In fact, I appreciate the efforts of the Shadowserver Foundation in depriving Avalanche malware families of their command and control infrastructure by sinkholing the domain names generated by the malware domain generation algorithms. I understand false-positives like this can happen. It comes with the territory. It just sucks that the domain name I was using happened to be a false positive. In this case, it ended well because the Shadowserver Foundation (along with Namecheap) acted quickly on my issue and asked NIXI to have the domain transfer undone.
Having said that, I do believe that you make a very good point. Actions like this should be taken with a lot more care. What if it were not a personal blog but a small business? Depending on the nature of the business, an inadvertent domain transfer like this could have affected the business seriously. The Shadowsecurity Foundation did say that they are improving their processes.
I am not very concerned about this particular foundation when I talk about this. But I am concerned about the systemic issue in the domain name management system that allowed a mistake like this to occur. There could be some type of peer review before a domain transfer like this is executed. I don't think there is a general and popular solution for this problem in the near future. I am hoping that the recent work that is going on in consensus protocols based on cryptography might pave the way to a more decentralized network and more decentralized name management that also become popular and mainstream.