Your Digital Wallet Is a Ticking Time Bomb
- By Winston Thomas
- September 24, 2025

Your grandmother shops online now. Your CFO nearly lost USD600,000 to a deepfake Zoom call. Your digital wallet connects to your Apple Watch, your crypto exchange, and that sketchy food delivery app you downloaded last week. Welcome to the wild west of digital identity, where millions of dollars change hands daily and fraudsters are getting smarter faster than security teams can keep up.
“Digital wallet adoption is really rising nowadays. Millions of dollars have been transacted via digital wallet,” says Jasie Fon, regional vice president for Asia at Ping Identity. “When you talk about a wallet, it means money. So when it comes to money…there's a huge increase in fraud.”
The numbers are large: three in four Singaporeans can't identify a deepfake, while finance directors in Hong Kong wire millions to scammers impersonating executives. The tools that were supposed to make financial lives seamless are becoming weapons against us.
The hidden ecosystem of vulnerabilities
Most people think they have one wallet when they actually have three to five different types scattered across devices. Your Apple Pay isn't your crypto wallet, nor is it your bank's mobile app. And each represents a different attack vector for security teams trying to protect what they can't properly inventory.
Part of the problem is that companies are rushing to deploy digital wallet solutions to capture market share, treating security as an afterthought. The result? A fragmented ecosystem where your morning coffee purchase could theoretically open a pathway to your retirement savings.
“Whether it is secure or not, a lot depends also on the issuer and the verifier,” Fon explains. “Consumers range from different ages. And it is the company's responsibility to ensure that you don't [onboard them] just for the sake of gaining customers.”
But consumer vulnerabilities are only just the beginning. While everyone obsesses over individual fraud, enterprise teams face supply chain threats. Digital wallets connect to payment processors, merchant systems, authentication services, and vendors that most organizations barely monitor.
“One of the biggest issues we see is the weak link and the vulnerability on the third-party supply chain, where they have access to your system and they don't have the right credentials,” Fon notes.
The logic is simple: Why hack a bank when you can hack the payment processor serving a hundred banks? The interconnected nature means a breach at one minor vendor can cascade across thousands of businesses and millions of consumers.
The AI arms race
If traditional fraud is like picking locks, deepfake fraud is like having a master key. Recent incidents in the Asia Pacific show AI-generated impersonations targeting C-suite executives who should know better.
“A Singapore director almost lost SGD670,000 through a deep fake Zoom video by the CFO,” Fon recounts. “And the good news was that the bank managed to stop it in time, and the money wasn't lost. But it made it to the news.”
When AI-generated video calls can fool executives, how can organizations trust any digital interaction? Modern fraud detection relies on pattern recognition, but criminals often mimic legitimate behavior more effectively. It has led to the classic “impossible travel” scenario, where identities appear in multiple countries within minutes.
“For example, I'm logging in and doing my online shopping at this moment. And then the next thing is, within five minutes, I'm in India, and then within five minutes I'm back home in Singapore doing a transaction,” Fon illustrates. “And this is where you feel that AI can come in and [help you verify].”
However, using AI to combat AI fraud is only part of the solution and won’t reduce the number of attacks. After all, both sides are deploying AI, escalating the cat-and-mouse game. In addition, buy-now-pay-later services add an additional layer of complexity by introducing credit decisions with limited identity verification, while machine-to-machine transactions open a new can of worms.
Finding the balance
The answer is philosophical. How do you balance security with usability without creating friction that drives customers away?
“You need to balance user experience with security. You cannot compromise security, but you also cannot compromise user experience, especially when it comes to shopping. If it's too difficult, they don't want to shop."
Industry insiders point to decentralized identity (DID) systems — like the one championed by Ping Identity — which give users control over their credentials. Instead of centralized databases that attract hackers, decentralized systems distribute information across secure containers.
Imagine proving your age without revealing your birth date, or confirming your address without exposing complete personal details. But implementation requires coordination across stakeholders and significant infrastructure changes.
For the moment, the digital wallet revolution shows no sign of slowing down, and security challenges are growing more complex every day. This means that organizations need to treat identity verification as a core business function, not an IT afterthought — today. Winners will master the delicate balance between convenience and security. Losers will prioritize growth over security until one major breach destroys years of investment.
As Fon puts it: “You just need to have one fraud to destroy all the goodwill and all the investment that you thought that you put in.” In the digital wallet era, that's a risk no organization can easily survive.
Image credit: iStockphoto/Pla2na
Winston Thomas
Winston Thomas is the editor-in-chief of CDOTrends. He likes to piece together the weird and wondering tech puzzle for readers and identify groundbreaking business models led by tech while waiting for the singularity.