The threat model of proof-of-stake (PoS) is weaker than that of proof-of-work (PoW). For example, "initial sync" (a new node joining the network, needing to find the sequence of blocks that everyone agrees is the right sequence of blocks) is
much simpler with PoW compared to PoS. And, furthermore, with PoS it's possible to compromise this process by stealing private keys from a group that comprises a majority. An attacker can do this silently, and at some later date start publishing alternative chains, thus breaking initial sync by offering multiple, valid chains to new nodes, thus making them unable to decide.
In contrast, it's not possible to steal a majority of PoW mining power, and sit on it for an extended period, without (a) foregoing a large profit, and (b) risking that others acquire more mining power than you have.
One of the Cardano whitepapers [1] contains a good summary of the advantages of PoW over PoS in Section 5.1.1 under "Consequences of PoS vs PoW":
A crucial difference exists between PoS and PoW at the network layer, with significant design consequences: in PoW-based systems, proof-of-work itself gives honest nodes an advantage over adversarial nodes (as listed below), and this enables system designs that are simpler and more modular. There is no such advantage for honest nodes in PoS-based systems such as Ouroboros.
In PoW systems:
• The number of different block headers with a valid PoW that can be constructed (over any given period of time) is bounded by the total available hashing power in the world. In Bitcoin for example this is one header every ten minutes on average.
• The header PoW can be checked with little computational cost. This does not require any significant or recent state, only a vaguely-recent lower bound on the hashing difficulty value is needed.
• Such a cheap and simple test can be easily integrated into existing distributed algorithms such as broadcast algorithms.
By contrast, with PoS in Ouroboros:
• There is no equivalent of the PoW check that is expensive for the adversaries and cheap for the honest nodes: adversaries can create many apparently valid or actually valid candidate headers or whole chains.
• Block headers can only be fully validated with access to a very recent copy of the full ledger state, and the other preceding headers – which is not a simple stateless check.
• Having the full ledger state relies on the other two pieces of Ouroboros functionality: chain validation and chain selection
[1] https://hydra.iohk.io/build/6684352/download/1/network-desig...