Well, she doesn't, they will block the attacker outright by a centralized decree. What's the better proof that decentralized solutions work than blacklisting accounts and making ad-hoc forks for each attack.
The DAO code that the stolen ETH is held in doesn't allow spending for 27 days, by which time the Ethereum developers hope to have 51% of node power on the fork that blocks transactions involving this address.