There are several papers about how to stop DDoS by using cryptographic puzzles.[1] The core idea is to give the abuser some algorithmic work he has to solve, thereby forcing him to waste processing power, and then to slow him down to a manageable level.[2] That only work if you are the target, and not some intermediary are targeted.
Could it be a solution for the WMF servers?
[1] (just a random pick) [2] (about TLS, but can also be done at the application level)