I am also puzzled by this, and if the number is hops is so large that it’s unfeasible to enumerate, how does the key generator know many hops it should be...
I remember watching a presentation by Tanja Lange and djb that explained that kind of thing very well. It starts with easy to visualize examples using "clock crypto" and then transitions to real ECC curves.