@Edent Some of the issue seems to be the app allowing login and active use from two different devices simultaneously.

(Though a determined attacker might find a way around that... But a lot of people aren't going to be worth that level of effort, especially when this already seems to be an extra level of effort above what the usual banking scams use.)