so DDOSing is not an issue IMHO
maybe campaign trash talk bashing .. but not DDOS
Here is one such exploit:
Enumerate all nodes on the network by following connections from the client. Delegates have to be online to produce blocks, so you'll be able to gather their IP addresses along with everyone elses.
Then, simply run through that list, DDOS bursting at each IP address and watch every single delegate for stats dropping. You will be able to find a map from IP to delegate with quite a high probability with enough DDOS probes.
edit: might cost a lot if you don't own a botnet, but the risk is there.