DNS propogation is not instant, it can take hours in some cases for the new ip's to propagate to all the DNS servers in the world
But *everytime* when I changed DNS records to new IP or even when I created yet another DNS record (do you remember my post about new DNS api3.bitcoin.cz last week?), attack followed those changes in DNS or posts on forum almost immediately. Thanks to that I know attacker is here between us, following what's going and targeting attack to new places instantly (in matter of minutes).
Don't forget that this wasn't first attack to pool and this pattern was here every time. So yes, this *prove* that attacker didn't follow IP changes intentionally.