I had one domain stolen from my eNom account. They fixed the loophole* now, but they claimed the loophole was a feature back when the domain was stolen. I had thousands of domains with them. I removed all but a handful of domains from them after that. Which is where it stands today. They refused to file a TDRP.
* The loophole: They retained the old password on domains won at auction. Enabling the previous owner to unlock the domain, get the Auth Code, and transfer the domain away. All done with a phonecall.