Interesting hypothesis. I wonder if all of those attacked are running full Bitcoin nodes at the same public IP addresses?
I have never run a bitcoin node, so have little insight as to what can be harvested by way of intel from the relayed traffic. But I don't think that running a node would make you any more or less susceptible to this type of attack.
If they were targeting specific servers, they wouldn't be redirecting Bitcoin miners to a scrypt server - kinda pointless

Gawd, well that pretty much sums it up.