I still think this is fundamentally Facebook’s problem.
For example, I don’t care if it’s a failure of the payments ecosystem or my bank if using a new payment technonlogy opens me up to fraud that then drains my bank account- I just won’t use that new technology anymore. Similarly I don’t care who’s fault it is if using Facebook leaks information about me I didn’t realize and didn’t want to become used in the ways it has been. I will just not use Facebook anymore.