Alice can send anything in any cryptographic scheme involving two parties, the only real safety in any of it is "are the odds of an accepted different value low enough to be impractical for an attacker". Does that apply here too?
Imagine such a bank. Or social media (impersonate anyone, just say you’re them on the request why not), or any website.
The “zero knowledge” part of the name checks out.
Also nice sock puppet.