Now, you could truncate this to eg a /64 or /56 range to identify users, but each ISP has different rules. Mine gives a /56, but I also hear many give only a /64 or less.
As such, it basically means that you can’t really rely easily on IP addresses anymore for spam detection, rate limiting, etc.
Note that I’m not an expert on spam filtering, but I do have quite some networking experience and QoS, and ran into these issues a lot.
Whereas the same in IPv6 isn't feasible. There is no reasonable way to divide the IP space non-sparsely and keep in RAM and still ban without ending up banning a whole ISP.
Even at 128:1 CGNAT ratios a /24 has 32,768 potential users.
By comparison, a /56 has 256 potential users on a /64 each.
With some heuristics of "hey, we saw two /64's from the same /60" you can catch most ISP's that are offering prefix delegation to their customers, and that's only 16 /60's in that /56 before you are fully blocked...
It's not that much harder or difficult.
v6 is more difficult, by design. The lower half of the address is deliberately not subnettable and it is the explicit design intent that machines on a v6 network can just make up new addresses within a /64 as they please. So you have to burn subnets. Except there isn't really a standard for how subnets are issued: most ISPs hand out /48s, Comcast insists on /64s for residential use, etc. In the IPv4 world you could ban one IP at a time, and only move on to banning entire AS allocations if you needed to. On IPv6, banning a /64 is a lot less impactful, so you have to start with the most drastic and customer-hostile option.