To open this comment: I used to own application security at an international bank. I was responsible for technical penetration testing across the organization, including code responsible for deposits, withdrawals, C2C transfers (customer to customer), wire transfers and ACH transfers (as well as the multifarious authentication mechanisms and APIs interacting with external verification systems). I was also closely involved in incident response on more than one occasion, though that was not my particular team.
With that background in mind, I'm going to have to strongly disagree with your point on two grounds. First - yes, SWIFT was successfully attacked, and $800M is an egregious amount. But while security vulnerabilities can exist in essentially any type of software, it is significantly more difficult to get away with defrauding a banking institution out of seven digits or more. There is virtually no way to identify a single vulnerability and then exploit it to rapidly siphon funds out of the institution. If nothing else, the intermingling of various transfer protocols and identity constraints tends to make that very difficult.
When I was in that role, we were very frequently targeted. The only way attackers were ever able to successfully steal money from the bank was by first achieving identity theft or by compromising existing accounts. Here there is still an economic caveat - to achieve successful attacks against banks on the scale of what is currently rampant in Ethereum smart contracts, you generally need to reliably achieve a certain scale. The attackers tend to be groups acting in concert, and will actively look for institutions where a critical mass of accounts can have funds siphoned out of them.
In practice, this most often occurs when there is either 1) a truly egregious security flaw in the specific institution or 2) a major security breach that facilitates password cracking en masse against users who have accounts at the bank and use the same passwords. A good example of #1 would be an online bank that allows users to bypass the identity/address verification step in the account opening process (i.e. there may be a vulnerability that allows them to assign themselves a social security number without verification, skip parts of the verification process or change it later on). I was very good at making sure we never had such a serious issue.
That leaves #2, and it's the way that we were almost always attacked in practice. Password breaches would occur, we'd get a rash of accounts compromised, and those accounts would attempt transfers out of the system. Sometimes it was more complex (two types of compromised accounts involving C2C transfers, etc). We mitigated these through sophisticated rate limiting, aggressive logging and a lot of incident response. Sometimes it happened often enough to essentially become a dull background noise for us. But in my ~2 year tenure, the most I ever recall us losing in any single attack was about $15,000 (across hundreds of accounts), and I can count on one hand how often that happened.
So that's my first point, regarding inherently superior (or more charitably, "mature") security mechanisms. My second point is that a bank and a smart contract or an ICO aren't really analogous. They are both in the financial domain, but they have different risk profiles and functions. A smart contract would be more analogous to a regular contract, and while I am very willing to concede that smart contracts have theoretical benefits, it is very clear at the moment that the lack of a legal fallback (for now) is a weakness, even if it's also a strength. A smart contract and a contract are both generalizable, whereas a bank would more akin to a specific, constrained type of legal contract that houses money in exchange for certain privileges. Smart contracts are inherently more vulnerable than banks because they can be much more open ended in purpose and execution, without the corresponding legal oversight that regular contracts have.
An ICO is also not analogous to a bank; as the name implies, it's much more similar to an IPO. IPOs absolutely do not share the risk profile of ICOs, and there would be significant legal penalties if an IPO were manipulated in such a fashion as to cost investors tens of millions of dollars that simply evaporated due to fraud. No one would take the underwriting bank or the founding team seriously if they said, "well hey it's not a significant amount of money that was lost compared to our market capitalization." NB: I'm not talking about an overvalued IPO dipping in share price, I'm talking about a significant amount of the invested money literally being stolen from both the company and the investors with apparently no way to make either of them whole. The idea of this happening is conceptually beyond the pale for me.
Instead of a smart contract or ICO, a banking institution is more like a wallet or an exchange. And this brings us full circle to Mt. Gox, which actually was liable, much like a bank would be. In return for legitimacy and expanded utility, companies like Coinbase have had to accept an increasing amount of legal oversight and liability over the years.