National censorship systems burn bridge IPs through several distinct methods. Active probing sends connection attempts to known bridge ports from inside the censored network. If the server responds in a way that reveals Tor traffic even through obfs4 obfuscation, the IP is added to a blocklist. China's GFW is the most advanced active prober; it has protocol fingerprints for obfs4 versions and can burn a new bridge within hours of BridgeDB distribution.
Passive observation at the network level tracks which IPs receive traffic from many different source addresses in short bursts, a pattern consistent with bridge usage. Even without decrypting traffic, the correlation is strong enough to justify adding IPs to blocklists. Iran and Russia use variations of this approach.
Intelligence sharing between censorship organizations means a bridge burned in China can appear on Russian or Iranian blocklists within weeks. Operators running bridges intended for a specific country should not assume that geolocation prevents burning from other censor networks that share threat intelligence.