Both of these are astronomically high in the case of Bitcoin and Ethereum, and it's been some time since any breaking bugs have been found, so the odds of any remaining exploitable bugs must be pretty low.
A new bug could be introduced, obviously, but I think the review period for new changes reduces the odds of that too.
https://www.coindesk.com/markets/2018/09/21/the-latest-bitco...
If the project zero team or Tavis by himself dedicated time to reviewing bitcoin it would fall apart like any other software.
Security researchers don't work for free. I did some light searching and I couldn't find any sanctioned audits against Bitcoin core. The Bitcoin team should hire someone like trail of bits to do a multiple month audit.
The ideal ecconomic outcome would be something small enough you don't get noticed. Whose to say that isn't already happening? By definition you wouldn't be able to tell.
This is why the idea of "smart contracts" seems so crazy to me. As many flaws as there are in human-based contract systems, the fact that contracts aren't an incontrovertible source of truth isn't one of them. This isn't even the classic mistake of trying to solve a social problem with a technical solution; this is creating an entirely _new_ social problem that doesn't exist with a technical "solution" to one that doesn't fix any issues that do already exist.
A slightly smarter one would be "I unequivocally agree to give you this much of my bitcoin on 1/1/2030"
> human-based contract systems don't suffer from needing to think of every possible edge case up front
This isn't always a good thing. As smart contracts are in a form enforceable by computation, they could be put through a series of automated checks to help ensure all edge cases have been considered.