App PIN Security

What am I missing with Monzo security:

  1. I have face authentication & app lock pin switched on.
  2. Someone knows my iPhone pin
  3. They get my phone, open Monzo app and face isn’t recognised, so they use the iPhone pin to open Monzo.
  4. From here they can create a payment link using phone pin and empty my account.

Surely this can not be right. I changed my iPhone pin thinking it was a mistake, but it’s not.

Someone with access to your iPhone pin has full access to empty my account.

I’ve just tested it twice and I can log into the app using my iPhone pin. From here I can create a payment link by hiding my face, Monzo app fails to authenticate me and asks for a pin. Put in iPhone pin and link is created.

Please try this and tell me what I’m doing wrong

Are both your pins the same?