The bank would be responsible for getting the user their money back under US law, actually - even if it was the user’s fault due to bad security

Victims can spend hundreds of hours over the course of years navigating corporate and legal bureaucracies before their account balances and credit scores are restored. The system absolutely makes a bank error the victim’s problem to solve. Guilty until proven innocent.