It sounds like they were blocking by IP addresses rather than domain names, so when X went behind Cloudflare’s reverse proxy, the traffic was going to Cloudflare’s IP addresses, through the proxy and then to X.
Any bets that there aren’t gaping holes in the blocks in IPv6? (An expanded addressing scheme that everyone should have switched to a long time ago. It’s complicated.)