Earlier quoted context omitted.
What if a portion of those sent coins are sent to attacker-owned wallets?
If it's a non-negligible amount compared to other wallets, that would be pretty easy to track down. I mean, you'd look at new wallets compared to existing wallets.
The attackers can still poison new wallets that appear on the chain - either you effectively shut down new wallet creation, or let the attackers possibly spend their coins.