OAK — OnChain Attack Knowledge

Worked example · 2023-02

Blur airdrop incentive-wash cohort — Ethereum — 2022-10-19 through 2024 (cohort case)

Loss
no single direct-loss figure attaches to this cohort because the failure mode is price-discovery-distortion, not direct theft. The cohort harm is borne by (a) third-party buyers who purchased NFTs at floor prices anchored on inflated trade history and (b) the integrity of marketplace-leaderboard, floor-price-trend, and per-collection volume metrics across the affected window. Public on-chain forensic analysis (Hildobby Dune dashboards, NFTGo wash-trade reports, CryptoSlam wash-trade indices) consistently reported that a substantial share of Ethereum NFT trading volume routing through Blur during the airdrop-incentive seasons was wash. Quantitative estimates varied across providers and methodologies; widely-cited figures placed Blur's wash-trade share at the multi-tens-of-percent level during peak airdrop-incentive windows (Season 1 launch through Season 2), with specific collections inside the Care Package / Bid Pool incentive scope showing materially higher per-collection wash rates. The economic transfer in the cohort is from the BLUR token-emission budget (which paid out airdrop allocations partially to wash-trading farmers) and from third-party buyers anchoring on distorted floors, not from a single named victim.
OAK Techniques observed
OAK-T12.001 (NFT Wash-Trade Volume Inflation) is the canonical Technique mapping for the cohort, with the marketplace-incentive-driven wash sub-motivation explicitly named in the T12.001 page as a sub-class of the same on-chain artefact. The Blur cohort is the canonical worked example for that sub-motivation: the wash trades targeted token-airdrop allocation (Care Packages, Season 1 / Season 2 / Season 3 BLUR airdrop scoring) rather than a third-party-buyer exit, but the on-chain artefact (self-financed trades between related addresses on an NFT marketplace) and the marketplace-side detection surface (per-cluster wash-trade-rate metrics, leaderboard-validation reconstruction) are shared with the price-discovery-distortion sub-motivation. Cohort touches OAK-T3.002 conceptually (incentive-wash-farming on a marketplace-token reward formula) but the on-chain artefact lives at the NFT-marketplace layer rather than at the DEX-pair layer, which is why T12.001 is the load-bearing reference. OAK-T7.004 (NFT Wash-Laundering) is adjacent / motive-ambiguous: the on-chain trade pattern is structurally indistinguishable from T7.004 laundering-motive wash-trades at the trace level even though the dominant motive in the Blur cohort is airdrop-farming rather than illicit-proceeds laundering — the case is the canonical T3.002 / T7.004 motive-ambiguity reference per techniques/T7.004-nft-wash-laundering.md, demonstrating that marketplace-layer detection requires goal-discrimination heuristics rather than trade-pattern alone.
Attribution
inferred-strong at the cohort level. Per-cluster cohort identification is well-established in public on-chain forensics (Hildobby's Dune analyses, NFTGo's wash-trade reports, CryptoSlam's filtered-volume index) and Blur publicly acknowledged the airdrop-incentive-wash dynamic by tightening its airdrop-eligibility scoring methodology between Season 1 and Season 2. Per-individual operator attribution to named persons is pseudonymous at the cohort level; specific addresses identified as high-volume wash-farmers are routinely anonymous, and OAK does not name individual cohort participants. The strongest evidentiary tier in this cohort is at the marketplace-acknowledgement layer (Blur's airdrop-formula adjustments) and at the cohort-level on-chain forensic layer (Hildobby / NFTGo / CryptoSlam).
Cohort framing
this is a cohort case — incentive-wash farming during the Blur airdrop seasons was conducted by a population of operators in parallel rather than by a single named operator at a single named time. The cohort case captures the marketplace-incentive-driven wash sub-motivation of T12.001 across the multi-season Blur incentive program; per-incident worked examples are not the appropriate frame because the cohort harm is in the aggregate distortion of marketplace metrics, not in any single named transaction.
Key teaching point
The Blur airdrop incentive-wash cohort is OAK's canonical worked example for the marketplace-incentive-driven wash sub-motivation of T12.001. The cohort is empirically distinct from the price-discovery-distortion sub-motivation that anchors the standard T12.001 framing — distinct in operator goal, distinct in Mitigation owner, distinct in cohort dynamics under defender response — but the on-chain artefact and the detection surface overlap, which is why the T12.001 page treats the sub-motivation as a sub-class rather than promoting it to a sibling Technique at v0.1.

Summary

Blur launched on 2022-10-19 as a pro-trader-focused Ethereum NFT marketplace and aggregator. From launch through 2024, Blur ran a multi-season points-and-airdrop incentive program — Care Packages (the pre-airdrop accumulation phase), the Season 1 BLUR token airdrop (February 2023), Season 2 (May 2023), and Season 3 (continuing through 2024) — that scored user activity (listing, bidding, trading) and converted accumulated points into BLUR token allocations at season-end. The economic-design intent was to accelerate Ethereum NFT volume migration to Blur's order book and to compensate liquidity providers (bidders especially) for the platform's price-discovery contribution.

The unintended consequence was a structurally-incentivised wash-trade cohort. Operators with two or more controlled wallets discovered that the airdrop-eligible activity scoring rewarded gross trade volume and bidding activity in ways that did not adequately discount self-financed trades between related addresses. The result was a cohort of operators who traded the same NFTs (often the same token-ids) repeatedly between their own controlled wallets to farm Care Package and airdrop allocations, in addition to whatever T12.001-classic price-discovery-distortion flows ran in parallel.

Public on-chain forensic providers documented the dynamic at scale across the Season 1 launch and the Season 2 window. Hildobby's Dune dashboards published per-collection wash-trade rates that, at peak Blur airdrop windows, materially exceeded the comparable rates on OpenSea and X2Y2. NFTGo and CryptoSlam published parallel wash-adjusted volume metrics. The public-record consensus across providers was that Blur's airdrop-incentive structure was a substantive contributor to its early-2023 wash-trade volume share — distinct in motivation from the LooksRare / X2Y2 incentive-wash episodes of 2022 (which had similar artefact patterns under different reward formulas) and distinct from the price-discovery-distortion T12.001 cohort that ran in parallel for collection-level marketing reasons.

Blur publicly acknowledged the dynamic and adjusted scoring between seasons. Between Season 1 and Season 2, Blur introduced changes to airdrop-eligibility scoring that tightened the discount applied to self-financed trades and to bid activity that did not result in genuine price discovery. The exact scoring formulas were never fully public-documented, but the Blur team's public communications across the seasons explicitly framed the adjustments as responding to incentive-wash farming. The Season 2 → Season 3 transition included further adjustments along similar lines.

For OAK's purposes, the Blur cohort is the canonical worked example for marketplace-incentive-driven wash as a sub-motivation of T12.001. The case demonstrates three structural points the T12.001 page identifies but did not previously have a dated cohort to anchor against: (a) the on-chain artefact for incentive-wash overlaps with the artefact for price-discovery-distortion wash but the operator goal is different, (b) the highest-leverage Mitigation surface for incentive-wash is at the reward-formula layer (the marketplace's airdrop scoring), not at the per-collection metric-display layer, and (c) marketplaces running incentive programs occupy a defender position that requires explicit per-cluster wash-trade-rate computation if the program is to avoid subsidising the wash cohort.

Timeline (UTC)

When Event OAK ref
2022-10-19 Blur launches as a pro-trader Ethereum NFT marketplace + aggregator with a recommended-minimum 0.5% royalty default and buyer-customizable royalty input (separate cohort question; see examples/2022-11-x2y2-looksrare-royalty-optional.md for the parallel royalty cohort) (Blur launch context)
2022-10-19 to 2023-02-14 Care Package accumulation phase — pre-airdrop activity scoring; Blur publishes points-mechanic guidance; trader cohort begins accumulating activity-derived points (incentive-program setup)
2022-11-01 onward Hildobby Dune dashboard wash-trade analysis publishes per-marketplace wash-trade rates including Blur; cohort wash-trade share visible in public forensics T12.001 cohort observation phase
2023-02-14 Blur Season 1 BLUR token airdrop distributed; airdrop allocations attributed across the Care Package activity ledger; large recipients identified in industry coverage T12.001 incentive-wash crystallisation
2023-02 — 2023-05 Industry coverage and on-chain analysis (NFTGo, CryptoSlam, Hildobby) document Season 1 wash-share patterns; Blur publishes Season 2 scoring guidance signalling tightening of self-financed-trade discounts (incentive-formula adjustment)
2023-05 Blur Season 2 airdrop distributed under adjusted scoring formula; per-cluster wash-trade-rate analysis continues to show non-trivial cohort persistence but at lower share than Season 1 T12.001 cohort observation phase 2
2023-08-17 OpenSea Operator Filter Registry sunset announcement (parallel cohort event; see examples/2023-08-opensea-operator-filter-sunset.md) further accelerates volume migration to royalty-optional venues including Blur (parallel cohort context)
2023 — 2024 Season 3 and subsequent airdrop seasons continue with iteratively-tightened scoring; the cohort persists across seasons but per-season wash-share trends downward as the reward formula matures T12.001 cohort tail
Through 2024 Cohort-level wash-trade-rate metrics published by NFT analytics platforms (NFTGo, CryptoSlam, bitsCrunch, DappRadar) become a standard part of NFT collection due-diligence (Mitigation maturation)

What defenders observed

  • Per-marketplace wash-trade-rate metrics were the load-bearing detection surface. Hildobby's Dune dashboards published per-marketplace and per-collection wash-trade rates across the cohort window using a self-financed-cluster heuristic at the address-cluster level (filtering on same-cluster-buyer-and-seller per-trade signatures). NFTGo and CryptoSlam published parallel metrics. The cohort observation was visible in real time to defenders consuming these dashboards; the limitation was that per-trade goal-attribution (incentive-farming vs price-discovery-distortion vs T7.004 laundering) was not surfaced by the wash-trade detection alone — all three sub-motivations produced overlapping on-chain artefacts.
  • The Mitigation surface for incentive-wash sits at the reward formula, not the per-collection metric. OAK-T12.001's Mitigation guidance for the price-discovery-distortion sub-motivation is per-cluster wash-trade-rate caps applied to leaderboard volume and floor display. For the incentive-wash sub-motivation, the equivalent Mitigation is per-cluster wash-trade-rate caps applied to airdrop-eligible volume at the reward-formula level. Blur's Season 1 → Season 2 → Season 3 scoring adjustments are the canonical worked example of marketplace-side response to the cohort: tightening the discount on self-financed trades within the airdrop scoring methodology, not adjusting any per-collection display metric.
  • The cohort persists across reward-formula tightening but at decreasing share. The pattern across Blur's seasons is that each formula adjustment reduced the per-cluster yield of incentive-wash farming but did not eliminate the cohort. This is structurally consistent with the T12.001 framing: the on-chain artefact is detectable, the formula adjustment makes the activity less profitable but does not change its detectability, and a residual cohort persists at the level where the marginal yield still exceeds the operational cost of running the wash trades.
  • Volume migration to Blur was parallel to (not driven by) incentive-wash. The cohort framing should not collapse Blur's overall Ethereum NFT volume share growth into the wash-cohort dynamic. Genuine pro-trader volume (pool bidding, professional liquidity provision, aggregated execution) accounted for a substantive share of Blur's volume growth across the same window. The cohort observation is that a meaningful fraction of Blur's airdrop-incentive-window volume was wash, not that all of it was. Public forensic estimates clustered at the multi-tens-of-percent level during peak airdrop windows, with significant uncertainty in the per-percent attribution depending on the cluster heuristic used.
  • Cross-marketplace comparison is the load-bearing context. OpenSea's wash-trade share across the same window was lower than Blur's (per Hildobby and NFTGo), and the LooksRare and X2Y2 incentive-wash episodes of 2022 had per-marketplace wash rates reaching the ~94.5% (LooksRare) and ~84.2% (X2Y2) levels documented in industry studies for those windows. The Blur cohort sits between OpenSea (low wash share, no incentive program) and the LooksRare / X2Y2 2022 incentive episodes (extreme wash share under naive incentive formulas). Blur's better-than-LooksRare-2022 share reflects the iterative scoring adjustments; the worse-than-OpenSea share reflects the residual incentive-cohort yield even under the adjusted formulas.

What this example tells contributors writing future Technique pages

  • T12.001 incentive-wash sub-motivation is empirically distinct from price-discovery-distortion wash. Future T12.001 contributions should preserve the distinction. The on-chain artefact overlaps but the operator goal differs (token-reward extraction vs third-party-buyer attraction), the Mitigation owner differs (the marketplace's reward formula vs the marketplace's display logic), and the cohort dynamics differ (persists under formula adjustments but at decreasing share, vs episodic per-collection bursts followed by real-buyer exit).
  • Marketplace-acknowledgement is a strong attribution anchor for incentive-wash cohorts. Blur's public communications across its seasons explicitly framed scoring adjustments as responding to incentive-wash farming. This is the strongest available evidence tier for incentive-wash cohorts short of named-operator attribution, and contributors writing future incentive-wash worked examples should treat marketplace-acknowledgement-of-the-dynamic as the primary attribution anchor at the cohort level.
  • Per-cluster wash-trade-rate metrics in NFT analytics platforms are the load-bearing defender practice. Hildobby Dune dashboards, NFTGo wash-trade reports, CryptoSlam's wash-adjusted volume index, and bitsCrunch's per-collection wash metrics are the defender-side instruments for tracking T12.001 cohorts. Contributors writing the v0.x Mitigation entries for T12.001 should treat standard NFT-analytics wash-adjusted volume + per-cluster wash-trade-rate metrics as a discrete first-class Mitigation alongside marketplace-side per-cluster reward-formula caps.
  • The cohort framing generalises to other incentive-program marketplaces. LooksRare (2022) and X2Y2 (2022) are the historical antecedents in the same Mitigation-class but under more naive reward formulas. Future incentive-program-launching marketplaces (across NFT, perpetuals-DEX, points-program contexts) should be expected to face the same cohort dynamic, and the Mitigation surface (per-cluster discount in the reward formula) is portable across the venue class.

Public references

  • [hildobbynftwash] — Hildobby's Dune dashboards on per-marketplace and per-collection NFT wash-trade rates including Blur airdrop windows.
  • [nftgoblurwash2023] — NFTGo wash-trade analysis for the Blur Season 1 / Season 2 windows.
  • [cryptoslamwashindex] — CryptoSlam wash-adjusted volume and per-collection wash filtering methodology.
  • [blurseason1airdrop2023] — Blur public communications on the Season 1 airdrop distribution and methodology context.
  • [chainalysis2022nft] — primary NFT industry retrospective; cohort-scale framing for the broader T12.001 surface.
  • [blurzeroroyalty2022] — Blur launch documentation including the recommended-minimum 0.5% royalty default and customisable-royalty mechanism.

Citations

  • [hildobbynftwash] — Hildobby Dune dashboard cohort-level wash-trade rate analysis across marketplaces.
  • [nftgoblurwash2023] — NFTGo Blur Season 1 / Season 2 wash-trade analysis.
  • [cryptoslamwashindex] — CryptoSlam wash-adjusted volume index methodology and per-collection wash filtering.
  • [blurseason1airdrop2023] — Blur Season 1 airdrop announcement and scoring methodology context.
  • [chainalysis2022nft] — Chainalysis NFT industry retrospective; primary anchor for T12.001 cohort framing.
  • [blurzeroroyalty2022] — Blur launch documentation.

Discussion

The Blur airdrop incentive-wash cohort is OAK's canonical worked example for the marketplace-incentive-driven wash sub-motivation of T12.001. The cohort is empirically distinct from the price-discovery-distortion sub-motivation that anchors the standard T12.001 framing — distinct in operator goal, distinct in Mitigation owner, distinct in cohort dynamics under defender response — but the on-chain artefact and the detection surface overlap, which is why the T12.001 page treats the sub-motivation as a sub-class rather than promoting it to a sibling Technique at v0.1.

The case carries additional analytical weight as the most recent large-scale demonstration of a structural pattern that has recurred across NFT-marketplace incentive programs since LooksRare's 2022 launch: any reward formula that scores gross trade volume or bid activity without an adequate per-cluster discount on self-financed trades will subsidise an incentive-wash cohort. LooksRare 2022 (~94.5% wash share at peak per industry studies) and X2Y2 2022 (~84.2% peak) are the historical antecedents under more naive formulas; Blur's iterative tightening across Seasons 1–3 demonstrates that the cohort yields to formula adjustments but persists at the level where the marginal yield exceeds the operational cost. The Mitigation lesson — apply per-cluster wash-trade-rate caps to airdrop-eligible volume at the reward formula level — is portable across venue class and is the load-bearing v0.x guidance for future incentive-program launches.

For OAK contributors, the cohort framing should not be confused with the per-incident T12.001 worked-example shape that a named collection-level price-discovery-distortion case would take. The Blur cohort is structurally the analogue of examples/2024-10-inferno-drainer-handover.md for the drainer-services category — a service-level / cohort-level worked example that captures a structural pattern across many parallel operators rather than a single named incident with a named victim and a named amount. Contributors writing future per-collection T12.001 worked examples (where a specific named collection's wash-cohort is documented at the per-collection level, with a real-buyer exit at the inflated price as the load-bearing terminal event) should preserve the distinction between the cohort frame used here and the per-incident frame those examples will use.

The case also sits adjacent to the parallel T12.003 cohort documented at examples/2022-11-x2y2-looksrare-royalty-optional.md and examples/2023-08-opensea-operator-filter-sunset.md. The royalty-bypass cohort and the incentive-wash cohort played out in parallel on the same set of marketplaces (Blur, X2Y2, LooksRare) across overlapping windows, but the two are structurally distinct: T12.003 sits at the standard-vs-enforcement gap on royalty payment, T12.001 at the per-cluster wash-trade pattern. Contributors writing future Blur-cohort or X2Y2-cohort worked examples should preserve the boundary explicitly — a single marketplace can contribute to both T12.001 and T12.003 cohorts simultaneously, and the worked-example set should classify each cohort by which Technique-specific defender-control surface the cohort reveals, not by the marketplace it played out on.

Techniques demonstrated (3)