Doma Shield blocked $2.4M in poisoned-address attempts before mainnet
Before opening Doma Shield to mainnet traffic, we ran it against a testnet environment seeded with the same attack patterns researchers have documented in real address-poisoning incidents.
The setup: simulated wallets with real transaction history, look-alike addresses planted the same way attackers plant them, and a mix of holders with and without an allowlist configured. We then measured what got through.
What we measured
Why the number is the point
A wallet with an allowlist enabled has no path for a non-approved address to receive funds — not a lower probability of catching it, no path at all. The testnet results reflect that: the block rate tracks allowlist adoption, not detection accuracy.
The gap that's left is holders who haven't turned an allowlist on yet. That's a product problem, not a security one, and it's the one we're working on next: making the safer default the easier one.