Blockchain tokenomics is the protocol's monetary and incentive design for running a secure, open network against attackers who can buy, borrow, or fork. The token pays validators, penalizes misbehavior, and funds the cost of keeping the chain hard to capture. Unlike app-layer token design, consensus rules make it slow and political to change, so the hard part is making something that still holds up across cycles.
Why L1 tokenomics is not app tokenomics
A blockchain's tokenomics is not an add-on to a chain that already works. It is part of the security model. At the application layer I can usually change rewards, pricing, and permissions without risking the underlying network. At the base layer I cannot, because the incentive schedule is what makes the network hard to attack in the first place.
That constraint reshapes almost every design choice. Consensus rules are rigid by design, and changing them takes a network-wide upgrade plus social coordination, which is slow and politically expensive. Issuance schedules, fee rules, and slashing conditions function as credible commitments the moment they ship. If those rules turn out to be extractive, users and developers can coordinate around a fork, a competing chain, or an L2 that absorbs the activity (credible exit is always part of the threat model, even when it doesn't fire). And the participants are adversarial by default: validators, block producers, relays, searchers, and wallet operators will all do whatever is most profitable given the rules.
In practice, L1 token design often becomes a multi-constraint elimination problem before any mechanism gets modeled. Our work on Midnight's $DUST resource token, for example, started with nine hard constraints and eliminated four of five candidate acquisition mechanisms before the economic modeling began. That level of constraint density is typical at the L1 layer.
The useful way to frame L1 tokenomics is that your consensus assumptions become economic assumptions. "Honest majority" only holds if the economically rational majority is aligned with honesty, including when attackers can buy, borrow, or bribe stake. For how these same questions look at the application layer, where the design surface is wider and the stakes per decision are smaller, see our piece on tokenomics design 101.
The security budget: who pays for making the chain expensive to attack
A chain has to pay every day to stay expensive to attack, and there are only three places that payment can come from: newly issued coins, transaction fees, or extracted value that participants take on top of the first two. The mix changes what the chain is, not just how much it costs. Each leg has a different demand side, a different political cost, and a different failure mode when volume drops.
Bitcoin's design is explicit on the mechanism in the original whitepaper: block producers are compensated by new issuance plus fees, and the long-run direction is for security funding to transition to fees as the subsidy tapers toward zero. That makes the fee side load-bearing in a way that hasn't been stress-tested yet. If average fees don't cover hashrate cost-of-capital once the subsidy is negligible, the security budget contracts or holders accept perpetual inflation. Either outcome contradicts something the chain was supposed to guarantee.
Ethereum chose a different mix. Under PoS, validators post ETH as collateral, earn issuance plus priority fees, and can lose stake to slashing for dishonest behavior. EIP-1559 added a base fee that is burned, which turns fee revenue into partial deflationary pressure rather than validator income. Post-Merge, energy use dropped by roughly 99.95% and issuance settled well below the PoW-era rates. Around 29% to 31% of ETH supply is now staked across roughly 1.1 million validators, with base APY in the 3% to 4% range depending on priority fees and the staking ratio.
The practical question is who pays, and when. Funding security mostly through issuance dilutes holders and creates persistent sell pressure on whatever portion of rewards gets liquidated. Funding it mostly through fees raises user costs during congestion and pushes activity to L2s or cheaper alternatives (Ethereum sits in exactly this position post-blobs: most user activity happens on rollups and L1 fees are increasingly a blob market). Which means the demand-side drivers of the token's price determine how much sell pressure the security budget can absorb before something breaks.
MEV: the third revenue stream that reshaped the model
MEV (maximal extractable value) is the value a block producer can capture by controlling transaction ordering, inclusion, and censorship on top of the issuance and fee payments. The Flash Boys 2.0 paper documented the systemic version in 2019: arbitrage, liquidation, and sandwich bots running priority-fee auctions, with priority-fee mechanics capable of destabilizing consensus. What looked at first like a DeFi nuisance turned out to be a structural change in who earns the security budget and how.
Post-Merge, Ethereum moved most of the MEV flow through Flashbots' MEV-Boost and proposer-builder separation (PBS). Around 90% of blocks are now built by external builders who submit through relays, and the arrangement is meant to democratize access to MEV while sparing validators from running extraction infrastructure themselves. In practice, two to three builders consistently produce 80% to 95% of blocks, and at peak periods nearly half of blocks have been produced through relays that enforce OFAC-style compliance. Builder concentration is where real centralization lives now, not in the validator set.
The protocol response is enshrined PBS (ePBS, EIP-7732), which would bring the auction on-chain and remove the trusted relay. I think it helps at the margin, but it does not erase the underlying pull: whoever has the best private order flow wins blocks, builds a bidding reserve, and consolidates the market from there. Protocol design can shape that dynamic (inclusion lists, MEV burn, enshrined timing rules), but it cannot cancel the economic gravity of specialized ordering.
What MEV means for tokenomics: the security budget is now funded partly by users losing value to ordering, not just by holders absorbing issuance or paying fees for service. When MEV rises as a share of validator revenue, cutting issuance feels cheap. When it falls, cutting issuance becomes a problem. A security budget that leans on MEV is strategy-dependent and cyclical, which is not the same as funded.
What scales, what concentrates
The blockchain trilemma shows up directly in validator economics. Higher throughput and lower latency raise hardware, bandwidth, and uptime requirements, which push the validator set toward professional operators, data-center deployments, and delegation to large intermediaries. Tokenomics can partially counterbalance that (subsidizing small validators, smoothing reward variance, lowering minimum stake), but it cannot cancel the physics of coordination at scale.
Ethereum's actual stake distribution shows the pattern. Lido sits around 24% of staked ETH, down from above 32% a few years ago as competition and social pressure on single-operator dominance pushed flow toward other LSTs and solo stakers. Coinbase, Figment, Kraken, and a few other operators each hold low-single-digit shares. The Pectra upgrade in mid-2025 raised the maximum validator balance from 32 to 2,048 ETH, which was a usability win for large operators but quietly reduced the number of independent signing keys in the active set. A 29% to 31% staking ratio makes the network more economically secure per unit of attack capital, but it does not automatically translate to more distributed control.
Restaking is the newest version of the same question. EigenLayer lets stakers pledge ETH to secure additional protocols (AVSs) in exchange for extra yield, and before slashing went live in April 2025, TVL peaked near $28 billion on points-farming alone. Once real slashing conditions activated, TVL contracted to the $7 billion range, then recovered into the $8 to $19 billion band depending on the reporting window. The honest read is that restaking is a real primitive for bootstrapping new networks, but it also couples their failures back to Ethereum's validator set. For a cleaner view of how hardware-coupled networks handle the same decentralization tradeoffs with different constraints, the patterns in DePIN tokenomics are close cousins.
Evaluating L1 tokenomics without hand-waving
If I am reviewing an L1 design or writing an investment thesis against one, these are the questions I keep coming back to. None has one correct answer. Each has a cheapest-plausible-attack and a cheapest-plausible-collapse that the design either prices in or ignores. On live engagements I work through these with a scored constraint matrix on the design space and Monte Carlo simulation on the parameters. Both force the conversation off narrative and onto which mechanism survives which pressure.
- Security budget across cycles. Where does the payment for security actually come from across a full market cycle: issuance, fees, MEV, or a mix? What happens if one of those legs drops by 70%?
- Decentralization forces. What pushes stake, hashpower, or block-building toward concentration, and what counter-incentives exist in the protocol itself (not in social pressure, which is not a mechanism)?
- Attack economics. What is the cheapest credible attack on the chain (reorg, censorship, governance capture, validator bribery), and how do rewards, penalties, and MEV change the price of that attack?
- User cost and demand destruction. How do fees behave under sustained load, and at what point do users leave for an L2 or a competitor? Does the fee regime still fund security after that migration?
- Credible commitment. Which parts of monetary policy are truly hard to change, who has the formal or informal authority to change them, and what is the cost of breaking the commitment?
I have reviewed many L1 pitch decks whose tokenomics answer is "the token captures value from network usage." That is not an answer. It is a placeholder where the answer is supposed to be. The useful version is a table of who pays, how, and what breaks if the token price drops 80% while volume halves. Across the L1 and infrastructure projects in our portfolio, the cleanest ones had that table worked out before the whitepaper shipped.
