TBF, it’s more likely just overconfidence/incompetence. Cracks are OFTEN flagged by AV, and it’s usually nothing malicious. The guys at 1337x aren’t dumb enough to think a crypto miner wouldn’t be found pretty quickly.
Hanlon’s Razor: Never attribute to malice that which is adequately explained by stupidity.
That’s only for authentication and some apps. You can set an IP whitelist so it doesn’t require auth from certain ranges - when I changed ISP a little while ago, I was still using Plex offline.