The debit card linked to the customer's account can be used in customer's own monzo.me link - Transfering from me to me :)

Issue:

I was able to use my personal Monzo card within the Request Money feature. However, I’m unsure if there are any validations in place to prevent cards linked to the account from being used for payments. While this is an ON-US transaction, restricting such usage could help conserve certain system resources.

Details to reproduce:

Generate a ‘Request Money’ link

Enter customer’s own debit card

Authorise the transaction in App

OS: Android 16
Device: Pixel 8 Pro
App Version: 6.46.0

What do you mean?

Someone steals your debit card details and pays using someone else’s monzo.me link?

That’s a pretty daft fraud move, as Monzo will just freeze/close the receivers account.

Therefore unlikely to happen.

I create a monzo.me link and I am able to use my own debit card to make a transaction which is like transferring within same account. There is no business scenario where we would need this. Though scope for fraudulent activities is limited, I believe there should be validation to prevent self transfers

You’re just making an online transaction, the card processor doesn’t know this (which monzo doesn’t handle, Mastercard does).

It’s unclear what your issue is?

Paying someone else’s monzo link may be easier for some with monzo as a saved card on their browser, why would they want to remove this simple option? Not everyone banks or makes payments on their mobile device.