I've seen first hand how a serverless application, "scaling" to meet a huge demand, will stampede the weakest downstream service and DDoS it.
In this case they're lucky that their payment processor (Stripe) didn't start throttling them. You may have spoken with Stripe beforehand about your expected load and get some sort of agreement / whitelist for your API token. That would be very wise.