An attacker controlling more than half of the hashrate can, over time, produce a heavier chain than everyone else. That gives real but limited powers.
What a majority can do
- Double spend their own coins: pay, wait for delivery, then publish a heavier chain without that payment.
- Censor: refuse to include some transactions, and orphan other miners' blocks that do.
- Disrupt: cause deep reorgs that damage trust in recent payments.
What it cannot do
- Spend coins without their private keys.
- Create bitcoin beyond the schedule or change the reward.
- Change any rule nodes enforce: invalid blocks are rejected whatever the hashrate.
The cost is the obstacle: acquiring and powering more hardware than the rest of the industry combined, while attacking the value of the very coins it would earn. Smaller coins that share an algorithm with a bigger one have suffered such attacks; Bitcoin, with the largest hashrate of its algorithm, never has.