This is a big nothing-burger. The "attacker" has to actively sustain downloading the data being requested. No amplification, no anything making it anything but a nuisance. Just a lamer that discovered that they can keep making requests in a loop in a Python script.
Sure, some per-IP rate-limiting might be desirable there (but has to be balanced against new nodes being able to download the history), but any service exposing data on the public Internet can be DDoSed by just making requests to it from multiple IPs, and that's why so many companies hide behind Cloudflare.
The total rate limiting seems to be already implemented: https://notatether.com/academy/how-to-limit-bandwidth-of-bit...
This "attack" might rake some fees on people hosting public nodes in the cloud (just like about any http server, S3 bucket etc.), but that's about it. Lots of nodes don't accept incoming connections, communicate via Tor, network relays, etc. so this has absolutely no chance of making any dent in the network as a whole.