1. Blockchain smart contracts are often unchangeable, so you can't fix bugs
2. The language is being built as people write code, with some bad design choices that encourage mistakes (slowly being fixed)
3. Libraries are still being developed
4. Tooling is still limited (even basic linting)
5. People are not taking the time to have a beta process.
6. People prematurely optimize gas, at the cost of readability
(For non-Ethereum devs, here's a short tutorial for how the language works: https://learnxinyminutes.com/docs/solidity/ )
My own view is that you have to code expecting that things go wrong, and ensure that your logic survives inevitable mistakes ('resiliency').
There's a lot of great resources on security, for people interested in this space:
Ethereum Safety: https://github.com/ethereum/wiki/wiki/Safety
Decentralized Application Security Project: https://dasp.co/
Consensys Smart Contract Best Practice Guide (I helped coauthor this back in 2016 after the DAO): https://consensys.github.io/smart-contract-best-practices/
Hacking Distributed is a great blog for blockchain security:
http://hackingdistributed.com/
Emin and Phil Daian are great to follow on Twitter:
https://twitter.com/el33th4xor
Audit Checklist (written by my team): https://github.com/cryptofinlabs/audit-checklist
(Disclosure: Our team does audits for a few projects: http://audit.cryptofin.io/index.html )
Feel free to add other resources to this thread. Imagine it'll be useful for everyone.