Machines have been transacting with each other, at scale, with no human in the loop, for twenty years. Programmatic advertising clears billions of them a day, bids settled in under a hundred milliseconds, money moving between parties that have never met and never will. Nobody is in the room. Nobody could be.
It runs on an identity layer that doesn't work, and most people in the business know it.
Cookies got deprecated, then partially undeprecated, then worked around. Fingerprinting filled the gap and got regulated. Attribution windows are a negotiation, not a measurement. If you've ever sat in a meeting where the publisher's numbers and the platform's numbers disagree and neither side can prove which one is wrong, you've already met this problem. That meeting happened at every publisher I worked with, and it had been happening for twenty years before I got there.
Adtech never fixed it. It built a patch instead - verification vendors, fraud detection, viewability scoring, brand safety. An industry whose job is to stand next to the transaction and grade it after the fact.
Grading works when the thing being faked is traffic, because you can look at a request and estimate how likely a person is behind it. It stops working when the fake thing is the person.
Then the cost fell
Three years ago AI video meant that grainy Will Smith eating spaghetti clip everyone passed around. Now it's cinematic, and it is hard to tell what is real.
The tooling for wiring that into a pipeline is a free npm install, and it works the same for cloning a voice.
The FTC's 2025 numbers show what came out the other side. Americans reported losing 15.9 billion dollars to fraud, up 27 percent on 2024 and roughly 430 percent on 2020. Imposter scams took 3.5 billion of it across about a million reports, and business impersonators alone took about a billion.
That category has topped the FTC's list five years running.
The patch is coming apart in court
Penske Media is suing Google over AI Overviews. The complaint puts click-through down as much as 58 percent and describes the change as one from a search engine that sends traffic to websites to an answer engine that removes the reason to click.
Then in late May a court in Munich ruled Google couldn't claim host-provider protection under the DSA for inaccurate AI Overviews. Verification vendors rely on that same defense, that they only pass things along and don't originate them.
I do AEO audits for publishers, so I watch this up close. Most of the work is making a publisher's material legible to systems that answer without linking. Every conversation ends up being about attribution, and it ends up there because nobody in the room can prove any of it.
One name, both sides of it
Deepfaked MrBeast ads have been running scams across YouTube for a while, using one of the most recognizable faces on the platform to take money from people who thought they recognized him.
In January, BitMine Immersion - Tom Lee's company, and as of that announcement the largest corporate holder of ether - put 200 million dollars into Beast Industries, partly to build a financial services platform on decentralized finance, sitting on an audience north of 450 million.
The standard being written for agents
While the suits proceed, ERC-8004 shipped. It's called Trustless Agents and it defines three onchain registries - Identity, Reputation, Validation. An agent gets a portable identity as an ERC-721 pointing at a registration file. The stated goal is letting agents find each other and trade trust signals across organizational boundaries with nobody central vouching for anyone.
It's live on Ethereum, Base, Polygon, Monad, and BNB Chain. The authors work at MetaMask, the Ethereum Foundation, Google, and Coinbase.
What I got wrong about my own swing at it
Last year I drafted a provisional patent for blockchain-based attribution and automated revenue allocation in creator commerce, and a counsel brief to go with it. Working out why it would not hold taught me more than filing it would have. The background named the problem fine. Affiliate systems run on centralized links, cookies, and manual tracking, and those are prone to fraud, data loss, and disputes.
I got it in front of Gunderson Dettmer. They told me the industry runs on trade secrets. Filing a patent only pays if you can afford to enforce it, and enforcing means legal proceedings Apple can absorb and a small startup cannot, so execution matters more.
Good advice. What I missed is that the technical problem was right there and I never claimed it. Attribution state dies when it crosses a trust boundary. That's the actual hole, and if you're building anything that hands off between two systems that don't share a database, it's your hole too. It doesn't matter whether the thing crossing is a referral, a payment, or a claim about who somebody is.
Why it's worth something now
IBM spent ten years selling this to banks and insurers. An immutable record, a contract that pays out on its own, a way to trust a stranger with nobody in between. It mostly didn't stick, because banks already had middlemen they trusted and regulators standing behind them. They didn't need it badly enough.
Machines transacting with machines need it badly, and so does anyone whose face just became a monetizable asset. Which is what Circle bought when it went from owning almost no patents to holding the largest blockchain portfolio in the US, nearly a thousand of them from IBM. The framing is USDC protection. Most of what's in there was never about currency - supply chain verification, enterprise infrastructure, identity, insurance. Adtech spent twenty years not building that, and Circle picked it up for the price of a patent portfolio.
The patents sat unused at IBM for a decade, and Circle owns them now. The thing in between still doesn't exist.
