Exploiters are still able to decompile local scripts, it’s just that due to the new VM all old methods are broken and need to be redone. It’s also slightly more difficult.
Additionally, it breaks many exploits because of the new bytecode structure but also because we no longer embed local variable names in the bytecode. (worth noting is that fundamentally the VM isn’t more secure aside from that and we expect exploiters to catch up)