i don't know their architecture, but am going to speculate that they are possibly doing logging where requests write to the database or something else where auth attempts from a ddos have an impact against the database.
days ago when mtgox was under a different ddos attack, tux said something to the effect of a backup process that runs hourly implements a lock but that process was being impacted as the result of the ddos. because the backup had locked but wasn't succeeding, then trades were not occurring.
this may be all be way off the mark but there hasn't been any better info to explain the underlying problem but we now have two ddos attacks that we know of where trading was impacted.
assigning blame to the use of mysql was wrong, sorry. the intended point was that this exchange wasn't built with the same technologies or dev team that an etrade or oanda are built with.