I'm not the GP, and I'm not a nefarious actor for whom the strategy has been tested, but this is similar to my personal approach:
PayPal, Venmo, Stripe, etc -- any service provider that I choose to share bank account (or debit card) numbers with -- gets the information for a small holding account only.
I maintain the balance in that holding account around the level where I'd be "irritated but not affected" if something were to go wrong.
Honestly I just don't trust them to correctly and quickly fix any errors or exposures. So I prefer to avoid the issue altogether.