Defense in depth – maybe I’m paranoid, but just because something is unlikely doesn’t mean an extra layer of security isn’t advantageous. Particularly when I already have a VPN, so there’s little reason not to use it.
Plus, my logs are easily checked as a side effect.
I’m running a Venstar Colortouch thermostat. They’re not cheap, but they have a local API and there’s a Homeassistant integration.