This is a problem at any stake. Random coalitions to alter the past can be formed at no cost to those colluding.
Checkpointing is not an alternative to decentralized consensus but central override of it.
The same works for Bitcoin, too.
Why do you insist on defining a mining rig differently from a PoS token?
If bitcoin miners collude, they could alter the past.
If Nxt forgers collude, they could alter the past.
I see no difference.