Phones are really rather secure. Even a 2 year past security patches android rarely has any of the most severe vulnerability (remote code execution with no action from the user).
The common security issues (app can get permissions it shouldn't have) are nowhere near as important if you don't download random APK's from dodgy sites.
Overall, my fully patched linux laptop has far bigger security holes than a 2-years-unpatched android.
You could use only the banking websites or switch banks. That's what I did personally since I want completely control over any device I use, and more importantly over my data.
According to https://support.google.com/pixelphone/answer/4457705?hl=en pixel 5a is getting eol this month, with the next security update dropping for pixel 6 starting in October 2026
"Last gen" pixel 8 is going to get android and security updates through October 2030