It’s been a while since I looked at the technical details of Apple Pay, but my understanding (from what I remember) is that it generates a unique “card number” for each device.
So if there is fraud, there is no lasting damage as it is a virtual number - it can be cancelled without affecting the underlying account (ie no need to cancel cards etc).