How do you make sure that the single IPv4 address you are blocking is not used for CGNAT? When you don't care about collateral damage you could as well block IPv6 /40 or /48s. Currently this is maybe not a problem yet because most people don't have CGNAT addresses but the problem will become bigger.