Yes, and they can't do that since the blockchain is public and can be verified by anyone with a node.
Lightning may be a different story but even there, the channels should be verifiable.
So if you go to a bank and don't check that they actually have your funds somewhere on the blockchain, that's on you. For example, you can ask them to sign a message. Also, you should use a 2of2 multisig. Else, they can just tell multiple people about the same funds.