exactly.
for security, what they should do is make it like what they do with your google login. every time you use your card, it should sent an email or text. so if someone hacks it, you'll know right away. they can layer on the same algorithms that credit cards already use to track aberrant behavior.
and it already creates a virtual credit card number. as far as i know, practically no personal information is stored. it's not like a hacker would have access to your bank accounts. just your credit card. and, to be even more secure, for big purchases can't they throw on a 2-factor authentication, like a pin code or something, that wouldn't be stored on your phone?
i'm more worried about someone hacking into my google account
and looking at my search history than i am about my android pay, but i don't see google disallowing us from checking gmail on a rooted/unlocked phone.
what it is, i would guess, is that the banks and google don't give a **** about the threat to our individual bank accounts. they care about a large breach where they would have to deal with thousands of accounts at once and the negative publicity.
iphone 2017