I mean, the blockchain trilemma is real. There are no designs that eliminate scaling and centralization pressures. Monero just makes another different set of trade-offs.
Likewise, I don't think there is any way to prevent a dedicated spam attack from an adversary that has unlimited money.
But making the cost of performing the attack quadratic rather than linear is a good start.
