You know what's easier than waiting around to get really lucky?

Using those same network-health dashboards as DDoS target lists, to temporarily degrade/shut down the whole network except for your own nodes.

Also, big nodes route more Tor circuits each. Costs more to run them, and they intentionally don't function as exit nodes (to avoid the "obvious" attack) — but just having a bunch of these big nodes in the network handling only middle hops, biases the rest of the network away from handling middle hops, toward handling end hops. Which means that if you then run a ton of tiny nodes...