I don’t think you understand. The arbitrage bots aren’t exploiting poorly written contracts, they are capturing free value that users of a dApp have opened up. This free value is available to miners as well, and could be used to subsidize an otherwise-unprofitable double spend attack.
But more to the point: allowing smart contracts in a blockchain introduces all of the complexity of trying to make any other piece of software secure. Except... now it’s on a blockchain where the code is open source and mistakes can allow adversaries to steal money, not just data. How is this an improvement?