Navigating the modern internet often feels like walking through a digital minefield. Every website visited, every mobile app opened, and every smart television streamed from triggers a cascade of invisible data transactions. Billions of tracking requests are fired off in milliseconds, harvesting geolocation coordinates, device fingerprints, and deeply personal user profiles.
Historically, the entities orchestrating this massive harvest—and the opaque advertising platforms powering them—have operated behind a veil of ambiguity. While much of this infrastructure relies on semi-public disclosure files, the data has traditionally remained walled off, fragmented, and exceedingly difficult for ordinary users, privacy advocates, or cybersecurity researchers to parse.
That dynamic shifted dramatically with the launch of DecryptAds, a powerful, free, public-facing intelligence service designed to scrape, correlate, and demystify the sprawling architecture of the global advertising technology (adtech) ecosystem.
Main Facts: What is DecryptAds and How Does It Work?
Developed by a team of cybersecurity and threat research veterans—including Zach Edwards, chief research officer for DecryptAds and a threat researcher at Infoblox—decryptads.com is engineered to approach adtech strictly through a security and privacy lens.
The platform continuously harvests and cross-references machine-readable configuration files that websites, mobile applications, and smart TV networks are required or encouraged to publish. These include:
ads.txt (Authorized Digital Sellers): Public declarations identifying all authorized adtech companies and data brokers permitted to sell or run advertisements on a specific website.
app-ads.txt: The equivalent framework designed for mobile and smart TV applications to prevent counterfeit inventory.
buyers.json and sellers.json: Cryptographic directories detailing the entities buying, selling, or reselling advertising inventory across programmatic exchanges.
Rather than looking at these files in isolation, DecryptAds automates the grueling process of cross-referencing them. By synthesizing cross-domain relationships, the platform allows security analysts to map complex supply chains, spot ownership anomalies, and expose the shadowy networks feeding on consumer data.
Chronology and Genesis: The Evolution of Adtech Transparency
To understand the necessity of DecryptAds, one must look at how the adtech industry attempted to regulate itself, and where those efforts fell short.
The Rise of ads.txt
In 2017, the Interactive Advertising Bureau (IAB) introduced ads.txt to combat ad fraud—specifically domain spoofing, where malicious actors pretend to be premium publishers to steal ad revenue. While the standard achieved widespread adoption, it was never designed as a security auditing tool. It was meant to protect ad dollars, not user privacy.
The Fragmented Enforcement Era (2018–2025)
Over the following years, regulatory pressures mounted. Several U.S. states—most notably California, Oregon, Texas, and Vermont—enacted data broker registration laws. Concurrently, cybersecurity researchers increasingly realized that vulnerabilities in the digital advertising supply chain were becoming primary vectors for malware delivery (malvertising) and state-sponsored espionage.
However, investigating these issues remained an excruciating manual process. Threat hunters had to manually crawl individual sites, pull ads.txt files, cross-check them with fragmented sellers.json logs, and manually search corporate registries. Bad actors exploited this friction, quietly removing compromised partners or hiding behind multi-layered shell companies without public accountability.
The Launch of DecryptAds (2026)
Recognizing that supply-chain integrity issues rarely live in a single file, Edwards and his co-founders built DecryptAds to bridge this intelligence gap. By continuously scraping, indexing, and normalizing millions of publisher declarations, the platform transformed unstructured advertising metadata into an accessible, searchable intelligence graph.
Supporting Data: Inside the Adtech Ecosystem
To demonstrate the platform’s analytical power, consider how DecryptAds breaks down high-traffic digital properties.
The ESPN Case Study
A query for the major sports network espn.com reveals a sprawling web of partnerships: 143 ad partners and 19 registered data broker domains declared within its combined ads.txt and app-ads.txt files.
Because of state-level data broker registry laws, DecryptAds can flag the specific behaviors of these entities. The platform reports that nearly half of those listed data brokers collect precise geolocation data from visitors who do not employ ad blockers. Furthermore, three separate brokers explicitly disclose that they harvest device fingerprints and sensitive personal information.
Geographic Risks and Sanctioned Entities
One of DecryptAds’ most striking features is its Geo-Risk classification engine. The tool automatically flags advertising partners rooted in high-risk jurisdictions—such as China and Russia—or in strategic financial hubs with close ties to both, including Cyprus and the United Arab Emirates (UAE).
For example, DecryptAds highlights that espn.com maintains commercial relationships with four advertising entities based in Russia, China, or the UAE. Among them is Between Digital, an adtech firm that lists a New York corporate address on paper. However, DecryptAds’ investigative dossier exposes Between Digital as a Russian firm whose publisher payout offers are processed through Alfa Bank—Russia’s largest private commercial bank, which was placed under heavy U.S. sanctions following the 2022 invasion of Ukraine.
When researchers pivot on Between Digital’s network footprint, the scale of exposure widens dramatically. The firm’s app-ads.txt file points to hundreds of low-quality, ad-heavy mobile gaming domains. Furthermore, searches across multiple high-profile U.S. military news outlets—including Army Times, Air Force Times, Defense News, Navy Times, Marine Corps Times, and Federal Times—reveal that all of them permit Between Digital to serve ads and track their military-affiliated audiences. DecryptAds estimates that Between Digital collects ad telemetry across roughly 55,000 partner websites globally.
Similarly, an audit of the popular Opera web browser—which has been majority-owned by the Chinese firm Kunlun Tech since 2016 (though operationally headquartered in Oslo)—reveals 27 registered data brokers embedded in its ecosystem. These include 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine.
Official Responses and Industry Dynamics
As of publication, entities like Between Digital and its founder have not publicly responded to inquiries regarding their corporate ownership or banking ties. However, the broader digital advertising industry is facing unprecedented scrutiny over how it handles accountability.
The Problem of "Quiet Removals"
According to Zach Edwards, major ad exchanges frequently catch bad actors engaging in unauthentic traffic generation, ad fraud, or malicious ad delivery. When this happens, exchanges often quietly purge the offender from their sellers.json files without issuing public advisories.
"The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public," Edwards explained. "The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone."
To counter this opaque self-regulation, DecryptAds incorporates a Quiet Removals Feed. This dedicated feature logs and correlates historical removals across multiple ad exchanges, allowing security professionals to track when and where bad actors are being quietly excised from the digital supply chain.
The Conflict-of-Interest Loophole
Edwards also points out systemic risks stemming from vertical integration. Platforms like Between Digital frequently list themselves as both publishers and resellers across approximately two-thirds of their portfolios.
By playing both sides of the programmatic bidding equation, these firms create inherent conflicts of interest—opening doors to direct client ad spend toward owned-and-operated properties or compromised infrastructure without external oversight.
Implications: Malvertising, AI Slop, and National Security
The democratization of threat intelligence provided by tools like DecryptAds carries profound implications for cybersecurity, privacy rights, and geopolitical risk management.
The AI Slop and Malvertising Pipeline
While premium publishers like ESPN or major news outlets employ rigorous security teams to filter out malicious ad injections, the vast expanse of the internet is increasingly populated by automated, machine-generated content farms—colloquially known as "AI slop."
These low-quality websites, dedicated to everything from home improvement recipes to generic consumer tech blogs, rarely invest in brand-safety tools. Instead, they onboard the cheapest, lowest-tier ad partners available.
Recent investigations—such as research by Bitsight into compromised H96 TV streaming sticks spoofing mobile devices to click on programmatic ads—demonstrate how these content farms act as greased rails for malvertising. Malicious actors leverage these unvetted networks to push zero-click payloads, malware downloads, and phishing campaigns directly to unsuspecting web surfers.
The Missing Piece: Supply Chain Objects (SCO)
Solving the malvertising crisis, Edwards argues, requires structural reform within the adtech industry. Specifically, major ad platforms must begin broadly sharing Supply Chain Objects (SCO)—structured metadata attached to programmatic bid requests that expose every intermediary, seller, and buyer involved in an ad impression.
Without access to server-side SCO logs, organizations targeted by sophisticated malvertising campaigns remain flying blind, unable to trace the ultimate origin of malicious payloads. DecryptAds attempts to offset this deficiency by offering a robust Application Programming Interface (API), allowing researchers to automate queries and integrate adtech intelligence directly into modern AI threat-hunting platforms.
Practical Defense: What Can Users Do?
Given the pervasive nature of programmatic tracking, data brokering, and malvertising, cybersecurity experts agree that passive browsing is no longer viable. Securing personal privacy requires proactive defensive measures at multiple layers of the digital stack.
1. Browser-Level Ad and Script Blocking
For everyday users browsing on desktop and laptop computers, deploying a robust, open-source content blocker is essential:
uBlock Origin Lite: A lightweight, highly efficient, and well-maintained extension that strips out malicious scripts, ads, and trackers.
Adblock Plus: A reliable alternative for users on Apple’s iOS (iPhone and iPad) ecosystem.
NoScript: A power-user tool that blocks all unapproved JavaScript by default, preventing drive-by downloads and malvertising scripts from executing, though it requires manual management of site permissions.
2. Network-Level Defenses (Pi-hole)
For technically inclined users seeking a comprehensive household solution, deploying a hardware-based DNS sinkhole is the gold standard. By setting up a low-cost Raspberry Pi running Pi-hole and routing local network DNS requests through it, households can systematically block ad and tracker domains at the router level, protecting every connected device—including smart home appliances—simultaneously.
3. Skepticism Toward Mobile Apps
Users should exercise extreme caution regarding mobile applications and smart TV software. Major digital platforms aggressively push users toward dedicated mobile apps not because of superior user experience, but because apps bypass browser-level protections, enabling deeper surveillance, precise geolocation tracking, and unconstrained harvesting of user data for algorithmic training. Whenever possible, interacting with services directly through a hardened web browser remains the privacy-preferable choice.
As tools like DecryptAds continue to pull back the curtain on the multi-billion-dollar adtech surveillance apparatus, the hidden plumbing of the web is finally being brought into the light—giving researchers, regulators, and everyday users the data they need to fight back.