You're right, with a VPN you just shift trust from your ISP to the VPN provider.
There's nothing a malicious relay operator can really do to you, other than perhaps try to DoS you if they're some kind of script kiddie, but even that is at most an inconvenience.
Nobody can doxx you based on your IP address alone, for example, as they aren't accurately geolocated. If you're in the states then they may know what state you're in, for example, but that's about it.