it's not a theory, i wrote a key miner and it does over 100k new pubkeys every 5 seconds CF is only stopping the more obvious bulk traffic attacks, not protocol level ones
POW enables gateway stop ur script unless you hardware is strong enough
NIP-42 and POW both that prevent that but allowing non-auth npub is also important for growth of nostr. no normies even know how to use nostr and asking everyone to use NIp42 client is make no normies use nostr. so RATE LIMIT is still the key
PoW, or fees, either way we have lightning network integrations everywhere PoW will only last as long as it remains more expensive or complicated, after that, only subscription fees will stop them bitcoin survives entirely because it costs more to attack it than the benefits it provides