What's not obvious from outside of Cloudflare is that DDoS attack traffic doesn't increase our costs. While someone like AWS charges based on bytes delivered, we instead pay for bandwidth based on the capacity of our connection. Importantly, we pay for the greater of the traffic into our network (ingress) or out from our network (egress).
To make it tangible with made up numbers, imagine we pay $10/megabit per second per month. If our egress (out) is 10Mbps and our ingress (in) is 1Mbps then we'd pay 10 x $10 = $100/month. If our ingress went up to 9Mbps and our egress stayed at 10Mbps then we'd still pay 10 x $10 = $100/month.
Since we're a caching proxy, you'd expect egress (out) to be higher than ingress (in). That is in fact the case. While DDoS attacks push the ingress up, the spread between ingress and egress is so large that even the largest attacks don't push ingress above egress. In fact, even attacks that are many times larger than the largest attacks ever seen would still not increase our bandwidth costs.
This is different from other providers that run separate networks for DDoS mitigation, or only provide DDoS mitigation without providing other caching services. My understanding is that Akamai runs a separate network for DDoS from their CDN, which is why large attacks drive up their costs. We made different architectural decisions, which is why it doesn't for us. And, as our caching services get more popular, it effectively increases the size of the largest theoretical attack we could handle without it driving up our bandwidth costs.
So, yes, there is a theoretical limit of an attack we could not handle today. That, however, is at least an order of magnitude bigger than the largest attacks the Internet has ever seen. And, if such an attack did happen, I think there would be other parts of the Internet that would fall over before we did.
For the record: since we announced Unmetered DDoS mitigation in September 2017 we haven't terminated any customer, free or paying, for an attack they've received.