[24 JUL 2025] SECURITY
Doma identified a drainer contract days before it went viral
TEAM DOMA, SECURITY
One policy engine. Every transaction checked.
SHARE
Wallet-drainer losses fell 83% in 2025 because pre-sign protection works — it catches the pattern before the first victim signs, not after the thousandth.
In this case, a Doma user was asked to approve an “unlimited” spending allowance to a newly deployed contract, framed as a routine step in claiming an airdrop. Transaction Shield flagged it before the signature: an unbounded approval, to a contract with no transaction history, requesting access to a token with real value.
The timeline
Day 0 — flagged as high-risk, unlimited approval
→Day 4 — approval blocked for Doma users
→Day 7 — same contract drains wallets elsewhere
What made it catchable
- ▸An approval request with no explicit spending cap
- ▸A destination contract deployed days earlier, with no prior activity
- ▸A request framed around urgency — a claim window, a limited-time airdrop
None of these signals alone proves malicious intent. Together, on a contract with zero track record, they're exactly the pattern Transaction Shield is built to catch — and cap, before a single signature turns into an unlimited one.
Never miss new content