We are not compromised, however our current ISP has troubles coping with the DDoS.
Note that a DDoS has nothing to do with security. Security usually involves getting inside the site to steal stuff (for example) while DDoS just means sending a lot of legitimate-looking traffic to make the site go down.
Anyway we'll be moving to a much stronger solution soon (contract already signed, waiting for setup).
The site has been slow for what, a week (or more)?
Even if the site wasn't compromised, someone must benefit from it; Even a 100mbit/s downlink DDoS costs about $500 per day on russian forums by western union.
Utilizing a big botnet is not free at all.
I still fail to see the motive though. Driving people to other exchanges? Undermining bitcoin? Seems pretty expensive.