Well when you consider that a traditional bank has teams of security experts, spend millions of dollars on security infrastructure and STILL have the occasional lapse in security; how do you think a couple of guys in their spare time will fare?
A bank's software infrastructure and "attack surface" dwarfs these tiny bit coin exchanges. Banks also have byzantine processes and guidelines that encumber their technical teams so building their software is inherently costly regardless of security.
Meanwhile unregulated, nimble BitCoin exchanges struggle with the OWASP top 10.
I'm not quite sure I buy that. Obviously banks are more complicated. But because of the regulatory environment what they are not is "just servers on the internet". You can break into a bitcoin exchange and steal BTC by copying data. You can't do that with a bank -- banks can only transfer electronically to other banks, and "being a bank" is a tightly regulated state.
So while the complexity is there, it's not clear to me that it correlates to an "attack surface" in the sense network security people use the term.
> Well when you consider that a traditional bank has teams of security experts, spend millions of dollars on security infrastructure
Those banks are often guarding a considerably larger amount of money, which is something to take into consideration. I think your point still stands though.