The win-win solution is to only buy Pixel phones that are several generations old. The kinks are ironed out, they're less than half the price, and for 95%+ of users, they're just as capable as the latest-and-greatest.
Phones are really rather secure. Even a 2 year past security patches android rarely has any of the most severe vulnerability (remote code execution with no action from the user).
The common security issues (app can get permissions it shouldn't have) are nowhere near as important if you don't download random APK's from dodgy sites.
Overall, my fully patched linux laptop has far bigger security holes than a 2-years-unpatched android.
You could use only the banking websites or switch banks. That's what I did personally since I want completely control over any device I use, and more importantly over my data.