frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

OpenAI is connecting ChatGPT to bank accounts via Plaid

https://firethering.com/chatgpt-bank-account-plaid-openai/
45•steveharing1•1h ago

Comments

ernsheong•41m ago
What could go wrong
steveharing1•9m ago
It won't go wrong if you don't wanna use this feature but if you do then its upto you that you''re trusting a for profit company that much that you provide them with your confidential data.
righthand•40m ago
“Let the bodies hit the floor!”
hyperionultra•40m ago
Do we still have a choice to not use?
steveharing1•38m ago
You absolutely do not have to use the new financial feature. Its optional
reaperducer•35m ago
Until every web site and bank requires you to use it because their CTO saw an ad in an airport that said it was a good idea and makes line go up.

"Leadership" today is monkey-see, monkey-do.

See also: Sign in with Google on every web site, even if you don't have a Google account; and Cloudflare interrupting your web surfing every six minutes to make sure you haven't be absorbed by the Borg.

parliament32•39m ago
Little doubt the true motivation behind this is the advertising angle. What better way to advertise to consumers than seeing exactly what they're spending money on, historically and in near-realtime?
Zenst•39m ago
All set for a perfect storm with a single exploit down the line. Which could take out so much and OpenAI with it. What a way to burst the bubble, not an if, more a when as so many eggs in that basket and they have yet to invent a solid lid.

Reminds me of the underpant gnomes in many ways

Collect underpants ???AI??? Profit

JumpCrisscross•36m ago
> Which could take out so much and OpenAI with it

I guess I’m not seeing the systemic failure mode with a Plaid hook-up? The worst case is it sends a bunch of peoples’ money into the aether. That sucks for them and for OpenAI. But I’m not seeing it e.g. collapsing a bank.

warkdarrior•32m ago
A meme prompt with a prompt injection in it would easily reach millions of ChatGPT users.
simianwords•25m ago
can you give an example of how it can work?
cyanydeez•32m ago
just takes a single corrupt prompt and a class action lawsuit is easily primed.

But yeah, can't have a systemic failure in the grift economy.

dude250711•39m ago
The only better idea would be a Robinhood integration.
ReptileMan•34m ago
Polymarket.
frangonf•27m ago
And Sports Bets and casino integrations.
forinti•38m ago
People will pay for OpenAI to have access to their financial data??
mcphage•32m ago
I wonder if I could pay someone to run me over with a bus.
nonethewiser•26m ago
Sure. But it's going to be expensive. It actually costs me a lot of money to provide a "running you over with a bus" service.
rprenger•10m ago
Didn't Matt Levine tell a story about Masayoshi Son doing that? https://news.ycombinator.com/item?id=21427688
lacy_tinpot•11m ago
What do you think plaid is doing?

OpenAI is just a new-ish player.

andy_ppp•38m ago
It’s like we are trying to run as fast as possible towards an AI controlled disaster by connecting absolutely everything we can to the AI… even in the worst sci-fi the robots need to steal codes to get access to systems and we are just leaving the door wide open.
lenerdenator•30m ago
We're not trying to run as fast as possible towards anything. It's a bunch of investors trying to run as fast as possible towards the AI controlled disaster, or as they see it, an AI controlled unlocking of value.
micromacrofoot•24m ago
don't worry, we'll have plenty of human controlled disasters from this before we even get to agi
carlos-menezes•37m ago
I feel like every single day OpenAI and Anthropic are entrenching their slopware in everyday products and workplaces with little to no way to opt-out. This is getting dystopian.
frb•26m ago
Was thinking the same recently.

It feels like an arms race on who’s gonna become the Microsoft of the 90s, trying to own and provide everything.

I think it will play out in the same way

frb•36m ago
I’m generally positive towards AI and LLMs..

BUT there’s just things that nobody should be doing ever, like give it access to your production system or bank account.

cyanydeez•35m ago
People have been electing a clear grifter in multiple countries to do the same, so, you know, people gonna people.
carlos-menezes•34m ago
I feel like we're now at a point where that's a hot take.
rvz•28m ago
But LLMs are like humans!

Nothing wrong about with giving them access to your bank or savings accounts /s

binarymax•35m ago
I’ve been asked to sign up to plaid by clients three times. Each time I’ve said no. I’m not giving a 3rd party access to my bank account. I don’t understand how people enable this total loss of friction for direct account egress. There needs to be friction.
chao-•31m ago
Refinancing a loan I passed on the lowest possible rate I could get, for a slightly higher one, specifically because they used Plaid.

I'm not the most privacy-focused individual, not nearly as paranoid as I could be, but Plaid's model is an OBVIOUS step too far.

njovin•13m ago
Depending on the rate difference, I'd be tempted to setup a 'burner' checking account at a separate financial institution and just auto-transfer the loan amount from my primary bank to the burner every month.
lazide•7m ago
That generally wouldn’t pass underwriting. They want the account the money is coming from to be the account with history and money in it already.
josephscott•21m ago
One thousand times this. I am not giving away the keys to my bank accounts.
lxgr•6m ago
It’s worse than keys, it’s a persistent read-only view of all account data.

At least there is a process for unauthorized ACH debits. For this blatant breach of privacy, there is nothing.

hypeatei•21m ago
Have you ever entered your routing+account number into HR software for direct deposit? Doesn't that qualify as handing a third party essentially the same access as Plaid gets? I think bank accounts are generally more accessible in the modern era, it's just a risk that you take.

Of course, you're not obligated to use Plaid but I do find the concerns around this quite strange since you're likely exposing account information already.

liveoneggs•17m ago
plaid asks for your bank username and password not just your routing + account
whycombinetor•16m ago
Plaid wants you to enter your bank username-password into their form. If it was just routing+account it would be truly no different than other bank connection methods.
formerly_proven•10m ago
Plaid works a lot like PSD2-based services in the EU then, which also typically consist of a form hosted by the service using Times New Roman and the original padlock.gif from Netscape asking for your IBAN and online banking password and then a TAN/2FA number. Obviously there are no technical controls at that point to what the service can do in your account. I tend to avoid anything PSD2 for much the same reasons as Plaid, it's extremely sketchy. Somehow we can have scoped access using OAuth for random webservices but for a credit check it's "please just give us your online banking login despite everyone telling you since 1995 that you're not supposed to hand that to anyone and always double check the URL in the address bar to be yourbank.com... we assure you nl-gwlogin.xs2a.openbankingservices.co.net is an entirely legitimate place to enter your PIN"
redserk•15m ago
With plaid they get access to all of your account numbers.

HR just sees a single savings account that I strictly use for direct deposit. They don’t see my actual savings account or my other purpose-specific checking accounts.

hypeatei•7m ago
Sure, but GP mentioned direct account egress which is why I brought up the typical method for doing that. I figured banks are already selling / reporting the other information (account types, amounts, transactions, etc.)

As an aside, I think each permission has to be granted explicitly in Plaid so it's not just getting "root" access to do simple transactions (unless you grant it)

webo•12m ago
routing+account numbers are not that sensitive. that's been API for how we transact money since pre-historic times. plaid gets access to your online account with access personal data, security details, documents, transactions, statements, write-access etc.
buzer•8m ago
Whenever I have seen the Plaid integration it will also ask permission to your transactions. HR software won't get those when I provide it my account & routing numbers.
lazide•6m ago
Generally no. Plaid access generally includes whatever name you put on the account, as well as transaction history.
lxgr•6m ago
It’s roughly the difference between giving somebody your phone number and letting them eavesdrop on every single call.
gavinsyancey•4m ago
The same info is also on checks, and there's an established story around fraud there -- if I didn't authorize an ACH withdrawal then my bank is legally required to make me whole. If I hand over my username+password to a third party, I'm on my own.

Also, the routing+account numbers just let them deposit/withdraw money, not snoop on all my transactions and harvest my data...

webo•17m ago
Hijacking this comment to complain about fintech apps / saas providers requiring Plaid - please stop.

For example, Coinbase requires logging in with Plaid to... setup auto-pay for their credit card statements. No way to just provide account/routing numbers the good ole way.

There's lots of issues with Plaid but one big one is that banks (e.g big ones like BofA) can lock your account due to suspicious login with Plaid.

https://x.com/kanateven/status/1973793740331368841

measurablefunc•14m ago
They're a YC company so every other YC company is going to use them, that's how YC companies operate.
webo•11m ago
Plaid has an option to let the client/provider accept plain account + routing numbers, a lot of apps for whatever purpose don't use it.
lxgr•8m ago
They do because their banks are largely not offering anything more fine grained, because they don’t have to, and in fact doing so would cannibalize their debit card business.

Requesting full account access for anything other than maybe budgeting software should just not be legal.

superkuh•35m ago
While openai's use of Plaid's spying on bank accounts is framed as a service it's real use case will be identification. Very few people if any will sign up to use this voluntarily. But it is a way to get users used to Plaid's spying and start slowly boiling the frog.

The endgame I see is that it will be illegal to communicate on the internet without having a proven bank account. At least in the USA where all ID verification is settling on banks (ie, Plaid). And the banks will tolerate 10,000 false positive denials of service to avoid a single false negative and be happy about it. Plaid even more so. Human beings will have no recourse as they are private companies. This really should be a service that the states of the federal government provide. It's a dark future we're speeding towards.

ReptileMan•34m ago
Today's edition of "What could possibly go wrong" presents ...
drcode•32m ago
It seems like every three years or so I need to use a tool with a plaid link feature, I try it, it gives some internal plaid error, then I find some other way of solving the issue.
cbg0•30m ago
> OpenAI did this with your health data in January. Now it wants your financial data too.

This is far more valuable, they can see what political affiliation you have based on your campaign donations, predict things like cheating on your wife & the impending divorce, what vices you have and they can also build shadow profiles of all the people you give and receive money from even if they don't use the product.

fontain•25m ago
it is far more valuable to know the type of boring things boring people buy in their boring daily lives
gruez•25m ago
>they can see what political affiliation you have based on your campaign donations

You can get a pretty good estimate just by looking at other demographic factors like age, education level, income, and zip code. Moreover, how many people actually donate to campaigns?

>predict things like cheating on your wife & the impending divorce, what vices you have and they can also build shadow profiles of all of the people you give and receive money from even if they don't use the product.

Google has all this capability for at least a decade. What concrete harms have actually materialized?

kridsdale1•16m ago
OpenAI is now run by former Meta executives.
gruez•5m ago
Okay, what concrete harms has Meta done with this information? At best you have some creeps using it to stalk their exes, which is bad, but a far cry from the AI takeover scenario implied by OP.
rixed•24m ago
If all they wanted was to know more about your profile, they could already buy this information form the bank I presume.
arrosenberg•18m ago
Campaign donations are already public if you donate over $200 - https://www.opensecrets.org/donor-lookup
lxgr•3m ago
I’d be willing to bet that ChatGPT will know the average user’s political affiliation and vices about three messages in.

The difference is that banking records are harder to falsify, so there’s that.

drcode•27m ago
The comments here do seem to ignore that rocketmoney exists, and that many people use it
dfee•27m ago
What's the local version of this? What's the best way to pull in my finance data locally, without clicking through to each portal? (USA)
pesus•25m ago
Lovely! It's probably inevitable this will fuck over people eventually. Sam may as well prepare his next blog post ahead of time.
delis-thumbs-7e•23m ago
Why don’t you just ask for my blood? I can bottle it and send it over for Sama to drink for breakfast.

This exactly the same shit Zuck did with Facebook. Hell with them all.

cdrnsf•21m ago
Only if it helps me buy more stock in GameStop
rfrey•14m ago
Man, I remember when the common wisdom was that there would NEVER be enough people willing to put their credit card into a web browser to support a business.

I never expected to be nostalgic for those days.

xandrius•10m ago
To be fair most frequently people online use debit cards which can be frozen if something goes wrong.
lazide•3m ago
Uh, debit cards are the worse as they (technically) don’t allow you to dispute charges like in a credit card. Money comes right out of your account first, and then you have to try to get it back.

Don’t use debit cards online.

TheChaplain•11m ago
Stupid question, but what if you just open an account at a credit union, then have that one connected to plaid?

If it needs to see transactions, just have your salary deposited there, then an automatic transfer the same day to your real account?

bubblegumcrisis•5m ago
I'm not sure if Plaid still is- but when they first came out they were pretty evil. They would go into your accounts and download all activity. I spent many hours e-mailing them, trying to get a clear answer of what data they collect- and they never said no to anything.

Whenever I've been forced to use Plaid, I use a throw away "free-checking" bank account that has $1 in it.

I guess birds of a feather flock together.

Ask HN: Can I take Meta to court for banning business Insta or FB account?

1•milanspeaks•4m ago•1 comments

Linus Torvalds declares AI-fueled code surges as the new normal

https://www.neowin.net/news/linus-torvalds-declares-massive-ai-fueled-code-surges-as-the-new-norm...
1•ell1e•5m ago•0 comments

Goodgallery: WebGL sprite engine that can load 100k thumbnails in 1 second

https://ggdemo.s80.me/demo-100000/#fit
2•thunderbong•5m ago•0 comments

OpenAI's KOSA Endorsement Is Regulatory Capture with a Smiley Face

https://www.techdirt.com/2026/05/14/openais-kosa-endorsement-is-regulatory-capture-with-a-smiley-...
1•repelsteeltje•6m ago•0 comments

Elephants Still Don't Play Chess

https://whattotelltherobot.com/p/elephants-still-dont-play-chess
1•stefie10•6m ago•0 comments

EY retracts study after researchers discover AI hallucinations

https://www.ft.com/content/a61cbcae-95e4-4449-86e1-ef40fb306f4e
1•JumpCrisscross•6m ago•0 comments

Anatomy of a WooCommerce Skimmer: A Technical Deep-Dive

https://scotthelme.co.uk/anatomy-of-a-woocommerce-skimmer-a-technical-deep-dive/
1•speckx•8m ago•0 comments

Magnus the wandering walrus swaps Scotland for Norway

https://www.bbc.com/news/articles/cy82j0q383no
1•speckx•8m ago•0 comments

Long Live Qt for HarmonyOS

https://lists.qt-project.org/pipermail/development/2026-May/047126.html
1•molinwow•9m ago•1 comments

Trending on Amazon: Cancer books by synthetic authors

https://danielmay.co.uk/posts/cheap-agents-alumni-shirts-and-elias-thorne/
1•danielrmay•11m ago•1 comments

U.S. DOJ demands Apple and Google unmask over 100k users of car-tinkering app

https://macdailynews.com/2026/05/15/u-s-doj-demands-apple-and-google-unmask-over-100000-users-of-...
7•tencentshill•11m ago•0 comments

Rich Guy Quote Journalism

https://stringinamaze.net/p/rich-guy-quote-journalism
1•Tomte•12m ago•0 comments

Ask HN: Has Google Deprecated Inurl:?

2•kuba-orlik•12m ago•0 comments

From PDFs to AI-ready structured data: a deep dive (2024)

https://explosion.ai/blog/pdfs-nlp-structured-data
1•Tomte•12m ago•0 comments

Subumbra – Attempting to keep API keys safe – Alpha Release

https://github.com/polysemic/Subumbra
2•polysemic•14m ago•1 comments

Feedr v0.8.0 – a TUI RSS reader, now read the full article from your terminal

https://github.com/bahdotsh/feedr
2•bahdotshxx•17m ago•0 comments

Greg Brockman Officially Takes Control of OpenAI's Products in Latest Shakeup

https://www.wired.com/story/openai-reorg-greg-brockman-product/
2•ent101•17m ago•0 comments

Show HN: Check for CVE-2026-31431 (copy.fail) without overwriting su

https://github.com/bddap/supertee
1•bddap•18m ago•0 comments

Show HN: Burn, baby, burn (those tokens)

https://github.com/dtnewman/burn-baby-burn
3•dtnewman•19m ago•0 comments

Vanguard succeeded because it is owned by customers

https://www.wsj.com/finance/vanguard-costco-acquired-podcast-hosts-bogle-96d97c7d
1•marojejian•19m ago•1 comments

Mathlib Initiative: Roadmap

https://mathlib-initiative.org/roadmap/
1•tosh•21m ago•0 comments

Jank now has its own custom IR

https://jank-lang.org/blog/2026-05-08-optimization/
3•DASD•23m ago•0 comments

I designed a nibble-oriented CPU in Verilog to build a scientific calculator

https://github.com/gdevic/FPGA-Calculator
6•gdevic•24m ago•0 comments

Show HN: Find local farms near you with raw dairy, pasture eggs, and more

https://farm-to-door.com/
8•YoungGato•25m ago•1 comments

Peter Norvig Joins $4B Effort to Build Self-Improving AI at 'Recursive'

https://www.nytimes.com/2026/05/13/technology/recursive-superintelligence-funding-ai.html
4•alhazrod•26m ago•1 comments

Aperio Lang

https://aperio-lang.github.io/aperio/introduction.html
6•mmcclure•27m ago•0 comments

Anthropic Raising $30B More as AI Labs Absorb Majority of VC Funding

https://www.wsj.com/tech/ai/anthropic-raising-30-billion-more-as-ai-labs-absorb-majority-of-vc-fu...
2•JumpCrisscross•29m ago•0 comments

Hitchhiker's Guide to Logical Verification (2023 Edition)

https://lean-forward.github.io/hitchhikers-guide/2023/
2•tosh•29m ago•0 comments

Predictions for the Next 30 Years of Cybersecurity (2018)

https://utkusen.substack.com/p/predictions-for-the-next-30-years
1•utku1337•29m ago•0 comments

Nordstjernen Web Browser

https://github.com/nordstjernen-web/nordstjernen
8•roschdal•29m ago•9 comments