This is a tough situation. I don't know about 94% of TOR traffic being fraudulent but I'm sure it's high. But I'm one of the legit users that gets taken out by blacklisting. I use a VPN service pretty regularly and it makes accessing my Cloudflare account and sites using it incredibly annoying.
I assume the actual claim is that 94% of fraudulent traffic comes via tor. Which is quite a different claim. There's a pretty obvious calculus. If you approach the question as 94% of the fraudulent traffic comes from the x% of total traffic that comes via tor... deciding to block tor exit nodes seems rational (particularly if x% is particularly small... say <1%).
The claim is thus:
> Based on data across the CloudFlare network, 94% of requests that we see across the Tor network are per se malicious. That doesn’t mean they are visiting controversial content, but instead that they are automated requests designed to harm our customers.
Meaning that for any given request coming from Tor, the odds are heavily in favor of it being malicious.