Absolutely, the average user won't be looking at the contracts (and yes there will be exploits). All software is buggy, the open-ness just gives malicious users a path to find exploits (and also bug bounty hunters incentive to responsibly disclose). With traditional software, the attackers are often large actors and we may never hear about all the exploits.
But think about where faith is being placed in traditional software vs. decentralized software: with traditional software, you rely on a whistleblower inside the company, or a government agency to expose corruption, malpractice, maliciousness, noncompliance, or incompetence.
In a dapp, there are also knowledgeable watchdogs who are incentivized to expose scams/fraud, or report bugs (I'd wager there are more responsible disclosures in crypto than exploits by bad actors).
Knowledgable researchers keep casual users informed of developments, and give layperson explanations of how dapp works (and Cunningham's law dictates that they're likely to be called out if their explanation is incorrect).
Either way, people are placing their trust somewhere. Traditional applications basically rely a lot on "security by obscurity" which doesn't make them truly secure. And many users enjoy truly transparent applications.
The biggest problem with crypto for the average person is that it's incredibly hard to assess risk in order to develop risk-appropriate strategies and expectations for interacting with crypto. And it can also be hard to get a straight answer when discussing risks (good signals are surrounded by lots of noise). That's why I think that rather than writing off the industry as a whole, those of us who have more insight into the technology (and the risks) should be advising less technical participants to be incredibly cautious, not to approach crypto outside of the top two as an investment without incredible diligence etc. (though, like the author, I'm very much opposed to bitcoin due to proof of work)