I think you misunderstood what I meant what I said it's simple to create an insecure REST api.
I also disagree with your entire premise. What do you mean by GraphQL is more complicated? And how does that lead to insecurities? What exactly what the insecurities it leads to?
GraphQL comes with one of the biggest security measures build-in, it strictly checks your inputs and outputs.