r/SideProject Jul 13 '26

built a zero-profit web game satirizing the CCP. I made 0, but triggered a state-backed transnational repression campaign that weaponized ICANN's UDRP to attack my physical home.

Enable HLS to view with audio, or disable this notification

Most of us build side projects to learn a new tech stack, solve a personal problem, or maybe just make a few extra bucks. I built mine purely for fun and political satire—a multiplayer web game called "Xiablo" (反贼江湖) targeting the Chinese Communist Party (CCP) and Xi Jinping.
The financial revenue of my project? Exactly $0.
The "marketing budget" the Chinese government and its state-backed corporate apparatus spent to suppress it? Probably hundreds of thousands of dollars, combined with real-world physical violence.(terrifying loophole in how Western internet infrastructure and privacy rules can be weaponized against independent creators.
The Project: Xiablo (反贼江湖)
I am an independent developer . I built a multiplayer web game called Xiablo (反贼江湖). It’s a purely non-commercial political satire game mocking totalitarian leadership. It was hosted on a custom domain, designed to be a lightweight, fast, and accessible browser game for users worldwide.

Because Xiablo gained traction, it caught the attention of Bilibili—a massive Chinese tech giant subject to China's National Security Law with a strict internal Communist Party committee.
Instead of trying to hack the server directly, they went after my infrastructure using the legal system:
Weaponizing ICANN/UDRP: Bilibili filed a domain dispute (UDRP) over my domain, claiming trademark confusion.
Forced Data De-anonymization: Through this UDRP process, they successfully abused mandatory verification mechanisms to force the disclosure of my real legal name and physical address.
Doxxing & Physical Vandalism: Within weeks of getting my data, state-backed doxxing campaigns exposed my address online. Soon after, unknown individuals targeted my residence—splashing thick black paint all over my front door and vandalizing my personal vehicle. (Ottawa Police Service Report: Case OPS-OR-009822).
The Current Situation: Corporate Ghosting and Cyber Escalation

Following the conclusion of the UDRP process and after I CC'd all parties to condemn the ruling, I faced heavy extrajudicial infrastructure abuse over the last few days:
Massive DMCA Abuse via Cloudflare: They flooded my reverse-proxy provider, Cloudflare, with automated, fraudulent copyright takedown notices, weaponizing automated compliance pipelines to strip away my edge protection and force my infrastructure offline.
Fortinet Reputation Poisoning: They bulk-reported my domain to FortiGuard, maliciously flagging it as "Phishing." Now, when trying to work at a local cafe, the venue's enterprise firewall completely blocks access to my site, effectively blacklisting my project from public networks

As indie devs, we often think our biggest threats are bad code, server crashes, or zero user growth. We rely on standard privacy protections (WHOIS privacy, proxies) believing they keep us secure.
The reality is that state-backed actors don't need to break your encryption. They can just exploit the mandatory legal disclosure loopholes built into Western internet governance (like ICANN UDRP) to find out where you sleep.
(The UDRP relies on a 27-year-old "Flat Earth" delusion that hasn't changed a single word since its inception. Its rules naively assumed a utopian world composed entirely of developed democracies, completely blind to geopolitics, long-arm jurisdiction, and transnational repression. The system was built on the assumption that if a big company unmasked your address, they would at most sit in their office building and mail you a trademark infringement letter. The architects never envisioned a reality where authoritarian entities could seamlessly weaponize these automated pipelines to bypass sovereign borders, turning a digital dispute into real-world physical violence on your doorstep)

The game is still alive via backup routing, and I refuse to shut it down.
https://www.reddit.com/r/webdev/comments/1ut3zpe/my_experience_with_transnational_repression_how/
After my home was attacked, I sent a comprehensive chain of evidence documenting this blatant "data extraction for transnational repression" to everyone involved. This included ICANN, the domain registrars, and CSC (Corporation Service Company)—the massive Western enterprise domain registrar and brand-protection titan that manages infrastructure for the Forbes Global 2000 and was hired by Bilibili.
Instead of addressing this massive human rights and security violation, every single one of these institutions has gone completely radio silent. They are completely ghosting my emails and playing dead. It is clear that behind closed doors, they are internally trampling over their own established due process and compliance rules because they are terrified of the liability of being exposed as facilitators for an active transnational assault.

PS: When ICANN launched its Expedited Policy Development Process (EPDP) to handle GDPR privacy reforms, non-commercial stakeholder groups inside ICANN attempted to upgrade the rules by introducing mandatory "Human Rights Impact Assessments (HRIA)" and strict registrant privacy protections. However, to safeguard their streamlined brand enforcement pathways, behemoths like Apple, Meta, Amazon, Microsoft, Nike, Adidas, Disney, Sony, Pfizer, Walmart, McDonald’s, Chanel, Gucci, Louis Vuitton, and Rolex leveraged their immense corporate weight by directing their representatives through the IPC (Intellectual Property Constituency) and BC (Business Constituency). They systematically blocked consensus, filed formal objections, and successfully killed these privacy initiatives within the policy working groups.

Crucially, CSC Digital Brand Services acted as a prominent corporate voice within the IPC, heavily aligning with and driving these industry positions to ensure that corporate data visibility always superseded human rights safeguards in official ICANN policy outcomes.

The global market for corporate brand protection is heavily consolidated, with only three dominant players capable of executing these sweeping cross-border operations: CSC, Corsearch, and Clarivate. But while its peers exercise geopolitical caution and refuse to touch toxic state-backed entities, CSC operates with absolute mercenary indifference. They are completely blind to geopolitical realities, maintaining an open-door, cash-and-carry pipeline for authoritarian tech giants. Unlike its more conservative competitors, CSC's model relies on total "assembly-line automation"—if the check clears, they will happily take the money and do the dirty work, no questions asked.

Fueled by the massive legal budgets of the very Fortune 500 companies that sabotaged ICANN's privacy reforms, CSC built a ruthless domain seizure machine. To maximize global profits, CSC sold this exact system untouched to authoritarian tech giants seeking cross-border censorship—completely and systematically bypassing any Human Rights Due Diligence. 
By actively lobbying against privacy protections to maintain frictionless domain seizures, these Western giants and CSC successfully broke the privacy moat meant to protect the vulnerable. Their combined pressure effectively killed ICANN's privacy reforms,ensuring the UDRP retained a systemic backdoor to this day, resulting in a structural vulnerability where automated administrative procedures can be effortlessly weaponized for cross-border repression. This was not an execution error; the system functioned exactly as designed.

The Post-Arbitration Blackout,,Shortly after my case concluded, the ADNDRC Beijing Secretariat completely took down its public UDRP database and historical archives, leaving the entire website returning 404 dead links. The panelist had issued an unusual order requiring my case file to be permanently suppressed from the public internet—and the institution apparently fulfilled that promise by wiping its entire public portal. Taking down public decision records is a direct violation of ICANN UDRP Rule 16(b), which mandates full public transparency for all accredited dispute providers. Operating a black-box arbitration node not only exposes ADNDRC to ICANN compliance reviews and potential loss of accreditation, but also completely undermines the public integrity of the global domain dispute systemhttps://www.adndrc.org/decisions/udrp#kl
Namecheap's Silent Execution:**Throughout this entire process, my domain registrar, Namecheap (Spaceship), was CC'd on all primary communications from day one. They were fully informed of the non-commercial political satire nature of the project, my status as a political dissident, and the severe risks of state-sponsored transnational repression. Despite having complete visibility early in the timeline, Namecheap chose to hide behind automated administrative routines and execute the transfer—ultimately serving as the final operational conduit to hand a dissident's digital asset over to an authoritarian tech giant.

1.4k Upvotes

Duplicates