Unlike clearnet DDoS that primarily targets network bandwidth or server CPU, hidden service DDoS specifically targets the Tor circuit establishment process. An attacker who wants to take down a hidden service creates many Tor circuits to the service's introduction points. Each circuit establishment requires cryptographic operations from the hidden service's Tor process, and the Tor process has a maximum rate at which it can handle circuit establishment requests.
When circuit establishment requests exceed the Tor process's capacity, the introduction points queue up and eventually reject connection attempts. Legitimate users trying to connect see "circuit build failed" errors or extremely long connection times. The attack does not require the attacker to have high bandwidth; it only requires the ability to create many circuits quickly, which any Tor user can do with a modified Tor client.
This attack was historically a serious problem for high-profile hidden services. The Tor Project responded by implementing proof-of-work (PoW) challenges in Tor 0.4.8, released in 2023. PoW requires clients to solve a computationally difficult puzzle before an introduction point will forward their connection request to the service. The difficulty scales automatically when the service detects it is under attack.