For performance reasons, we wanted to serve everything directly from the filesystem instead of dynamically using a script. If an image requested is not found, the 404 handler generates it, saves it to disk, and sends it back.
The legitimate URLs are for 'static' images (static in the sense that once they have been generated, they will never need to be generated again) that are stored on disk using the filesystem. For example, an image url might look like:
http://example.com/1e/2f/c/(image generation parameters).png
The idea is that 1e2fc (the hash) serves as both the path on disk (so that files are roughly evenly distributed among the 2^20 directories) and as a checksum to prevent DOS.