I get possibly a dozen or so emails a year to catch-alls that I dont recognise as having been given out - its incredibly rare that it is every anything other than someone mistyping my name.
I also get a monumental quantity of spam so not exactly a small sample but still just one example.
I do pop in every now and again and don't recall seeing anything akin to what the parent to your post is suggesting (many emails following the same format but to different addresses and I guess names).
Then along came web facing databases with no auth defaults, and you can have a billion active, in use email addresses with a living breathing human at the other end (and their username, password and dob) for free.
As such, a catch-all e-mail address was a sure way to get hundreds of copies of the same spam e-mail. And since most people who wanted a catch-all address were doing it as part of a strategy to get less spam, that was the opposite of what they were aiming for.
Perhaps spammers have stopped doing that since?
My domains are not really "out there" in any big way though, so perhaps I've just been lucky?