Tor has acknowledged their "botnet problem" since at least 2013:
https://research.torproject.org/techreports/botnet-tr-2013-1...
That same paper walks through the challenges of dealing with it and doesn't find any satisfactory solutions.
As I wrote in our post on the topic, there's a trade off between security, anonymity, and convenience. CloudFlare provides security to our customers. We believe in the importance of anonymously accessing the Internet. Unfortunately, that means we have to sacrifice some convenience. If you haven't read it, I encourage you to see the post I wrote on the topic:
https://blog.cloudflare.com/the-trouble-with-tor/
The two long-term solutions we proposed — blinded tokens or CloudFlare supporting .onion addresses — we believe could reduce the inconvenience, but they'll require help from the Tor developers. While public posts like this are discouraging in terms of coming up with a better solution, I'm encouraged by private conversations we've had with Tor developers who acknowledge this is a hard problem and want to find solutions.