The mempool is where exploits die
Every post-mortem we read ends the same way: the attacker submitted the transaction, the block confirmed, and the funds moved. Detection at that point is archaeology. The interesting question is what was knowable eleven seconds earlier.
What is actually visible
A pending transaction carries its calldata, its sender, and its target. Against current state you can simulate exactly what it will do before it lands. For a drain, that simulation shows value leaving a contract the caller has no claim over. That is a detection, and it is available while the transaction is still replaceable.
What we do with it
Snitch simulates every pending transaction that touches a watched contract. When the simulation moves value the caller is not entitled to, we attach a runnable Foundry proof and sign an alert. What you do next is your call, and that is deliberate: we are read-only and we never touch your keys.
The honest limits
Mempool visibility depends on the node. Private orderflow and builder bundles can hide a transaction until it lands. We watch multiple nodes per chain to reduce the blind spot, and we say so on the features page. No monitoring tool sees everything; the goal is fewer surprises, not zero.