Just spitballing here, but if you use a VM with gpu passthrough, the host system doesn't even see the GPU anymore, so if the VM is off I imagine the GPU is basically off as well. In terms of encryption at rest, you can probably make a separate LUKS volume for the VM disk image, and then lock it when the VM is off.
Edit: for example I have a VM with GPU passthrough and when the VM is off, I have no way to check the power consumption of the GPU (aside fom using external hardware) since the host doesn't have access. The host uses a sort of dummy driver for the GPU, so that the hypervisor can pass it on to the VM, so it is actually possible for the host to switch the driver and take control of the GPU when the VM is off. But until then I imagine power consumption is minimal.
Do you know if the scrapers/bots are using the VPN providers? Or if they are just using VPSes in the same datacenter as the VPN, and the datacenter is just NATing all egress traffic to have the same IPv4. In that case I wonder if IPv6 could help distinguish between VPN traffic and bot traffic...
Though ultimately a gate like Anubis or Angie Guardian might be the best solution here so nice work.