What? Of course it’s a massive security flaw if you let any end user device send anything they want and just go “well they probably won’t send fake amounts”
Imagine such a bank. Or social media (impersonate anyone, just say you’re them on the request why not), or any website.