Wero is basically an EU-wide version of the Dutch iDeal system, which in my opinion is the gold standard of how internet payment should work. I shouldn't have to fill in any card numbers on the site of the merchant (which is unsafe). Instead, the payment should redirect me to my bank, where I authorize the payment through my own bank's security system. I've always been annoyed by the need to type in sensitive card in…
The redirect to a bank is worrying, isn’t it trivial to fake redirecting to a fake bank ?
Worst case, you'll be entering a one-time code received out of band, e.g. via SMS, and that message will mention what you are consenting to by entering it anywhere, so even MITM attacks are very hard.
The days of entering a static password in 3DS are long gone.