One of the few reasonable comments on this thread.
I don’t see how cloudflare could have prevented this at all. Even if they took down the info site of the attackers they could just host it on GitHub pages, or a million other free static site hosters.
Zero evidence that cloudflare actually enabled the attack itself from what I can tell.