During Hamony's previous hack (Bridge exploit by DPRK). Some people helped them(include Zach), but the dev gives no reward for people for their help and they only said good job those who helped them.
Beside that they ever created bug bounty, but they also refused to pay anyone who found the bugs for them. Harmony team was a scammer, and simply didn't care to their blockchain.
No doubt no auditors had interest to work with them.
This implies that they rely solely on bug reports from their internal team; it is hardly surprising that this chain is frequently exploited, given the lack of external oversight. The community can conclude that this chain is fundamentally insecure in the long-term.
ONE's market cap was already very small before this incident. Its value now depends entirely on how well it rebuilds public trust. I don't think I'll see them shine again in the next bull market.