Address Relay under stress: Attack Characteristics and Measuring Its Effects

I think it’s because of this timeline of events:

  1. The bitprojects eclipser was running, providing decent listening capacity in the network.
  2. The eclipser switched off at the end of March, and the network lost a lot of listening capacity.
  3. The addr spam attack started in mid-April.

So my guess is that the tried table percentage dropped because the eclipser turned off its node, not because of the addr spam itself.

Side note: I think it’s reasonable to expect the tried table to be only ~50% reachable, since the unreachable addresses in the tried table were nodes with much older timestamps.