
An 18k-Star Open Source Project Got Destroyed by a Fake Site: Is SEO Dead, or Did Google Change?
Hi everyone, this is Neo.
Anyone working on independent sites or SEO has probably been following a jaw-dropping case lately.
A top-tier open source project with 18,000 GitHub stars actually lost in Google search results to a sloppily-built knockoff website.
This isn’t just an SEO incident — it’s a cautionary tale about brand protection, search engine algorithm flaws, and the reality indie developers live in.
Today, let’s do a deep postmortem of this event, now known as the “NanoClaw Paradox,” and see what bloody lessons it holds for those of us running overseas independent sites — operators and owners alike.
01 What Happened: The Real Deal Got Outplayed by a Scraper
The protagonist is Gavriel Cohen, a former senior developer at Wix.
In early February 2026, he launched NanoClaw, an open source AI agent platform built around security.
The project took off fast:
- VentureBeat covered it.
- The Register interviewed Cohen.
- AI heavyweight Andrej Karpathy publicly praised its architecture.
- GitHub stars quickly passed 18,000.
But while Cohen was busy writing code and building the product, someone slipped through the cracks.
Around February 8, a speculator registered nanoclaw.net and scraped the README straight off GitHub, generating a junk site full of ads.
Cohen hadn’t set up an official website yet, because in his mind, the GitHub repo was the project itself.
Two weeks later, when Cohen finally got around to it, he launched a polished official site at nanoclaw.dev and ran a standard set of SEO plays:
- Added the site link to the GitHub repo.
- Configured schema markup.
- Submitted to Google Search Console.
- Sent DMCA takedown notices to Google and Cloudflare.
And the result?
As of March 5, searching “NanoClaw” on Google still put the fake nanoclaw.net at #1. The legitimate site couldn’t even crack the first few pages.

Neo’s take
This is a textbook case of “bad money driving out good.” But in SEO terms, it exposes a deeper problem: Google’s algorithm may be too rigid in how it treats “new sites” versus “old sites.”
Even though the real site had elite authority signals (GitHub, top-tier media backlinks), its domain was registered just two weeks later — and it got ground into the dirt because of it. For technical teams that focus on the product and neglect marketing, that’s a brutal wake-up call.
02 Why Did This Happen? Did Google’s Quality Logic Collapse?
Google’s official spokesperson John Mueller once said: “If copied content persistently outranks the original, that may indicate a site quality issue.”
The NanoClaw case directly contradicts that.
Let’s compare the two sides:
| Dimension | Official Site (nanoclaw.dev) | Fake Site (nanoclaw.net) |
|---|---|---|
| Content quality | Original, accurate, up to date | Scraped, outdated, full of ads |
| External links | CNBC, VentureBeat, GitHub | Unknown (mostly spam links) |
| Social signals | Founder’s Twitter, Karpathy’s endorsement | None |
| User experience | Excellent, no ads | Poor, wall-to-wall ads |
| Domain age | Newer (2 weeks later) | Older (2 weeks earlier) |
The conclusion is obvious: Google’s algorithm completely failed in this case.
Even more interesting: Hacker News users tested this and found it wasn’t just a Google problem.
- DuckDuckGo: Fake site at #1, real site nowhere to be found.
- Bing: Fake site at #1.
- Kagi: Fake site at #3.
Only Mojeek correctly identified the legitimate site.
Neo’s take
This shows that today’s search algorithms broadly share a “first-come, first-served” flaw.
For a brand-new brand keyword, search engines tend to treat the first domain they indexed as the “authority.” When the real site finally shows up, it’s seen as the “latecomer” — and can even be misjudged as the “copycat.”
It’s like opening an authentic Quanjude Peking duck restaurant, only to have your neighbor put up a sign reading “Quanjude” two weeks earlier. You’ve got the secret recipe, but in the eyes of passersby (the search engine), the neighbor is the original.
03 This Is a Security Risk, Not Just a Ranking Problem
If this were only a fight over rankings, you’d just lose a little face. But Cohen points out it’s an “active security risk.”
The fake site only runs ads right now — but whoever controls it can do anything:
- Swap download links for malware.
- Build phishing pages to steal developer credentials.
- Publish fake version-update notices.
For a security-sensitive AI infrastructure project, that’s fatal.
Neo’s take
B2B and SaaS folks, take note: a domain isn’t just a traffic entry point — it’s brand equity and a security line of defense.
A lot of founder-engineers think, “My product is good enough, I’ll deal with the domain later.” This case proves that by the time “later” comes, you might have not only lost traffic — your brand reputation could be destroyed by hackers overnight.
04 Three Key Lessons for Independent Site Operators
As Chinese brands going global, how do we avoid becoming the next NanoClaw when building overseas sites?
1. Register your domains early — even before writing your first line of code
Don’t wait until the product is built to think about domains. The moment you have an idea for a name, immediately register the mainstream suffixes: .com, .net, .io, etc. A few dozen dollars now can save millions in PR costs later.
2. Protect your brand on every front Beyond the official site, claim your social media handles (Twitter/X, LinkedIn, Facebook) on day one. These high-authority social profiles help you occupy more real estate on search engine results pages (SERPs) and squeeze out the impostors.
3. Use the “complaint” mechanisms, but don’t count on them Cohen filed a DMCA, complained to Google, complained to Cloudflare — and it barely moved the needle. Big platforms’ review processes are painfully slow and mechanical.
The real solution is: build a strong enough brand moat that users come to you directly via bookmarks or typing your URL — instead of relying on search.
Summary
The NanoClaw story shows that in the AI era, traditional SEO rules are getting more and more surreal.
Even if you have the best content on earth and the most hardcore technical endorsements, if you neglect the fundamentals — domain strategy and timing — you can still lose the traffic war to a simple scraper script.
For those of us going global, “domain first, product second” should be an iron law carved into our DNA.
References: