A card-testing run is dozens of small checkouts in minutes, most of them failing, from hosting providers and proxy networks. Each one looks like a single shopper to your checkout page. The chargebacks and the processor warnings arrive later.
Fraud tools that score the transaction need the order. By then the attempt has already consumed a payment authorisation. Network context is available earlier: at checkout_view, at payment_attempt, at payment_failed.
Shield puts that context on the checkout flow itself, without ever seeing card data, cart contents or customer fields.