtained a penalty. So the Bureau extracted a token dollar from an insolvent estate in order to unlock $46.2 million contributed by other firms’ misconduct.
I don’t say that as a criticism — it’s a resourceful use of a narrow authority to get money to people who had no other route to it. But look at what it tells you about the structure. This was the first time the fund had been used for a fintech collapse of this kind, which is why some observers called it a fintech bailout. Two things follow. First, the backstop is discretionary: it depended on an agency choosing to act creatively, not on any entitlement the depositors held. Second, the fund is finite, and this allocation drew it down substantially, with reporting at the time noting it was running low. A second Synapse would arrive to find the same legal gap and a materially emptier pot.
That is the opposite of how deposit insurance works. The FDIC’s fund is pre-funded by assessments on banks, backed by the Treasury, and pays on a rule. This paid on a $1 penalty and an act of institutional improvisation, and it covered about half.
Is This Fixed? No — and the Detail Is Worse Than “Stalled”
The tempting read is “Synapse is gone, lesson learned, move on.” Two rules were supposed to close the gap. Neither binds anyone today.
1. The rule that would have caught the ledger gap is still a proposal. In September 2024 the FDIC proposed Recordkeeping for Custodial Accounts (RIN 3064-AG07), which would require banks holding these pooled accounts to maintain beneficial-owner records identifying each owner and balance, reconciled daily, in a standard file format, with an annual sign-off from the CEO. It is hard to design a rule more precisely aimed at what went wrong. The comment period closed January 16, 2025 — and it has not been finalized since. The FDIC didn’t withdraw it, notably, even while formally scrapping a batch of other proposals in March 2025. But the reason it’s parked is on the record. Travis Hill was Vice Chairman when the rule was proposed, and he said at the time that it had been prematurely issued and should have waited for responses to a pending request for information on bank-fintech relationships. He was confirmed as FDIC Chairman on December 18, 2025 and sworn in the following month, for a five-year term. The industry’s own lobby has since asked the FDIC to withdraw the rule outright. A guardrail whose most prominent skeptic now runs the agency, with four years left on the clock, is not a guardrail I’d plan around.
2. The rule aimed squarely at the logo got softer, and still doesn’t apply. This is the part I’d missed, and it’s the sharper story. The FDIC adopted digital signage requirements back in 2023 — rules about when the official FDIC sign must appear on a website or app, and when non-deposit products must be flagged as not insured. Exactly the mirage problem. Full compliance on the digital provisions was set for May 1, 2025, then postponed to March 1, 2026. Then, on January 29, 2026, the FDIC finalized amendments that loosened it: prescriptive formatting requirements dropped, the display obligation narrowed to the homepage, login page and first page of account opening, and non-deposit signage confined to pages primarily dedicated to non-deposit products. Practitioners read it, accurately, as easing compliance burden. The amended rule took effect March 2, 2026 — with a compliance date of April 1, 2027.
Add it up: the signage regime has been on the books since 2023 and will not actually constrain anyone until 2027, in a form weaker than originally written, while the recordkeeping rule sits unfinalized indefinitely. Three years after 100,000 people lost access to their money, the regulatory response to “the FDIC logo does more work than it’s entitled to” is a rule that has been postponed twice and relaxed once.
3. The structure is still everywhere. Synapse died; the model didn’t. The same app-to-middleware-to-pooled-bank stack sits under a large share of everyday fintech accounts, and any of them can hit a reconciliation failure, an outage, or a middleware bankruptcy that deposit insurance was never designed to catch. This wasn’t a freak event. It was a design flaw behaving exactly as designed.
The Honest Handicap
Let me be careful about what I’m not saying. My near-miss is not evidence these apps are safe — if anything it’s survivorship bias with my name on it. I can’t prove any particular app is mishandling money today; the vast majority move billions daily without incident, and pass-through insurance genuinely works when the recordkeeping is clean. The failure here isn’t that fintechs are frauds.
I should also concede the strongest counterpoint to my own pessimism about the money. I’ve made a lot of the CFPB being hollowed out through 2025, and of the Civil Penalty Fund historically averaging something like 682 days from judgment to first payment. But this case moved unusually fast by that standard — judgment in September 2025, allocation by late November — which is evidence against the “skeleton crew can’t deliver” story I’m inclined to tell. The delay to date may be ordinary administrative lag rather than institutional collapse. I hope so.
And the boundary of the claim: this is a tail risk. Low probability, high impact, and nearly impossible to hedge once your money is already inside. That’s precisely the kind of risk worth pricing before, not after.
What I’d Actually Do About It
- Treat a headline APY as a question, not a gift. Above-market yield is someone being paid to take a risk; if you can’t see whose risk it is, assume it’s yours — especially as the rate climbs past ~4–5% into “rewards,” crypto “earn,” or fixed double digits.
- Know the actual bank. Find the named partner bank in the app’s disclosures and verify it on the FDIC’s BankFind tool. If you can’t find a specifically named bank, treat that as a red flag, not a rounding error.
- Separate “insured” from “reachable.” Insurance answers “what if the bank fails?” It says nothing about a frozen ledger, an app outage, or a middleware bankruptcy — the things that actually locked people out.
- Mind the aggregation trap. If you already bank directly at the same partner bank behind the app, your balances stack toward the single $250,000 limit at that bank. The split you see across two apps is an illusion.
- Don’t keep operating or emergency cash in a fintech layer. Payroll, rent money, the emergency fund — that belongs somewhere you can reach it on a bad day, not somewhere that can go dark for months while lawyers reconcile a ledger.
- For serious cash, cut out the middleman. Hold it directly at a bank in your own name, or in a brokerage in T-bills or a money-market fund. Give up a few basis points of “high yield” to delete an entire category of counterparty risk.
Where I Land
My YieldStreet book is effectively closed and I don’t put new money there — I wrote up why in detail when they rebranded to Willow Wealth. The Wallet was never part of my thesis; it was a convenience I happened not to be using on the wrong day.
But the specific thing I got wrong is worth naming, because it wasn’t about YieldStreet at all. I had mentally filed cash as the part of the portfolio that didn’t require diligence — the safe corner I could stop thinking about while I concentrated on whether the cases and loans I’d actually chosen would pay. Every hour I spent underwriting an investment, I spent zero underwriting the account the money waited in. The Synapse depositors weren’t reaching for 12% in crypto. Most of them were doing the responsible thing with their savings, in an app with a logo on it.
So the verdict is narrow and operational rather than sweeping. I’m not avoiding fintech — I still keep a spending float in apps because it’s convenient, and losing that float would annoy me rather than hurt me. What changed is that I now size the balance to the structure instead of to the interface: money I could not afford to lose reach of for six months does not sit anywhere that a bankruptcy court would have to reconstruct a ledger to find. Insurance is not custody, and a logo is not a lien.
The question I ask a screen that says “FDIC-insured” is now two questions, and the second one is the one that matters: who has to fail before this promise pays, and is that the failure most likely to happen? For a pooled fintech balance the answers don’t line up. The promise pays if the bank fails. The bank is the sturdiest link in the chain — four of them came through Synapse intact. What failed was the ledger that said which dollars were mine, and no insurance product in this structure is written against that.
Sources
- YieldStreet investor emails to the author (May 2024 Wallet-delay notices; June 26, 2024 Evolve Bank data-breach notice)
- “How Millions of Americans Got Tricked Into Using a Bank That Isn’t a Bank” (YouTube)
- CFPB: Synapse Financial Technologies, Inc. enforcement action — adversary proceeding filed Aug. 21, 2025; stipulated final judgment entered Sept. 12, 2025; failure to maintain adequate records of the location of consumer funds; shortfall of $60–90 million; Stipulated Final Judgment and Order (the $1.00 civil money penalty enabling access to the Civil Penalty Fund)
- CFPB Civil Penalty Fund — $46,248,291 allocated to Synapse victims Nov. 28, 2025; consumers cannot apply, eligibility determined by the Bureau; American Banker: CFPB to refund $46 million to Synapse victims; Crowdfund Insider — first fintech-collapse use of the fund; fund running low; 682-day historical average from judgment to disbursement
- CNBC: Synapse trustee says $85 million of customer savings is missing (Jun. 7, 2024) — 100,000+ customers; ~$265M owed vs ~$180M held
- Fintech Business Weekly: The Synapse-Evolve Disaster, One Year Later — ~$265M owed vs ~$219M paid
- American Banker: Evolve Bank says it will start returning money to Synapse end users — $65M–$95M trustee shortfall range; McWilliams as trustee
- Federal Reserve: enforcement action against Evolve Bancorp and Evolve Bank & Trust (Jun. 14, 2024) and the cease-and-desist order — 2023 examinations found unsafe and unsound practices in fintech-partnership risk management; no fine; issued jointly with the Arkansas State Bank Department
- U.S. Senate Banking Committee letter re: Evolve (Apr. 22, 2025) — individual loss examples
- FDIC: Recordkeeping for Custodial Accounts (RIN 3064-AG07) — proposed Sept. 17, 2024, published 89 FR 80135; comment period closed Jan. 16, 2025; daily reconciliation and beneficial-owner records; still not finalized. Davis Polk on Vice Chairman Hill’s “prematurely issued” objection; Steptoe and Davis Wright Tremaine confirming it was not withdrawn in the March 2025 rollback; American Fintech Council letter requesting withdrawal
- FDIC: Travis Hill sworn in as 23rd Chairman (Jan. 13, 2026) — Vice Chairman from Jan. 2023, Acting Chairman from Jan. 2025, confirmed by the Senate 53–43 on Dec. 18, 2025 for a five-year term
- FDIC: final rule on Official Signs and Advertising (12 CFR Part 328, RIN 3064-AG14), 91 FR 3801 (Jan. 29, 2026) — effective Mar. 2, 2026, compliance date Apr. 1, 2027; Davis Wright Tremaine analysis of the loosened requirements; FDIC Part 328 Q&As (updated May 13, 2026)
- FDIC: pass-through deposit insurance requirements
- Federal News Network: CFPB can proceed with mass layoffs (Aug. 2025)
- American Banker: Evolve Bank settles for $11.9 million over 2024 data breach — LockBit; ~18 million people; YieldStreet among affected fintechs
- FTC: Beam Financial settlement (2021) — ~$2.6M refunds, founder banned
- FDIC & Federal Reserve: cease-and-desist to Voyager Digital over false FDIC-insurance claims (Jul. 2022); FTC settlement with Voyager (Oct. 2023)
- FDIC National Rates and Rate Caps — savings national rate 0.38% as of July 20, 2026
- Neobank scale: ~53.7M U.S. adults on digital-only accounts by 2025 (EMARKETER/Insider Intelligence); Chime FY2025 Form 10-K (“Chime is a technology company, not a bank”)
Commentary and personal experience — not investment, legal, or tax advice. Investing carries risk, including total loss of capital. Always do your own due diligence.






