Steem is designed for an easy 1/3 + 1 attack.
That is very innacurate...1/3 +1 only gives the "attacker" the ability to block a hardfork but you cannot takeover consensus...for that you need 2/3 +1.
What is more, it's designed through the multivote rule to be 100% controlled by a very small number of top SP holders.
It designed for the majority stake to dictate consensus. The number of accounts holding the SP is irrelevant to the consensus logic. This favors centralization.
The real threat is voter apathy. Before this whole incident started only about 28% of the stake was voting (it might have been less so I might be wrong on the exact number). With that level of participation and combined with the 30 vote rule you only need 29% of the stake to take over the witness positions.
Mix in some colusion with exchanges and you have exposed the DPOS vulnerabilities.
The solution seems obvious...limit the number of seats that an account can vote on and incentivize voting (maybe direct a portion of the inflation for that). Although limiting the amount of positions introduces other risks (such as the blockchain forking if no one can control consensus).
RE: Fact: Steemit Sybil Attacked the Steem Blockchain