The World's Most Valuable Domain Wasn't Stolen. It Was Bought at Checkout for $12.
In 2015 a graduate student bought google.com for $12 on Google's own registrar. The control that failed was a renewal, not a firewall.
The most-trafficked domain on the internet went up for sale.
Twelve dollars.
At the checkout, like any other domain name.
In September 2015, Sanmay Ved was awake late, clicking around Google Domains — Google’s own registrar.
He typed google.com out of habit.
He had worked at Google for five and a half years; poking at the product was reflex.
The interface showed a green icon, not the gray one that means a domain name is taken.
Available.
He added the world’s busiest web address to a shopping cart, entered his card, and the charge went through. Twelve dollars.
Then the confirmations started — not a generic receipt, but owner notifications.
His Google Search Console filled with messages meant for whoever controlled google.com.
Internal emails arrived.
For about a minute, the webmaster controls for Google’s flagship domain answered to a graduate student’s account.
Nobody broke in.
There was no exploit, no stolen credential, no clever payload.
The thing protecting google.com was its registration — the quiet assumption that the domain name stays yours because someone, somewhere, keeps the record current. No firewall sits in that path. There is nothing there to hack.
That assumption is the whole security model. And it runs on a clerical task.
A domain is not property you own. It is a lease you renew. Miss the renewal, or let the registrar’s internal state slip, and the asset does not degrade slowly — it becomes available. Purchasable. By anyone at the checkout, in the same flow that sells a hobbyist a blog address.
The last line of defense is a renewal — and renewals are clerical.
What matters for a decision-maker is where this mistake lived: in the administration, not the engineering.
Most companies guard the things that feel dangerous: the servers, the endpoints, the logins. The domain sits in a registrar account that often has no named owner, no audit trail, no multi-factor, and no line in the security policy. It renews on a credit card that expires. It depends on an email address belonging to someone who left two years ago.
The most expensive loss in your infrastructure can come from your own renewal calendar — no attacker required.
Ved reported it. Google paid him $6,006.13 — a number that reads as “Google” if you squint — then doubled it to over twelve thousand dollars when he asked that it go to charity.
He could have just kept clicking.
What kept the world’s most valuable domain safe was a renewal, not a firewall, nor multi-factor protection.
And that renewal almost didn’t happen.
Magyar változat: [zona.hu/a-vilag-legertekesebb-domainjet-nem-loptak-el/]


