> Another way of looking at this is that whoever controls greater than 50% of the network cannot be considered malicious from the network's perspective.
What people forget about in these imagined 50% attack scenarios is that 50% attacks only work if the attacking nodes generate valid blocks. All the hashpower in the world doesn't matter if your blocks do not pass validation. So no consortium can just start mining bad blocks and get away with it. The problem is that there are a non-trivial amount of clients that don't do any validation themselves and so rely on full nodes to tell them the true state of the network. Those clients would be subject to losing money. But any big exchange should be validating blocks themselves so the risk to the entire network is minimal to non-existent.
What people forget about in these imagined 50% attack scenarios is that 50% attacks only work if the attacking nodes generate valid blocks. All the hashpower in the world doesn't matter if your blocks do not pass validation. So no consortium can just start mining bad blocks and get away with it. The problem is that there are a non-trivial amount of clients that don't do any validation themselves and so rely on full nodes to tell them the true state of the network. Those clients would be subject to losing money. But any big exchange should be validating blocks themselves so the risk to the entire network is minimal to non-existent.