Your post reminded me of this situation with .IO. that was on HN recently...
https://getstream.io/blog/stop-using-io-domain-names-for-pro...And then there was the security researcher who took control of 4 of the 7 authoritative name servers... http://www.securityweek.com/researcher-takes-over-io-domains...
Not sure what to do in this situation though.