If I had to guess, one thing that makes services like Dwolla less risky than traditional credit cards is that credit card security is built around end users keeping secret a string of numbers written on a plastic card that they hand out to random strangers on a regular basis. As a secondary fraud-prevention measure, merchants may ask you to sign a receipt that may or may not match the one on the back of your card.
To be fair, there are a number of fraud detection algorithms at play as well, but those algorithms often have wholes in them or come into play only after the fraud has occurred.
As an online service, Dwolla requires users to authenticate directly with them, where they can take steps to mitigate fraud by requiring two-factor authentication, etc. Authentication with merchants is handled via a token-based method. In addition, fraud detection may also be substantially easier because Dwolla is privacy to additional information about its users (IP address, purchase details, cookie tracking, etc.) that may not be available to traditional credit card providers. Dwolla may also be privy to additional information that allows them to assess the credit-worthiness of their customers and minimize the danger of default.
This probably doesn't totally explain how Dwolla dropped the cost of fraud detection down to a flat 25 cents (e.g. it doesn't explain why PayPal charges a percentage-based fee), but I bet it's part of the story.