Instead of burning electricity, a validator posts a bond of the chain's own coin. The protocol selects proposers roughly in proportion to stake, and misbehaviour such as signing two conflicting blocks triggers slashing, which destroys part of the bond.
Security comes from capital at risk rather than energy spent. Attacking the chain means acquiring an enormous stake and then watching the protocol destroy it, while the attack itself craters the value of what remains.
Example: with 32m coins staked and a 33% threshold for disruption, an attacker needs over 10.5m coins. At $3,000 each that is $31bn tied up and exposed to slashing. Critics counter that stake compounds to whoever already holds the most, and that most stake in practice sits with a handful of large operators.