The app is an interface
PhonePe, Google Pay, BHIM and bank apps initiate payments. They do not normally hold the linked bank balance.
Interactive field guide · August 2026
This guide traces one ₹500 payment, then examines identity, fraud, market concentration, public subsidy and the projects India should fund next.
01 · UPI in one minute
It captures your intent. Banks hold the accounts. NPCI routes the request. Several systems have to agree before the merchant sees “paid.”
The app sends your payment instruction. Your UPI PIN or approved on-device method authorizes the request.
A deceptive QR, collect request or social-engineering prompt can make a genuine user authorize the wrong transaction.
PhonePe, Google Pay, BHIM and bank apps initiate payments. They do not normally hold the linked bank balance.
It operates the common rail and rules. The payer and beneficiary banks still have to respond correctly.
The failing layer may be an app, bank, telecom connection, risk engine or the shared network.
A UPI transfer crosses the customer interface, payment service provider, remitter bank, central routing layer and beneficiary bank. Common network rules let systems owned by different institutions work together, while each institution remains responsible for its part.
A technical decline may start at a bank or the central network. The account balance, a transaction limit or a risk rule may cause a separate business decline. Reversals and disputes begin after the immediate result shown to the customer.
02 · UPI at current scale
At this volume, outages, weak fraud controls and funding decisions affect millions of people.
| Financial year | Volume in crore |
|---|---|
| 2021–22 | 4,595.61 |
| 2022–23 | 8,371.44 |
| 2023–24 | 13,112.95 |
| 2024–25 | 18,586.60 |
| 2025–26 | 24,161.69 |
Source: Ministry of Finance, July 2026. Values are financial-year totals.
Calculated from NPCI payer-app volume for August 2025. Concentration can change; this is a dated snapshot.
03 · Aadhaar's role in UPI
KYC, PIN reset, on-device biometrics and AePS use different systems and controls. Grouping them all under “Aadhaar-linked UPI” hides those differences.
Banks may use Aadhaar for voluntary KYC; Aadhaar is required for receiving benefits under notified schemes. UIDAI does not approve each UPI payment.
Fast, paperless onboarding and easier access to benefit-linked accounts.
Offer equivalent non-Aadhaar KYC and store masked or tokenized identifiers.
What the breach record shows
UIDAI reports no breach of the Central Identities Data Repository. Documented exposures of Aadhaar numbers and related personal data have come from other government and institutional systems.
Knowing an Aadhaar number alone should not authorize a withdrawal. The risk comes from combining leaked attributes with weaknesses elsewhere.
UIDAI states that its central repository and core biometrics have not been breached. That claim covers CIDR, not Aadhaar data copied into other databases.
In 2024, MeitY blocked websites exposing Aadhaar and PAN details. Earlier disclosures involved institutional or beneficiary datasets rather than a demonstrated extraction from CIDR.
CERT-In acknowledged samples claiming to originate from ICMR. Reporting described verified sample records and arrests, but this was not evidence that UIDAI’s central repository was penetrated.
04 · Where fraud and failure happen
The main risks involve payment prompts, account recovery, devices, telecom providers, banks, agents and mule accounts.
A real user is manipulated into authorizing the wrong transaction.
Funds move rapidly through recruited or compromised accounts.
Attackers target identity recovery instead of payment encryption.
A bank or network dependency times out or rejects the request.
Failure or policy changes at a dominant app affect a large user base.
Responsibility is split across the app, two banks and the network.
This matrix is my qualitative assessment, not an official loss-frequency model. The placement compares potential impact with ease of exploitation.
Approval screens should bind the amount and payee to the user’s action. Strong identity proof cannot rescue an ambiguous payment prompt.
PIN reset and device rebinding should trigger cooling-off periods, lower limits and multi-channel alerts.
Users should not have to diagnose which institution’s seeding, onboarding, agent or risk control failed.
05 · The price of free
Every payment consumes switching, core banking, authentication, fraud monitoring, settlement, support, dispute resolution and regulatory capacity.
Public incentive schemes and broader digital public infrastructure.
Central rail, standards, switching, settlement coordination and resilience.
Core systems, APIs, authentication, AML, fraud controls, reversals and support.
Consumer software, support, acquisition, redundancy and fraud tooling.
Devices, reconciliation, operations, fraud exposure and downtime.
No normal explicit fee, but indirect exposure to fraud, failure and lost time.
The public figures disclose subsidies, not UPI’s total economic cost. Banks and apps do not publish unit costs, so outsiders cannot calculate a reliable cost per transaction.
Keep P2P and low-value small-merchant payments free. Charge a small, capped amount for higher-value commerce, premium services and cross-border payments. Banks and payment providers should contribute more when their scale or risk increases operating costs.
06 · My 2030 priorities
The projects below address poor connectivity, reusable credentials, international connections and the digital rupee.
UPI Lite and proximity modes can reduce load on core banking systems and make low-value payments more tolerant of uneven connectivity.
Faster small payments and better access in low-connectivity settings.
Who carries loss when devices are offline, duplicated or compromised?
Retain PIN and assisted options for people who cannot use a newer identity method.
Show cost bands, incentive flows and the performance expected in return.
Users should be able to switch apps without losing service or access to their transaction records.
Payers should see compliance and foreign-exchange costs before approving a payment.
The argument in one sentence
Hundreds of millions of people depend on UPI and Aadhaar. NPCI and participating institutions should publish operating costs, fallback procedures, service levels and liability rules.
Sources & method
I used primary material from NPCI, RBI, UIDAI, the Ministry of Finance, CAG and BIS wherever available. Dated snapshots are labelled. The recommendations are mine.
Known gaps: Public sources do not disclose a complete per-transaction cost, app-level fraud rate, or adoption and false-rejection data for the new Aadhaar face-authentication flow. The risk matrix and funding recommendation are analytical, not official.
Currency: Facts checked through 21 August 2026. The app-concentration chart uses August 2025, the latest detailed NPCI snapshot used in this analysis.