So later I will put your theory to the test and process each list together for duplicates. I will generate my own ip list doing the wc before and after.
The following table is copied directly from: https://github.com/firehol/blocklist-ipsets
A firewall blacklist composed from IP lists, providing maximum protection with minimum false positives. Suitable for basic protection on all internet facing servers, routers and firewalls. (includes: bambenek_c2 dshield feodo fullbogons spamhaus_drop spamhaus_edrop sslbl ransomware_rw) | ipv4 hash:net | 2094 subnets, 613957376 unique IPs | updated every 1 min | |
An ipset made from blocklists that track attacks, during about the last 48 hours. (includes: blocklist_de dshield_1d greensnow) | ipv4 hash:net | 15225 subnets, 28990 unique IPs | updated every 1 min | |
An ipset made from blocklists that track attacks, spyware, viruses. It includes IPs than have been reported or detected in the last 30 days. (includes: bruteforceblocker ciarmy dshield_30d dshield_top_1000 malc0de maxmind_proxy_fraud myip shunlist snort_ipfilter sslbl_aggressive talosintel_ipfilter vxvault) | ipv4 hash:net | 17878 subnets, 30610 unique IPs | updated every 1 min |