There are tons and tons of much smaller coins, that can be attacked for very cheap, and yet attacks are still very rare.
IMO, this is because double spends just aren't a very good idea. If you tried to steal money from an exchange, everyone would know it was you doing the attack, and then they wouldn't accept your money in the future, or maybe you'd just go to jail instead.
Also, the network is not static. If there is lots of hashpower sitting unused, maybe that hashpower would turn in to defend against an attack.
More people have something to lose from a successful attack, and thus could be motivated to defend when an attack happens.