A small validator set is a cheap target
Any new network or service that wants cryptoeconomic security faces the same uphill problem: it needs validators willing to lock up capital and put it at risk, but at launch it has no track record, no established rewards, and no proof that participating is worthwhile. So it has to attract that capital cold. Even if it succeeds in attracting some, the resulting validator set starts out small, because trust and capital accumulate gradually, not all at once. And a small validator set backed by a small amount of total staked capital is, by definition, cheap to attack.
The cost of attacking a Proof of Stake system scales with how much capital an attacker would need to acquire or control to overwhelm the honest validators. For an established, mature network with a large, broadly distributed pool of stake, that cost is enormous, often prohibitively so. For a brand-new network, the equivalent cost might be small enough that a well-funded attacker could acquire it directly, or even that existing large holders could threaten the network's integrity without much effort. The security a new network offers is only as strong as the capital actually protecting it, and that capital starts thin.
