You already can't do that since the abuser will just buy residential proxies.
Banning a couple of faraway datacenters by ASN (and thus IP address) took out like >80% of the bot traffic to a site I help. They won't "just".
At my previous job we routinely gave out IP-based bans, and it worked pretty well; the most insistent guys gave up after their third or fourth IP banned at most.
Cloudflare Warp has been more of an issue for a small webapp I run than residential proxies. Because it's a mix of legitimate users whom I guess installed the 1.1.1.1 app and have no idea they're tunnelling all their traffic through Cloudflare, and abusive users. I've never seen an actual CGNAT IP addresses from a consumer ISPs being shared by a legitimate user and a persistent abusive one.
CF seems to end up in the business of making problems worse, and selling the fix way too often. Before this, I had someone try to DDoS a webapp by setting up their own domain to proxy to my backend and running their attack traffic through CF. But that was easy, I could just block CF's IP range entirely as I don't use their reverse proxies.