Executive Overview
For decades, the mechanics of online advertising have operated behind an opaque curtain of technical jargon, corporate conglomerates, and decentralized networks. While the average internet user routinely navigates websites and mobile applications, the invisible architecture tracking their movements, harvesting their personal data, and serving targeted advertisements has remained largely shielded from public scrutiny. While this data has technically been semi-public, it has historically lacked a unified, easily parsed interface—leaving consumers in the dark and forcing privacy advocates to manually sift through walled-off disclosures maintained by massive adtech platforms.
That era of ambiguity is coming to an end. A powerful, free new intelligence service known as DecryptAds has emerged to scrape, correlate, and demystify this vast web of advertising technology. By aggregating and analyzing publicly accessible disclosures—such as ads.txt, app-ads.txt, and underlying exchange registers like sellers.json—DecryptAds provides a streamlined, transparent window into the entities harvesting user data across the digital landscape.
Conceived by a team of security and threat researchers, including Infoblox Chief Research Officer Zach Edwards, DecryptAds approaches the adtech ecosystem not through a commercial marketing lens, but from a rigorous cybersecurity perspective. The platform addresses long-standing vulnerabilities that have been severely underserved, including supply-chain integrity failures, the proliferation of AI-generated content farms, and the hidden channels through which geopolitical adversaries infiltrate western digital spaces. As modern tracking technologies evolve to siphon sensitive telemetry—ranging from precise geolocation data to complex device fingerprints—DecryptAds serves as an indispensable tool for journalists, researchers, and privacy-conscious organizations aiming to map the modern surveillance economy.
Detailed Chronology & Mechanics: Unveiling the Hidden Infrastructure
The genesis of DecryptAds lies in the realization that adtech transparency files, while mandated by industry standards to curb ad fraud, are virtually useless in isolation. Launched officially via decryptads.com, the platform operates by continuously scraping and cross-referencing files that publishers and app developers are required to make public to authorize ad-selling partners.
These foundational files include:

ads.txt(Authorized Digital Sellers): A standardized text file published by website owners that lists all adtech companies and data brokers authorized to sell or manage their ad inventory, as well as harvest data.app-ads.txt: The mobile and smart-TV counterpart toads.txt, detailing entities permitted to display ads or harvest telemetry from applications.buyers.json/sellers.json: Structured directories published by ad exchanges that identify the specific corporate entities buying, selling, or reselling ad inventory.
According to Zach Edwards, the data contained within these files only reveals its true nature when correlated across multiple exchanges and domains. "Supply-chain integrity issues rarely live in a single file," the platform notes in its analytical documentation. Instead, they manifest as broken cross-references between authorization lists, cloned declaration sets spanning entirely unrelated domains, sudden seller removals, and supply paths visible only within server-side bid logs.
To demonstrate the sheer scale of modern ad exposure, a search on DecryptAds for the premier sports network espn.com reveals an astonishing 143 ad partners and 19 registered data broker domains explicitly declared within its ads.txt and app-ads.txt files. This granular visibility is increasingly supported by emerging regulatory frameworks. Four U.S. states—California, Oregon, Texas, and Vermont—have enacted legislation requiring data brokers to officially register if they collect, buy, or sell consumer data originating from within their borders. DecryptAds’ analysis of ESPN’s disclosures shows that nearly half of these listed data brokers actively collect geolocation data from visitors who fail to block ads, while others explicitly harvest device fingerprints and sensitive personal information.
Supporting Context & Metrics: High-Risk Partners, Geopolitics, and Supply Chain Vulnerabilities
One of DecryptAds’ most critical features is its automated identification of high-risk advertising partners, flagging entities operating out of "geo-risk" jurisdictions such as Russia and China, as well as financial safe havens with close ties to both, including Cyprus and the United Arab Emirates (UAE).
The Case of Between Digital and U.S. Sanctions
A prime example surfaced during an audit of espn.com, which revealed partnerships with entities based in geo-risk regions. Among them is Between Digital, an adtech firm that outwardly lists a New York corporate address. However, DecryptAds’ dossier flags Between Digital as a Russian firm, noting that its publisher payout offers are processed through Alfa Bank—Russia’s largest private commercial bank, which was placed under sweeping U.S. sanctions following the 2022 invasion of Ukraine.
The footprint of such entities extends deeply into sensitive infrastructure. Audits of major U.S. military-focused news outlets—including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com, and federaltimes.com—reveal that all of these publications authorize Between Digital to serve ads and track users, alongside multiple entities based in the UAE and Panama. DecryptAds estimates that Between Digital collects ad-related intelligence across approximately 55,000 partner websites globally.

Furthermore, analyzing Between Digital’s app-ads.txt file exposes hundreds of low-tier, web-based mobile games designed to bombard users with continuous advertisements. Edwards points out that Between Digital is listed as both a publisher and a reseller on roughly two-thirds of its portfolio, creating profound conflicts of interest. "It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure," Edwards explained.
Browser Ecosystems and Cross-Border Ownership
The platform also sheds light on widely used consumer software whose ownership structures obscure foreign data collection pipelines. For instance, the Opera web browser remains popular globally, yet it has been majority-owned and controlled since 2016 by the Chinese technology firm Kunlun Tech (though Opera’s operational headquarters remain in Oslo, Norway).
DecryptAds’ profile for opera.com identifies 27 registered data brokers, including 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine. These foreign-nexus entities account for roughly 7% of the total adtech partners specified in Opera’s authorization files.
Official Statements & Investigative Deep Dives
Legal Dossiers and the H96 Streaming Stick Investigation
DecryptAds provides a powerful "Legal Dossier lookup" tool. While queries can take several minutes to process, the tool compiles comprehensive ownership histories, registration timelines, aliases, and operational connections linking disparate domains and mobile apps.
This feature proved vital in contextualizing recent findings by cybersecurity researchers at Bitsight. Bitsight uncovered that a popular line of residential TV streaming sticks known as H96 was quietly turning user internet connections into proxy nodes for strangers. Furthermore, when these devices were idle, they were observed spoofing mobile phones to automatically click on advertisements hosted across automated, AI-generated content farms.

Bitsight attributed this malicious ecosystem to a Chinese entity known as the Fengwo Group, which controlled both the malicious Android applications installed on the H96 sticks and the network of AI "slop" websites receiving fraudulent ad clicks. A DecryptAds legal dossier on a dormant Fengwo domain (medicalbeautyhub.com) revealed that it shared a seller ID (1674071) with a gaming portal (giacoloredstones.com), which in turn pointed to an additional seller ID (103488000). Pivoting on this latter identifier exposed hundreds of active websites tied to Russia’s Yandex ad network, all pumping out low-quality games and utility software designed to aggressively harvest ad impressions.
Tracking "Quiet Removals"
In the traditional adtech industry, ad networks that discover an exchange partner engaged in fraudulent click manipulation or malvertising will frequently purge the offender from their authorization lists quietly, without public disclosure. This lack of transparency allows rogue players to rebrand, migrate, and continue victimizing other networks.
To combat this, DecryptAds introduced a Quiet Removals Feed, which aggregates and tracks all sellers.json deletions across multiple ad exchanges. "The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public," Edwards observed. "The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone."
Future Outlook: Malvertising, AI Slop, and Defense Strategies
Looking forward, the convergence of generative artificial intelligence and programmatic advertising has created a fertile breeding ground for cyber threats. Low-quality, machine-generated content farms—covering everything from cooking recipes to home improvement and consumer tech—rarely invest in enterprise-grade security filters. Consequently, these sites act as "greased rails" for malvertising campaigns, where threat actors inject malicious payloads, zero-click exploits, and phishing redirections into ad streams targeting unsuspecting web users.
Edwards stresses that mitigating these threats requires a fundamental shift in how major ad networks handle data transparency. Specifically, he advocates for the broader industry-wide exposure of the Supply Chain Object (SCO)—structured data attached to server-side ad bid requests that maps every single intermediary, reseller, and buyer involved in a transaction. Without visibility into the SCO, defenders can observe malicious redirections, but they remain incapable of pinpointing the exact financial beneficiary or threat actor behind a malicious ad payload. To assist researchers in automating these investigations, DecryptAds provides a robust Application Programming Interface (API) enabling seamless integration with modern AI research platforms.

Recommended Defensive Postures for Consumers
Given the pervasive nature of modern digital tracking and malvertising, security experts universally endorse proactive defensive measures.
- Browser-Level Ad Blocking: For desktop users, open-source extensions such as uBlock Origin Lite offer robust, well-maintained protection against tracking scripts and malicious ads. Mobile browser users on Android can leverage Firefox combined with uBlock Origin, while iOS users on iPhones and iPads can utilize tools like Adblock Plus or configure custom blocklists via easylist.to.
- Network-Level Pi-hole Deployment: For advanced, network-wide defense, technically inclined users can deploy Pi-hole on a low-cost, credit-card-sized Raspberry Pi computer. Configured as a local DNS sinkhole, a Pi-hole blocks advertisements and telemetry domains for every device connected to a home network.
- App Caution and Browser Preference: Users should exercise extreme caution when downloading mobile applications or smart TV software. Major digital services frequently pressure consumers into installing native apps not for a superior user experience, but because apps grant corporations unfettered access to precise geolocation data, persistent device identifiers, and user permissions often repurposed for training large language models. Whenever possible, interacting with services directly through a hardened web browser remains the safer, more private alternative.
As surveillance capitalism continues to adapt, tools like DecryptAds represent a vital counterweight, shining a much-needed spotlight on the hidden plumbing of the internet and empowering the public to reclaim their digital privacy.
