In Franz Kafka’s The Trial, Josef K. wakes up one morning to discover that he has been arrested. Nobody will tell him what he’s done or seems capable of explaining who is ultimately in charge. He spends the rest of the book moving through an opaque system of officials, offices, procedures and intermediaries, each apparently connected to the machinery of justice but none possessing either the authority or inclination to resolve his situation.
I thought about Kafka a lot over the last week. Because I woke up one morning and discovered I had apparently become part of a cryptocurrency trading company.
On their About page was my name, my photo and enough of my professional identity to make it look as though I was part of the team behind a platform I had never heard of before that day. I also had some amazing new colleagues on the team: a venture capitalist, a professor, and a dead man.
And that was only the beginning.
I. The Summons
I am, for want of a better description, a semi-public person. I publish what I write on a public blog. I speak at conferences. I have a podcast. I talk a lot about software testing, technology and AI and have spent enough years publishing things on the internet that finding my photograph, job history or biography requires roughly the investigative skills of typing my name into Google.
The website I discovered was called CoinStacker.com. It presented a team consisting of Ted Maidenberg, Silvio Micali, Jim Simons and me as “experienced traders, data scientists, and software engineers dedicated to democratizing algorithmic trading.”

Meet the team!
With those high-powered Googling resources at hand, I found out that Ted is a venture capitalist in California, Silvio is a professor at MIT, a Turing Award winner and one of the founders of Algorand and Jim was one of the most famous quantitative investors in history – Jim also died in 2024.
My initial reaction was thinking it must have been some kind of joke.
I had never worked for CoinStacker. I had never advised CoinStacker. I had never invested in CoinStacker. I had never endorsed CoinStacker. I had absolutely never given anyone connected to CoinStacker permission to use my photograph, biography, professional reputation or anything else.
But the funny part faded quickly as reality set in, because your reputation is one of those things you spend decades building and these days someone else can borrow to shill dodgy crypto hacks in minutes. So, I did what I have spent a large part of my software quality career telling people who work in highly regulated industries to do when something strange happens in a system.
Start gathering evidence.
Before sending angry emails, before contacting anybody, before trying to make anything disappear, I took screenshots. I saved the website. I recorded the URLs. I captured the names, photographs, contact information and claims being made which turned out to be rather important.
Because CoinStacker was just the start.
II. Before the Law
I (wrongly) assumed getting my identity removed would be straightforward. Find whoever runs the website. Tell them what has happened. Ask them to remove it. But predictably, the support email published by CoinStacker bounced and no one answered from their Facebook or WhatsApp either. So, I started reporting things to the various providers: Facebook, Google, then found their registrar NameSilo and contacted them who explained they were just the registrar and did not control the website.
Fair enough.
So, I looked up the DNS records. Then the IP address. Then the network operating the address. That took me to Cogent who eventually told me the IP had been leased to a downstream organization called Fairchild Imagination.
That was another dead end, so I reported the site to the UK National Cyber Security Centre and because other real people were being represented alongside me, I contacted them or organizations associated with them. I contacted the Simons Foundation. I contacted Silvio Micali. I contacted MIT CSAIL communications. I contacted Ted Maidenberg and his company.
I was beginning to feel like K trying to clear his name navigating a system operating entirely outside normal rules. Nobody was necessarily doing anything wrong by explaining the boundaries of their responsibility or what that organization can and cannot do. But no one could answer my simple request: Could somebody please stop this website telling people I work there?!?!
And this was beginning to consume serious amounts of my time and mental energy.
I was spending hours tracking things down, taking screenshots/PDFs, looking up WHOIS records, running DNS queries, identifying IP addresses, reading abuse policies, drafting formal notices, recording ticket numbers, preserving email chains, checking websites again, contacting affected people and maintaining a chronology of what had happened.
It was becoming death by a thousand cuts, and then I found another website.
III. The Case Expands
Through the course of my research I found that CoinStacker.com had a clone site operating under the name Coin-StackerPro.com. It looked exactly like CoinStacker with all the same claims, contact details, fake supporters and team members. After digging through the details of trying to shut down Coin-StackerPro or at least get my image removed, I discovered there was ANOTHER website slinging the same garbage.
The third site was aicoin-pros.com. They had the same layout, claims, and propositions with my same imaginary teammates. So, I did some deeper searching and found coin-quant.com, but this time whoever had built the page had used different photos of us. The new photos suggested that somebody, somewhere, went looking and didn’t just clone the other sites, and then finally I found ai.coin-quant.com.
All these sites used the same branding, same general material, and same use of my identity in an AI enhanced virtual whack-a-mole game I was being forced to play to get the crypto influencer body spray stink off of me.
Three of the parent domains turned out to be registered through NameSilo. CoinStacker and CoinQuant shared DNSOwl infrastructure. coin-quant.com and ai.coin-quant.com resolved to the same IP address. Both returned the same server characteristics. That network traced to Evoxt while another site involved Cloudflare, so they both got abuse reports as well.
What began as “someone is using my photograph” had become something resembling a small digital forensics exercise across at least FIVE sites and their providers.
And then someone on the other side actually replied.
IV. The Interrogation
I had sent formal notices explaining to all the websites using my identity that they were doing so without my authorization or consent, but only aicoin-pros.com engaged with me. It started out reasonably with them saying they took the issue seriously and would investigate by checking whether my identity had appeared on their website or promotional material and remove or correct it if appropriate.
I thought I’d finally found the person who knew where the courthouse door was.
Then they asked for my “AI bot account information” so they could verify me before removing my details, small problem was that I had never heard of their company until discovering I apparently worked for it. I explained that I would not provide account credentials, wallet information, security information or anything else, and that removal of an unauthorized use of my identity obviously could not depend on verification of an account that did not exist.
Then they asked where I had obtained the information about myself appearing on their website.
Ummmmmm. From. Your. Website.
Eventually they asked for evidence so I sent screenshots, PDFs and the links to their own website and you wouldn’t believe this if I didn’t have the emails, but they then claimed that was not their official website, and somebody was impersonating THEIR platform. But strangely, the email they were replying from was the email address published on the supposedly unofficial website.
After another day of back-and-forth (they even warned me that their legal team might pursue action if I was “deliberately making false and defamatory claims against us” for pointing out that my photo was on their website), I eventually received a vague response saying they would report the issue and get it taken care of as soon as possible.
After a couple days though, that same website that had just told me the other site was not theirs emailed me that they had investigated further and found ANOTHER website – coinquantbot.com – which, according to them, was ALSO using my information. They said that site had copied material from their CoinQuant website and suggested I contact it as well.
And yep, there was another one – same site, same branding, and same fake team making the running total of six sites using my name and image to sell crypto crap.
I got no notice. I have no idea who changed it or why. But after another day, my now regular check on the sites found that everything else was the same but mine and my fake colleagues’ photos (Ted, Silvio, and dearly departed Jim) were gone from aicoin-pros.com. CoinStackerPro and CoinStacker sites seem to be entirely down for who knows why and at the time of writing, coin-quant, ai.coin-quant, and now coinquantbot.com still have our details displayed. I can’t tell you if any change was caused by the operator, the hosting chain, one of my complaints or simply a technical problem.
It would be tempting to claim victory and say somebody took something down because of my reports, but the evidence does not establish that and the distinction is important.

Statue of Kafka (D. Černý)
V. Judgement
There is an obvious cautionary tale here about the democratization of technology. We have spent decades making enormously powerful and sophisticated technical capabilities more available to ordinary people.
I think the jury is still out on whether that was a good decision.
Because democratization of a capability does not discriminate between people who do things we like with it and benefit society and the ones cloning dodgy crypto businesses. And in the age of AI, I guess you no longer need to steal somebody’s identity when you can just reconstruct a version of them from public fragments.
But as we know from living in the Matrix, “fate, it seems, is not without a sense of irony”, so as the size and scale of what was going on became clear, I have to admit I used AI to fight back.
If you know anything about me or what I have been writing about for the last couple of years, you’d know I am as heavy a GenAI sceptic as they come. To be clear: I see nothing in it to justify its unethical creation, damage to people/communities/business, danger to the world economy, or general harm its released on society.
But it did help me organize the investigation, maintain the chronology as the number of websites and organizations increased, interpret domain registration information and network records, structure abuse reports and formal notices, and reconcile dozens of pieces of evidence and identify gaps at a pace I could not have done myself.
But there is an enormous qualifier attached to all of that.
I know enough to know not to trust it. I’ve spent much of my career dealing with testing systems, evaluating behavior, and reporting on risk to know that something looking suspicious does not magically turn into good evidence. It also took a LOT of time reviewing everything it “extruded”, because it often got it wrong on the first (and sometimes second and third) pass.
Without my judgement, AI could just as easily have helped me confidently engineer very convincing nonsense or overstate/obfuscate the issues making the situation worse. But with my hard earned professional eye it allowed me to work through a problem much faster than I could have done alone. None of changes that fact that I also completely agree with Ed Zitron statement that “LLMs are interesting and their cost is inexcusable“.
VI. The End
Nothing tied up neatly and in fact this is still ongoing. No mastermind has been unmasked, and I still can’t tell you whether or not all these sites were operated by the same people. But the position today is different from the one I woke up to on day one: CoinStacker and CoinStackerPro are currently inaccessible and the team material containing my identity has disappeared from aicoin-pros.com.
The remaining CoinQuant sites have been reported to their registrar and infrastructure provider, and the NCSC has the reports on all of them. I also notified the other people and organizations whose identities appeared alongside mine, including the YouTube crypto creators whose names were presented as CoinQuant influencers.
But this does raise a question that I think more of society will be wrestling with as AI increasingly invades our lives: What happens when this is done to somebody who doesn’t know how to fight back? I knew how to start working the problem and have access to professional networks and resources, but even with all those advantages, this consumed several days of time and is STILL not completely resolved.
Obviously I know I’m not the only person having to deal with this either, an IBM “Cost of a Data Breach” report from 2026 stated that “AI-driven attacks, led by AI deepfake impersonations and AI-enabled malware” were responsible for an over 50% increase in those types of incidents.” CNBC reported that according to the Identity Theft Resource Center, in the first half of 2026, “there were 1,803 reported data compromises”, but predictably the burden of prevention and fixing identity theft falls almost entirely to the one with the stolen identity.
We’re making the cost of creating things near zero but keeping the price of consequences enormous.
And in this new AI era, while technology is dramatically reducing the effort required to manufacture bullshit, the effort required for the person on the receiving end to prove that it’s false remains Kafkaesquely human.
Appendix: What to do if this happens to you (what I did)
- The first thing I would do is preserve the evidence before contacting anybody. Take screenshots showing the URL. Save the entire page or website as a PDF. Record the date and time. Capture contact details and any statements associating you with the organization. Websites can change very quickly once somebody realizes they have been noticed.
- Then identify who sits behind the domain. WHOIS and RDAP searches can tell you the registrar and nameservers. The registrar will normally have an abuse-reporting process. If privacy protection is being used, there may also be a forwarding address through which you can notify the registrant.
- If the registrar cannot act on the website content, identify the infrastructure. DNS tools can show you the IP address. IP WHOIS services and regional registries such as RIPE or ARIN can help identify the network responsible for it. That network or hosting provider should have an abuse contact.
- Send the website operator a clear written notice stating exactly what is being used without permission and what you want removed. Keep the language factual. Do not embellish what you know. Preserve both your message and anything they send back.
- Do not give unknown website operators passwords, financial information, account credentials, security codes, identity documents or other sensitive information merely because they say it is necessary to “verify” your complaint.
- In the UK, the National Cyber Security Centre provides a suspicious-website reporting service. Social platforms and search providers also have abuse-reporting mechanisms when the site is being promoted through their services. Depending on what has happened, professional legal advice or reporting to other appropriate authorities may also make sense.
- If other real people are being represented alongside you, consider telling them. Do not assume their involvement is also unauthorized; simply show them what you found and allow them to determine that themselves.
- Most importantly, maintain a chronology. Once you have several domains, half a dozen organizations and multiple email threads, memory stops being reliable very quickly. Record what you found, when you found it, what you reported, who replied and what subsequently changed.
Resources
- ICANN Lookup – registrar and domain registration details
- RIPE Database – IP/network ownership for RIPE-region addresses
- ARIN Whois/RDAP – IP/network ownership for ARIN-region addresses
- WhoIsHostingThis – quick hosting-provider lookup
- NameSilo Abuse Reporting – example of a registrar abuse process
- Cloudflare Abuse Reporting – if Cloudflare is involved
- NCSC — Report a Suspicious Website – UK suspicious-site reporting
- Google Safe Browsing reporting – reporting malicious or deceptive sites to Google
Discover more from Quality Remarks
Subscribe to get the latest posts sent to your email.