1. DMs can be restricted to followed profiles.
2. Abuse can be reported and admins will likely act. Such a spam would be a once-and-done affair.
3. I'd need to check the spec / code, but suspect there's an upper bound on the number of profiles which can be mentioned in a single toot.
I'm not saying there's no opportunity for abuse. But on the whole, and on a cost-benefit assessment for the spammer, there are probably more viable options for spreading a message.