Enrollment is by token, and the token is the weak joint. A user registers an email address or a US mobile number with their bank, and that token becomes the address other people send to. What the sender sees before confirming is generally a display name associated with the token rather than a verified legal name from the receiving bank's records, so a recipient's display name is a claim rather than a credential. The New York complaint's illustration is an account presenting itself as a utility company's billing department. The practical countermeasure is to treat the name on the confirmation screen as unverified and to confirm a new recipient by some channel you already trusted.
Speed and irrevocability are the same fact. Because the transfer settles between banks rather than inside an app, there is no intermediate stage at which the money is sitting somewhere recoverable, and once the recipient's bank has credited them the sending bank has no unilateral route to take it back. The New York Attorney General's complaint puts the consequence directly: the platform's "emphasis on immediate and irreversible transfers means that by the time consumers realize they have been targeted by fraudsters, their money is often already gone." Sending to a token that is not yet enrolled anywhere behaves differently, because there is no account to credit, so the payment waits for the recipient to enroll. The network's own published guidance states the consequence both ways: a payment can be cancelled where the recipient has not yet enrolled, and once they have enrolled the money is sent directly to their bank account and cannot be cancelled.
The legal line that decides who bears a loss is about who pressed the button. A transfer a fraudster initiates from your account, including after tricking you into handing over a login or a texted code, is an unauthorized transfer, and the federal electronic-transfer rules give you strong rights against your own bank. A payment you sent yourself, however you were persuaded to send it, is not unauthorized under those rules, and the protection does not reach it. That rule and its exceptions come from the electronic-transfer regulation and apply the same way to every rail, so they are not restated here. What belongs on this page is why the line bites harder on this network than on most: the design maximizes the speed of exactly the payments that fall on the unprotected side of it.
The regulatory and litigation record, stated with dates because it is still moving. On 20 December 2024 the Consumer Financial Protection Bureau sued Early Warning Services, Bank of America, JPMorgan Chase and Wells Fargo in the US District Court for the District of Arizona, alleging unfair acts or practices under the Consumer Financial Protection Act and, against the banks, violations of the Electronic Fund Transfer Act and Regulation E. The Bureau voluntarily dismissed that action with prejudice on 4 March 2025 and the court dismissed it the following day, so it cannot be refiled.
On 13 August 2025 the New York Attorney General sued Early Warning Services in New York, alleging that it designed Zelle without adequate safety features and that users lost more than $1 billion to fraud on the platform between 2017 and 2023, and seeking restitution for affected New Yorkers along with a court order requiring anti-fraud measures. In July 2026 the court denied nearly all of the company's motion to dismiss, allowing the claims to proceed, and the company said it disputes the allegations and intends to appeal. Nothing in that record is a finding that the allegations are true, and none of it changes what a user is entitled to today. It is recorded here because the design questions it raises are the ones a user has to answer for themselves in the meantime.