Oh wait... There are actually tons of such projects. Why did they not take off? (I'm trying hard not to sound cynical because I don't really know that there is absolutely no way that they could, but also I do feel cynical)
Secure computing requires a relatively low time preference to be economical. Or, more precisely, marginal demand for secure computing increases with a marginal decrease in time preference. Most companies have (artificially inflated) high time preferences, so it's not economical for them to adopt what we consider secure computing.
This is, I believe, to the net detriment of human society as a whole (at least, at my personal time preference).
I'm not going to get too much into why time preferences are so (artificially) high on here, but I encourage people to look into it themselves. A lot of it has to do with government economic intervention, especially around monetary policy.
Don't single it out. Fiscal policy is as much guilty as monetary one. Even civil and criminal legislation help here.
We are doing exactly that, in what concerns me, I switched away into managed languages back in 2006, already replaced a couple of C and C++ based solutions by .NET and Java ones. On my line of work C and C++ only have a place as means to writing bindings to OS libraries written in those languages. what can be replaced by secure languages, gets replaced.
In what concerns big companies, C is persona non-grata on Windows, Azure IoT makes use of .NET and Rust, Microsoft is a big pusher for C++ static analysers, drives Checked C research, did two safe OS whose learnings got added back to .NET (async/await, Span<>, .NET Native), UWP sandboxing is merged with Win32, with upcoming Windows 10X having everything sandboxed in little pico processes.
Google allows very little C and C++ code on its OSes, ChromeOS sandboxes everything, Android has probably the Linux kernel fork with most security knobs turned on, NDK has very little API surface, and Android 11 now requires hardware memory tagging for C and C++ code.
Even though I don't think it is going far, Google is working on eventually use Swift for Tensorflow further developments. It remains to be seen how much C++ are they willing to replace by Swift.
Apple is now since one year driving drivers outside the kernel, with the exception of DriverKit, everything else can make use of Swift as well. Very few modern macOS APIs are C or Objective-C based. Since iPhone X, iOS makes use of hardware pointer validation.
Apple is also hiring Rust developers to replace C based infrastrutured on their backend.
GenodeOS is written in C++, and has since one year started to migrate security critical parts to Ada/SPARK.
Speaking of which, NVidia, a C++ powerhouse, is now using Ada/SPARK for security critical firmware.
We, security conscious people will get there, slowly, might not be on our lifetimes, but society will be there eventually.
Then again, progress only happens one person at a time.
There are lots and lots of software that is both well designed and popular. SQLite is a great example. Postfix and OpenSSH too.
The meta tables declaring all table structures are changeable via SELECT and CREATE VIEW statements, the fulltext search engine still allows follows arbitrary user pointers by default. Well-designed is different.
The problem is not the language, the problem is in the design.
In my experience secure computing is a lot more inconvenient. I don't mean Haskell is inconvenient (it is). I mean like, it's way more inconvenient to write in C# or Java than it is to write in plain C if you want to get real work done.
Speaking of history,
> if a builder build a house for some one, and does not construct it properly, and the house which he built fall in and kill its owner, then that builder shall be put to death.
-- Code of Hammurabi, Babylon.
Naturally, we shouldn't go to such extremes.