⁠⁠The $900 million wire that wasn't final

⁠⁠The $900 million wire that wasn't final
Wires, chargebacks, and why payments are never really final

Patrick McKenzie (patio11) reads his 2022 Bits about Money essay "Finality does not exist in payments." It argues that how final a payment is depends on the rails, the parties, and the governing law, not on the payment method alone. He explains why the reversibility of credit cards is what made internet commerce possible. He also covers the "hold harmless," the brief phone call between operations staff that quietly unwinds wire mistakes every day. He then applies the essay to Citibank's 2020 accidental wire of nearly $900 million to Revlon's lenders: a district court let recipients keep about $500 million before an appeals court reversed it. He closes with how the UK, India, and Japan have each tried, with mixed results, to make fraudulent instant payments less final.

Presenting Sponsors: Mercury & Granola

Complex Systems is presented by Mercury—radically better banking for founders. Mercury Spend hands your team and agents their own cards with limits you set once, so nobody waits on you to approve a SaaS invoice and nobody chases a receipt. Apply online in minutes at https://mercury.com/.

If meetings consistently leave you with hazy action items and lost context, Granola handles the transcription so you can actually participate and gives you searchable notes afterward. Try it free at granola.ai/complexsystems with code COMPLEXSYSTEMS

Timestamps:

(00:00) Intro
(01:23) Finality is a technosociolegal construct
(03:26) Non-state agreements for dispute resolution
(07:34) Wait, are you telling me wires are reversible?
(12:43) Why does this matter?
(13:26) The $900M mistake
(14:52) Sponsors: Mercury | Granola
(18:11) The $900M mistake (cont'd)
(20:37) Final, then not final
(23:09) How other nations handle finality
(32:39) Wrap

Transcript

This transcript will be annotated in Patrick’s usual style by the end of this week — be sure to check back.

Welcome to Complex Systems, where we discuss the technical, organizational, and human factors underpinning why the world works the way it does.

Most people have an intuitive ranking of payment finality. Put a $20 burger on your credit card, and you know if something goes wrong that you can dispute it. But you send a wire and you think the money is just gone, because wires are final. That's what wires are for. In August 2020, Citibank accidentally wired nearly $900 million to a group of lenders. Some sent it back. Some said, "Wires are final, and we're keeping it." A federal judge agreed with them. Two years and one appeal later, they gave it all back.

I have a classic essay on this topic, and then I'd like to riff a little bit to apply it to the Citibank case, which I think a lot of people misunderstand a bit.

Finality does not exist in payments, originally published in Bits About Money on February 15th, 2022.

Children have a culture all of their own, and one sacred ritual of it, in some times and places, is "no takesies-backsies." Like much of the child law, it both rhymes and is enforced by social sanction dictated by custom immemorial. It means: transactions are absolutely final.

Many adults believe final transactions to exist. They mostly don't, and it is a good thing, too. That might sound surprising.

Finality is a technosociolegal construct

What does a transaction being "final" mean? In the layman's use of the term, it means that the transaction cannot be reversed.

As a payments professional, finality can be thought of more as a probability distribution given the technical/organizational infrastructure which was used to make a payment (the "rails"), the facts of the underlying transaction, the relationship of the parties, and the governing law(s) and regulatory regimes. We can confidently say things like "wire transfers are more final than credit card payments," but we generally don't say "wire transfers are final." If they were really final, the world would break.

An extreme example which proves the point: the cryptocurrency enthusiast community largely believes that code is law, "not your keys, not your coins," etc. Many crypto enthusiasts would say that the Bitcoin protocol does not prohibit reversing transactions but provides a security guarantee which suggests that the likelihood of a reversal after an hour is infinitesimal.

And yet: someone sent $70 million worth of Bitcoin in 2016, and that transaction was partially voided, with the reversal being worth slightly more than $70 million due to Bitcoin volatility. This didn't happen an hour later; it happened in 2022. How?

The answer is nowhere in the Bitcoin whitepaper or any codebase. A full recounting of it is outside the scope of this anecdote, but it rhymes with "If you and the United States federal government disagree whether a transaction is final, you are wrong." That is true for notorious Bitcoin thefts, but also true for wire transfers, conveyances of real estate, credit card payments, and graverobbing. "Possession is nine-tenths of the law," so the saying goes, but the state can conjure as many tenths as required if it is motivated to.

The overwhelming majority of transactions do not go to the state for adjudication. In fact, English lacks a non-mathematical phrase in common use to describe how much of an understatement that is. Billions of transactions happen every year; on the order of hundreds of thousands get explicitly adjudicated.

Non-state agreements for dispute resolution

If payment rails don't provide finality, what do they provide in its stead? Predictability. They publish rules (don't call them "laws") and operate dispute resolution processes (definitely not "courts") which provide for relatively efficient, relatively inexpensive, relatively fast decisions on transactions without needing to escalate past the payment rail to the state.

These rules have a property in common with formal law: they are not fully descriptive of the system that is envisioned by them. For example, in credit card disputes, almost all decisions which matter are made by an entry-level employee of the card issuer, and those decisions vary wildly across issuers even in circumstances which look very similar. As a simplified example, issuers who focus on "premium" card users frequently make a business decision to side with their customer more frequently than, say, mass-market banks do. (They would probably entirely automate "Chargeback sustained!" if the network rules allowed them to do so, but they don't.)

A side effect of formal rules is that they give soft security guarantees to an ecosystem, and those security guarantees allow people within an ecosystem to transact in something approaching mutual understanding of the degree of finality on offer. Additionally, they let ecosystems compete for users and for individual transactions specifically on the basis of different rules for finality.

Take wire transfers (please!). We largely don't think of Fedwire as being an agent in the same sense that American Express is an agent, but Fedwire factually does have a marketing department and, believe it or not, is in vicious competition with Amex for at least some transactions.

One important fact in the minds of both the buyer and seller is that Amex charges more as the transaction gets larger (and Fedwire, in relative terms, basically does not). But another is that Fedwire has a relatively strong presumption of finality, and American Express very explicitly does not.

Businesses who use American Express (and other credit card networks) to process payments often wonder why this is, particularly after they've been hit by a chargeback (industry jargon for "credit card payment reversal") for the first time. The big strategic reason, unchanged in the decades we've had credit cards, is that card networks are a trusted overlay on economies with heavily heterogeneous trust relationships.

Some credit card transactions are between a regular and the cafe they've gone to for 20 years, but some are between a business traveler and a hotel they'll never set foot in again, and credit cards guarantee to users that the risk of these transactions is similar. They increase social trust between peers on the network by decreasing technical trust. This is akin to alchemy.

Younger generations might not appreciate this, but there was a very real question in the late 1990s (and across much of the world today) whether transactions could ever take place over the Internet without being able to look counterparties in the eye. "Aren't hackers just going to take all money exposed to the Internet?" And lo and behold, they did not, but a necessary precondition for answering that question was there being money exposed to the Internet. Credit card guarantees of reversibility substantially made that happen.

(I would be remiss if I didn't give regulation some of the credit here. Again, the payment rails could say in their rules that transactions are final, but private industry is not the court of final appeal. This is, incredibly to me, still a live question for at least some financial institutions in the United States, who believe Zelle transfers are final because Zelle does not contemplate reversing transactions. Until the people with guns stop enforcing Regulation E, guidance to customer service representatives about finality is not actually controlling.)

And I'll say, as an aside: years later, the CFPB did sue the large banks in the United States because they had told their customer service representatives to tell customers untrue things about the scope of Regulation E. That suit was then dismissed after politically motivated shake-ups in the CFPB in 2025. But just saying, as an analyst and observer: it is still the case that Zelle is an electronic payment method, and it is still the case that Regulation E says what it says with regards to customer liability for misused electronic payment methods.

Wait, are you telling me wires are reversible?

Of course wires are reversible. They were not designed by children, but by professionals who live in a society which has systemically important institutions, and in the event of malfeasance or mistakes society does not tolerate a bank failing or a state missing payroll simply because someone said "no takesies-backsies" fast enough.

Mistakes happen! By, conservatively, the hundreds of thousands daily across all payments systems, millions depending on your definition of mistake. Wire transfers, like almost all payment systems, explicitly contemplate them and have a sociolegal ritual to quickly reverse them.

The ritual is called "hold harmless" and comes from a soft guarantee about the wire transfer ecosystem, which is that transactions are largely between sophisticated counterparties acting in good faith, intermediated by institutions whose probity is almost sacrosanct. Importantly, wires are in expectation worth having a human in the loop for; that is very not true of most payments.

A "hold harmless" is a very, very brief conversation between two peers at different institutions which is then memorialized on paper. The peers are generally operations professionals, one at the receiving institution and one at the sending financial institution (and sometimes even at its customer, since many serious users of financial infrastructure have operations teams to interact with their providers). The conversation is often shockingly informal, on the level of "Yeah, we goofed and sent you $1.2 billion to the wrong account. Mondays, am I right?", and the operations professionals make a verbal agreement about disposition of the transaction in minutes (or less).

The agreement is then solemnized in a brief document which gives "hold harmless" its name. The ops professionals are both taking a risk in voiding a transaction, and the party asking to void it (the sender) offers the party with the capability to void it (the receiver) a contractual indemnification should the state later come to the opinion that the ops professionals acted improperly. You can get a flavor for the language from NACHA's model letter for ACH transactions; hold harmlesses for wires look a tiny bit different.

How common are hold harmlesses? It took the combined forces of several agencies of the federal government more than five years to reverse ~$4.5 billion in Bitcoin transaction; that probably accounts for a few days' worth of hold harmlesses executed after breezy phone calls.

It is worth noting that this is substantially more complicated internationally. You can still absolutely reverse a wire between an arbitrary bank in Japan and the United States, in either direction, but the risk of unintentional finality goes up materially versus domestic wires, and while substantially all financial institutions in those two nations are de facto peers in a group of high-trust counterparties, that is decidedly not true of all financial institutions in all nations.

As an aside, how do you reverse a wire that is erroneously sent to Japan? Well, a funny anecdote for you. There happen to be two Japanese banks which have SWIFT codes — which is the thing that one uses for routing an international wire — that are one letter off of each other and approximately nine letters long. Once upon a time, a Japanese salaryman who happens to live in the United States instructed his American bank, "By the way, when you wire the tax payment, please wire it to the correct bank, because there are two Japanese banks that have SWIFT codes which are one letter apart from each other, and occasionally miswires get blown up by American bankers, so please be attentive here."

And it turned out that that payment did not arrive in the ordinary course. So the salaryman called his bank in Japan, asking, "Hmm, what happened to the money?" And the bank said, very apologetically, "Well, you know how American bankers are. Sometimes they happen to make this particular genre of mistake." And the salaryman said, "Well, you know how American bankers are, but you also know how Japanese salarymen are. I instructed them about that mistake before making this wire, and then thoroughly checked the wire confirm, and it says the appropriate thing on it." And the Japanese bank said, "Well, we'll wait another day to see if it arrives, but it really should have arrived by now. Could you please ask the Americans one more time?"

So the salaryman got on the phone to the American bank and said, "Hey, since you sent a wire message, it probably went over SWIFT. Do you happen to have the actual SWIFT message available, so that I could present it to the Japanese bank and have them follow up with their investigation?" And the bank gave the salaryman a copy of the SWIFT message, and the SWIFT message had the wrong thing written on it, despite the wire confirm having the right thing written on it — due to infelicities in having to manually retype between applications, perhaps.

So the salaryman sent his American bank a letter saying, "Well, it seems that I told you to wire money to this particular account in Japan, and in fact told you to pay double-plus attention to make sure that it was not sent to this other financial institution in Japan. And yet the bank's money seems to have somehow ended up there anyhow. But clearly my money is still at the bank, so send that to the bank that I told you to, please." And the bank said, "Well, we don't really agree with that theory of our operations here, but by total coincidence, money has arrived back from Japan today, so we will resend the wire." And they did so. Anyhow, a fun story about the joys of dealing with wires internationally.

Why does this matter?

Obviously, if you (or, more to the point, your business) interact with the financial system, it is important to correctly model the sort of finality guarantees you get on transactions.

For financial professionals, we likely haven't seen the final form of finality! There is still a rich design space there, and it appears underexplored over the last few decades. Some newer payment methods, including cryptocurrencies, are doing interesting tweaks (generally towards making payments substantially more final than credit cards), but you could imagine guarantees in the opposite direction working for some transactions among some groups of users. Another very interesting axis is whether finality guarantees should be much more explicit than they are currently, and whether one should be allowed to pay for different finality guarantees.

I have a fun example of this, but it will have to wait until a later issue. (Not even newsletters are final.)

The $900M mistake

So that's the essay. Now, a brief riff on the Revlon situation from back in 2020 through 2022. Much of this was originally reported/commented on by Matt Levine, but while he has funny and directionally accurate takes on it, I have my own takes — how to put this — reflected PTSD about looking at applications facing operations professionals that would allow someone to make a $900 million mistake very easily, and then have that mistake not get caught despite two other individuals taking an eyeball at the contemplated transaction. This isn't the most expensive software/user experience bug in history, but goodness, it has got to be up there.

So, the situation that approaches the world in 2020. Revlon is a cosmetics company. It has fallen upon hard times, and it has arrived at a situation where it owes a lot of money to various lenders, principal balance of approximately $900 million.

So, in somewhat better times, in 2016, Revlon had taken out a roughly $1.8 billion loan with Citibank as the administrative agent. And so we're going to be concentrating on the actions of Citibank employees for the next few minutes, because Citibank employees made a bit of a boo-boo with respect to an internal piece of software called Flexcube. 

To make a long story short, if you want to make an approximately $8 million interest payment via Flexcube, you have to enter that fact in more form fields than is obviously, sort of, naturally required. And if you don't hit all of those form fields, you will instead wire out the entire principal of the loan rather than simply an interest payment. And there will be a confirmation, but the confirmation won't exactly make it obvious that the entire principal of the loan is leaving the bank.

And so, on August 11th, 2020, while attempting to make about an $8 million interest payment, one employee at a business process outsourcing firm in India attempts to key in that interest payment for $8 million and queues up Citi to send out $900 million or so. And then a second employee at the BPO also makes substantially the same mistake in checking it. And then it gets sent over to a Citi approver who actually works in Delaware, and that person also approves it, and so out $900 million goes.

So this hits the accounts of various lenders, and the lenders are largely surprised to get it. There is internal chatter: "Was this a mistake? Did Citibank send us a notice that they were going to repay the Revlon thing early?" And bluntly, if you think about it for a few seconds, this kind of stinks to high heaven, because this debt is trading at like 20 to 30 cents on the dollar, and you don't expect to get 100 cents in full satisfaction out of the clear blue sky several years early — from, again, a party with extremely averse interests to yours, who you might be engaged in active litigation with.

So, Citibank realizes its mistake within a day and hits all of the lenders with a recall notice, saying, essentially, "Hey guys, we goofed. You're going to do the thing that the culture that is New York City strongly suggests you're going to do right now, right?" And some lenders return the money, about $400 million worth. But about ten managers, representing various funds and similar and high-net-worth individuals that were invested in this instrument, continue to hold about $500 million. And so who is out the $500 million? It is Citi. And Citi is pretty unhappy, for a variety of reasons. You know, $500 million operational mistakes are not exactly unknown in the financial industry, but they're pretty rare. Citi sues over this.

Final, then not final

It gets to the district court, and the district court says, "Well, there is this obscure thing in New York law called the discharge-for-value defense." The discharge-for-value defense is basically: in the case of an obvious error in a payment, we reverse the payment, no worries. But if the recipient of the payment has the legitimate belief that, no, the payment is something that is actually owed to them — in the way that a lender might assume that full repayment of a loan is actually owed — and they haven't received notice of the error at the point the payment is made, payment is good. And so the judge says, "Nope. In this case, industry standard practice does not control. New York law controls, and New York law says you can just keep the $500 million that you believe you were owed."

This causes an absolute firestorm in the financial industry in so many ways, and results in, boy, probably north of $500 million in legal spend, as so many contracts get rewritten to say: despite what New York law says, if there is an erroneous payment, you absolutely do not do the thing that New York law suggests that you have the default right to, but instead will hew to what was previously industry-standard practice — take the telephone call and return the money, you freaking idiots. Sign on the dotted line, please.

But it turns out that the non-final final payment is more final than was expected at the moment, because it goes to the Court of Appeals. And the Court of Appeals says, among other things — you can read the entire opinion at your leisure — one, they think that the district court judge erred in applying the discharge-for-value defense, and then two, it's just monstrously perverse and disruptive that this transaction would get allowed to stand; that despite being a wire transfer, this should have been non-final from the jump.

And I think that is very instructive, in the way that the technical reality of the wire and the social reality of the wire — that, you know, we have this culture in the industry of doing hold harmless, and this should have been nothing more than a single, not-very-stressful phone call between Citi and each lender — resulted in, you know, a multi-year, multi-court battle. And then the legal reality trumped the social reality, trumped the technical reality of the wire. And I find that to be just endlessly fascinating.

How other nations handle finality

But the international comparison here is also quite instructive. So, in the United States, we've mentioned that — subject to ongoing disputes, or, well, they're not ongoing at the moment, but give it a minute — subject to disputes between the regulators of United States banks and the banks with respect to Zelle, Zelle payments are broadly thought to be mostly final at the moment for one interesting class of payments. Zelle — man, I should write an essay about this at some point — is a blocking play. It basically exists to give the banks a way to say, "Don't just take all your day-to-day activity to Cash App or Venmo." And it is broadly underbaked as a solution in a lot of ways, but it offers substantially instantaneous payments.

There are two competing standards for doing substantially instantaneous payments between bank accounts in the United States, but Zelle is the one that has most of the adoption right now. One is FedNow, which the payments-wag joke for many, many years has been calling "Fed Later." And the other is RTP, which stands, cleverly, for Real-Time Payments. You can make real-time payments right now, but the supported institution set for both sending and receiving is very far from full coverage, and Zelle is much closer to full coverage. And so most people use Zelle.

The guarantees that different nations make with respect to whether consumers are at risk for their payments or not are very different from each other. So the UK, as a broad feature of bank accounts, allows you to do instantaneous payments between bank accounts at almost any pound amount. And this has caused a lot of what's called APP fraud — A-P-P fraud — and it largely affected the usual suspects: largely consumers who might not be very sophisticated, older savers in particular, who responded to SMS messages or phone calls from scammers, et cetera, et cetera.

So the UK said, "Okay, well, we're going to make the banks eat that one," in the same way that Regulation E in the United States makes banks largely financially responsible for certain forms of fraud committed against users, and then the banks in the US offload it elsewhere. And there is a sort of cap on the amount that the payment standards body in the UK makes the bank eat, but it's very generous: £85,000 or so, reduced, after pressure, from more than £400,000. And the first-year reimbursement was on the order of £173 million out of banks. So not a small amount of money; also probably not full coverage for frauds committed in the United Kingdom — but that's just my finger-to-the-wind guess, based on the size of the economy and typical fraud rates.

So the PSR made an independent evaluation and believes that APP fraud was down by about 21%, which translates to about £70 million of savings to consumers. And they thought, well, this is just that, after this guarantee makes it possible to reverse these transactions — even with the bank being ultimately responsible for it — it's just a less attractive fraud surface. And that sort of whack-a-mole is quite common. Fraudsters go to whatever rail makes it most possible for them to successfully extract the money.

India also historically had a similar problem with UPI, and India's solution was somewhat different. So rather than having the transaction be reversible and put it on the banks if there's no longer sufficient funds in the account to recover, in the case of a mule account… For those of you who don't know this lingo, mules are the individuals or companies that fraudsters, with active knowing coordination or otherwise, suborn to move money on their behalf. Frequently it is people responding to work-from-home scams. But equally frequently — well, I won't make a claim about percentages. Some mules absolutely know what they're doing is too good to be true: "You know, just receive money that is directed into your bank account and then forward it on to someone we nominate, and keep 10% for your trouble." And then some people are a bit more naive about how the world works. And both people who are quite sophisticated about how the world works and quite naive about how the world works are allowed to get bank accounts, and that is broadly a just decision made by society and will not be reversed anytime soon.

So, India. UPI exists: public-private partnership, wonderful, substantially instantaneous rail to make payments. UPI's fraud guarantee did not cover the case of a customer being induced to approve a payment on their cell phone or other device, even if they were induced fraudulently to make that payment. And this resulted in a politically unsustainable amount of fraud in India. And so it appears that the decision the RBI made was, "Okay, we will allow a one-time reversal of a payment made in this common fraud modality, where it is actually the user, with their own hands on their own device, making the fraudulent payment, but they've been induced to do so by lies being told by the fraudster, and so they shouldn't really be liable for it. So we will allow you to reverse that one time. In the case where we can't get it back from the fraudster's mule, rather than putting it to the bank, we will put it to a special fund stood up by the RBI/payment scheme. Once-in-a-lifetime opportunity. Please don't get defrauded frequently. We would like to avoid the sort of moral hazard of you assuming that we will always cover for your mistakes."

And then Japan decided to do this sort of differently. So although it is technically possible to reverse a furikomi — a bank-to-bank transfer in Japan — in practice, the reversal procedure, which is called kumimodoshi, if you want some trivia-night credit for Japanese payments professionals, is so rare that most people, even in the Japanese financial industry, don't understand that that is literally a thing you can do. And what it does is — similar to the case of hold harmless in the United States, but somewhat more regimented — the sender sends a request to the receiving institution: "Hey, will you allow us to recall that?" The receiving institution can't, at the level of the ops team, unilaterally recall the payment. They have to ask the account holder. And the account holder, in the case of them being a money mule, will typically say no or not respond to the request. And so this poorly understood way to reverse bank payments doesn't solve for the fraudulent use case, or even the mistaken use case, in Japan.

So the Japanese government said, "Well, typically elderly people are getting taken for just absurd amounts based on scams here. What can we do about it?" What they largely settled on was user education and suasion against the financial industry to do, let's say, harm-mitigation approaches. So: "We're going to ratchet down the maximum amount of payments you can send today without actually coming into the bank. We're going to have bank tellers visit old people when they come up to the ATM and say, 'So, what brings you up to the ATM today? Is it perhaps that you have received a telephone call? If so, let's talk a little bit before you push buttons on the ATM.'" Because, unlike ATMs in the United States, the ATM in Japan can wire out close to $10,000 without any bank staff ever being involved.

But the other thing they did was they made a sort of special legal procedure by which someone could file a complaint, and then the Japanese version of the Deposit Insurance Corporation could designate a mule's account as no longer being legally owned by the mule, and then the defrauded users could take pro rata shares of the amount of money that was left in the mule's account. The problem with this is that in Japan, since money movement is substantially instantaneous, and since getting cash out of the financial system is still not all that weird of a thing to do, very frequently the amount of money that was in the mule's account at the point of the legal process being sent against it was nearly zero. And so this largely didn't solve for the redress to defrauded users.

And so that's how various nations have differently approached this question of, okay, if the payment is final if we say it is, when should we say it is? And even in light of concerted government action to make certain payments less final than they are otherwise believed to be, the socio-technical-cultural substrate of those payments continues to make them final, even when the state says, "No, no, we think, normatively, that shouldn't be final."

And this is part of the ongoing cat-and-mouse game between, you know, the good guys — all of us, inclusive of the financial industry — and the bad guys and their ravenous attempt to get at various people's owned assets. 

And that is, unfortunately, a recurring theme for Complex Systems and Bits About Money. We've covered it in the past — I will put some links in the show notes — and we are quite likely to cover it in the future. But hopefully we'll have a happier topic to end on next week. See you then.