Interesting. I assumed all VPNs switched to IPv6 by now, making detection much harder.
You just track and block /24 or /16 as necessary.
Even with IPv6 it's not a huge problem. With a few samples we can know that a provider is operating in a given /64 or /48 or even /32 space, and can assign a confidence level that the range is used for VPNs.